General discussion

Locked

Preventing Users Installation

By shaundyc ·
Is it possible to restrict Power Users from Installing softwares on a W2K Pro System? Coz some applications wont run if their account was not a power user. I just want to stop them from installing any more softwares...

Thanks

This conversation is currently closed to new comments.

12 total posts (Page 1 of 2)   01 | 02   Next
| Thread display: Collapse - | Expand +

All Comments

Collapse -

by shaundyc In reply to Preventing Users Installa ...

Point value changed by question poster.

Collapse -

by Smeglor In reply to Preventing Users Installa ...

You can establish this in the Local security snap-in located in the control panel.

Collapse -

by shaundyc In reply to

Poster rated this answer.

Collapse -

by Mike Jones In reply to Preventing Users Installa ...

This can be done via Group Policy on the local workstation.

I suggest reading up on this first as if done wrong can lock you out of the machine.

Collapse -

by shaundyc In reply to

OK. Do you have any URLs that can help me with this...

thanks

Collapse -

by Eric9 In reply to Preventing Users Installa ...

This is not perfect, but make a group policy with the following options in it, it will prevent most users from installing things:

Computer Config / Admin Templates / Windows Components / Windows Installer / Disable Windows Installer (For non managed apps only)

User Config / Admin Templates / System / Don't run specified Windows applications (setup.exe, install.exe)
(This option only prevents them from being run from a window, such as Explorer or the Run menu, not command prompt or Add/Remove Programs, so:)

User Config / Admin Templates / Control Panel / Add-Remove Programs / Hide "Add a program from CD-Rom or floppy disk" option

And if possible:

User Config / Admin Templates / System / Prevent access to the command prompt

Let us know if this will work for you.

Eric

Collapse -

by shaundyc In reply to

Poster rated this answer.

Collapse -

by Dennis@l In reply to Preventing Users Installa ...

Under Local security settings, local policies, security options you can define whether or not anyone can install by defining the Signed and non-signed driver installation behavior. It appears as if the application is installing then you get prompt to install it anyway, but it want and you have to ignore the file/cancel installation and the application want work at all.

You should be able to set something like this at Domain level since domain settings over ride local. However Warning Warning****** Not even the administrator can by pass these settings once you set them. If you set them you may have to remove the workstation from the domain to reset the local policies so that you can install applications later. I have a template if you really want to do this, let me know.

Collapse -

by shaundyc In reply to

hey thanks man, I want to give it a try may I ask for your template...

Collapse -

by exNN In reply to Preventing Users Installa ...

We have experienced the same thing, the way we worked out if those programs are stored locally, is log as administrator, and give full privileges to those folders which are used for each app. You can try giving just read/write/change, some sw will work, some not. Then logoff and logon as user again. Hopefully this will work.

Back to Windows Forum
12 total posts (Page 1 of 2)   01 | 02   Next

Related Discussions

Related Forums