Tabular array of Contents

  • Introduction:
  • How to make changes via Group Policy:
    • Plow off Windows Installer:
    • E'er install with elevated privileges:
    • Preclude running specific Windows Applications :
    • Run only specified Windows applications:
      • Restrict via Registry Edit:
  • Conclusion:
  • Run into Also:

Introduction:

​Sometimes users without having much knowledge virtually applications start installing applications. As a effect, the system presently become full of bloatware. In that location may be possibility of installing applications with malware. The arrangement get boring and functioning drops.

How to make changes via Group Policy:

Plow off Windows Installer:

  • In Start Search blazon Gpedit.msc and hit the Enter key.
  • The Local Group Policy Editor opens.
  • At present locate:

Computer Configurations > Authoritative Templates > Windows Components > Windows Installer > Turn off Windows Installer

  • Double click on it and select Enabled.
  • Now you volition discover 3 options under Disable Windows Installer
  1. Always
  2. For non-managed applications only
  3. Never


# If you opt Always "Always" selection indicates that Windows Installer is disabled.

This affects Windows Installer merely.  Simply users can use other methods to install and upgrade programs.

# The "Never" pick indicates Windows Installer is fully enabled. Users tin install and upgrade software. This is the default beliefs for Windows Installer on Windows 2000 Professional, Windows XP Professional and Windows Vista when the policy is not configured.

#The "For non-managed applications only" choice permits users to install only those programs that a arrangement administrator assigns.

Ever install with elevated privileges:

  • In Start Search type Gpedit.msc and striking the Enter key
  • In Local Group Policy Editor locate the following:

User Configuration > Administrative Templates > Windows Components. Locate Windows Installer and configure it to E'er install with elevated privileges.

  • To do this double click on Ever install with elevated privileges.
  • Click Enabled
  • If you enable this policy setting, privileges are extended to all programs. These privileges are ordinarily reserved for programs that have been assigned to the user
  • If yous disable or practice not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer.

[This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting constructive, you lot must enable information technology in both folders.]

Foreclose running specific Windows Applications :

  • Open Group Policy Editor.
  • At present locate the post-obit:

User Configuration > Authoritative Templates > System. In the right-hand side pane, expect for Don't Run Specified Windows Applications.

  • Click Enabled

A new selection appears called Listing of Disallowed Applications. Click Show and a Show Contents window appears where y'all blazon in the location of the program to be blocked. Now, y'all're going to add the Windows Installer Program which is called msiexec.exe and is found at: C :\ WINDOWS\system32\msiexec . exe Re-create and paste that into the space provided in the box and click OK. The Windows Installer should now be blocked.

Run simply specified Windows applications:

  • User Configuration > Authoritative Templates > System. In the correct-hand side pane, look for Run merely specified Windows applications.
  • Select Enabled.
  • If you enable this policy setting, users can only run programs that you add to the list of allowed applications.
  • If y'all disable this policy setting or do not configure it, users can run all applications.



Restrict via Registry Edit:

  • In Start Search blazon Regedit and hit the Enter key.
  • Have UAC.
  • In Registry Editor locate the following:

HKEY_LOCAL_MACHINE\Software\Classes\Msi.Bundle\DefaultIcon.

  • Right click, select Edit and modify the 0 to a 1 to disable Windows Installer.

Conclusion:

Autonomously from Group Policy editing or Registry tweaking there are number of 3rd political party applications are as well available in the market place. But when things can be washed without any assistance of third party applications then better to stick to that.
This is as well applicable for Windows ten version 20H2.

See Besides:

  • Fix problems that cake programs from being installed or removed
  • What's new in Windows 10, version 1903 IT Pro content