Policy
Always install with elevated privileges
Windows 11 25H2
Policy overview
Key metadata and intent for this policy.
Supported OS tags: Windows10, Windows10RT, Windows11, Windows2000, Windows7, Windows8, Windows81, WindowsRT, WindowsRT81, WindowsServer2003, WindowsServer2008, WindowsServer2012, WindowsServer2012R2, WindowsServer2016, WindowsVista, WindowsXP
This policy setting directs Windows Installer to use elevated permissions when it installs any program on the system. If you enable this policy setting, privileges are extended to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or made available in Add or Remove Programs in Control Panel. This profile setting lets users install programs that require access to directories that the user might not have permission to view or change, including directories on highly restricted computers. If you disable or do not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer. Note: This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting effective, you must enable it in both folders. Caution: Skilled users can take advantage of the permissions this policy setting grants to change their privileges and gain permanent access to restricted files and folders. Note that the User Configuration version of this policy setting is not guaranteed to be secure.
Registry values
How enabled and disabled states update the registry.
| Registry location | Type | Enabled value | Disabled value |
|---|---|---|---|
| HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated | REG_DWORD | 1 | 0 |
Policy elements
Inputs and configuration options exposed by this policy.
This policy has no additional user input fields.
Other policies in this category
Explore related policies at the same level.
- ComputerAllow user control over installsAt least Windows 2000
- ComputerAllow users to browse for source while elevatedAt least Windows 2000
- ComputerAllow users to patch elevated productsAt least Windows 2000
- ComputerAllow users to use media source while elevatedAt least Windows 2000
- UserAlways install with elevated privilegesAt least Windows 2000
- ComputerControl maximum size of baseline file cacheWindows Installer v3.0
- ComputerEnforce upgrade component rulesWindows Installer v3.0
- ComputerPrevent embedded UIWindows Installer v4.5
- ComputerPrevent Internet Explorer security prompt for Windows Installer scriptsAt least Windows 2000
- UserPrevent removable media source for any installationAt least Windows 2000
- ComputerPrevent users from using Windows Installer to install updates and upgradesAt least Windows 2000
- ComputerProhibit flyweight patchingWindows Installer v3.0