Restricting install rights for Windows Deployment Services

by Mitch Tulloch [Published on 8 March 2012 / Last Updated on 8 March 2012]

How to restrict which users can install images using Windows Deployment Services.

By default all domain users can deploy images from a WDS server. Can you restrict this so that only members a certain group of users have the right to install image using WDS? The answer is yes and there are two ways you can do this:

    • Use the /UserFilter parameter of the wdsutil /set-image command to control the list of images displayed to a user.


  • Use the /Security parameter of the wdsutil /set-imagegroup command to configure access control on file resources for all the images in the group.


For more info see the WDSUTIL syntax at

Mitch Tulloch is a seven-time recipient of the Microsoft Most Valuable Professional (MVP) award and widely recognized expert on Windows administration, deployment and virtualization. For more tips by Mitch you can follow him on Twitter or friend him on Facebook.


The Author — Mitch Tulloch

Mitch Tulloch is a widely recognized expert on Windows administration, networking, and security. He has been repeatedly awarded Most Valuable Professional (MVP) status by Microsoft for his outstanding contributions in supporting users who deploy and use Microsoft platforms, products and solutions. Mitch has published over two hundred articles on different IT websites and magazines, and he has written or contributed to almost two dozen books and is lead author for the Windows 7 Resource Kit from Microsoft Press. For more information, see .

Latest Contributions

Featured Links