Block users from installing MSI installed applications

  • Section(s): Applications, Security, Miscellaneous
  • Published on Apr 20, 2004.
  • Last Modified on Apr 20, 2004.
  • Last Modified by Wayne Maples.
  • Rated 3.6 out of 5 based on 10 votes.
You use Active Directory and GPOs to install applications but company policy forbids users from installing or removing applications. How do you enforce the policy? MSI installations require msiexec.exe and appwiz.cpl access. Change the permissions for these two files to Readonly for Authenticated Users and Everyone. Use RunAs to execute appwiz.cpl.

About Wayne Maples

Share this article


Article not looking right or info is missing? Let us know so that we can fix it: .


Receive all the latest articles by email!

Receive Real-Time & Monthly WindowsNetworking.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowsNetworking.com member!

Discuss your network issues with thousands of other network administrators. Click here to join!

Community Area

Log in | Register

Readers' Choice

Which is your preferred Data Recovery solution?