Windows OS Hub
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux

 Windows OS Hub / Windows 11 / Fix: The System Administrator Policies Prevent the App Installation

September 9, 2025

Fix: The System Administrator Policies Prevent the App Installation

The following error may occur when attempting to install a program using the MSI installation package on a workstation with local administrator permissions: “The system administrator has set policies to prevent this installation“. I tried running other MSI files, but they did not install either. How can this problem be fixed, and how can these security policies be disabled or bypassed?

Error installing MSI: The system administrator has set policies to prevent this installation

The error “The system administrator has set policies to prevent this installation” may appear when installing or updating apps from MSI packages or EXE installers on a Windows computer. This indicates that the computer has software installation restriction policies enabled.

If your account has local administrator privileges, you can install the application using a simple workaround without modifying the system’s security policy settings.

  • If it is an installer packaged in an *.EXE file, click on it and select Run as administrator.
  • If this is an MSI package, open a Command Prompt window as an administrator and run the installation using the following command: msiexec.exe /i C:\Install\MyAppInstaller.msi

Install MSI from elevated cmd using msiexec.exe

If the program still does not install, even with elevated privileges, check the computer’s Group Policy settings. You can use the rsop.msc graphical snap-in or the gpresult command to view the resulting GPO settings on a computer. Check if there are any configured policy settings under Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer.

The following GPO options can be used to prevent software installation via the MSISERVER service.

  • Turn off Windows Installer
  • Prohibit non-administrators from applying vendor-signed updates
  • Prevent users from using Windows Installer to install updates and upgrades

GPO: Turn off Windows Installer

If these policies are configured, open the local GPO editor (gpedit.msc), navigate to the section specified above, and change the policy setting:

  • Turn off Windows Installer: Enabled with option Never
  • Prohibit non-administrators from applying vendor signed update: Disabled
  • Prevent users from using Windows Installer to install updates and upgrades: Disabled
The policy allows administrators to enable or disable the ability of non-admins to update already installed apps (policy is disabled by default). If the installed app is running in privileged mode (with SYSTEM privileges), you must additionally enable the following GPO option:

  • Allow users to patch elevated products: Enabled

After making changes, run the command to apply the new GPO settings:

gpupdate /force

Never disable Windows Installer via GPO

If a computer is missing a local Group Policy Editor (for example, if it is a Windows Home edition) or if the restrictions are applied directly through the registry, you need to modify the registry. Navigate to the HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer registry key and set the parameter values as follows:

DisableMSI = 0
DisablePatch = 0
DisableLUAPatching=0
AllowLockdownPatch=1

Create these registry items manually if they are missing.

DisablePatch and DisableMSI registry parameters

Note that, unlike desktop editions of Windows, the default Turn off Windows Installer policy value in Windows Server is “For managed applications only“. Therefore, apps that are already installed cannot be updated using a user account on Windows Server.

"Turn off Windows Installer" GPO on Windows Server by default set to For managed applications only

For example, this causes an error when updating some Autodesk products under a user who is not a member of the local Administrators group:

This installation is forbidden by system policy. Contact tour system administrator.

This installation is forbidden by system policy. Contact tour system administrator
The policy must be disabled to allow non-admin users to install app updates. Or run updates with local administrator permissions.

Restrictions on installing programs can also be implemented using Software Restriction Policies or AppLocker. Check the resulting Group Policy settings under:

  • Computer Configuration -> Windows Settings -> Security Settings -> Software Restriction Policies
  • Computer Configuration -> Windows Settings -> Security Settings -> Application Control Policies -> Applocker

If this error occurs while installing or updating the Google Chrome browser, reset the browser policy settings by deleting the HKLM\SOFTWARE\Policies\Google registry key.

Learn more about resetting Group Policy settings in Windows.
0 comment
0
Facebook Twitter Google + Pinterest
Questions and AnswersWindows 10Windows 11Windows Server 2022
previous post
Fix: Slow Startup of PowerShell Console and Scripts
next post
Clean Up ETL Log Files in ProgramData

Related Reading

Configuring RemoteApps Hosted on Windows 10/11 (without Windows...

January 25, 2025

Disable BitLocker Automatic Drive Encryption in Windows 11

October 16, 2024

Disable and Completely Remove Widgets from Taskbar in...

September 26, 2024

Fix: Windows Update Tab (Button) is Missing from...

December 16, 2024

Check the Software Installation/Removal History in Windows

October 8, 2024

Bridging Multiple Network Interfaces on Windows

November 21, 2024

How to Cast/Mirror Android Screen to Windows PC

September 11, 2024

How to Prefer IPv4 over IPv6 in Windows...

April 15, 2025

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • How to Delete a Windows Service via CMD or PowerShell

    October 16, 2025
  • Resource Fair Sharing in Windows Server Remote Desktop Services (RDS)

    October 6, 2025
  • How to Disable (Enable) Credential Guard in Windows 11

    October 6, 2025
  • Wrong Network Profile on Windows Server after Reboot

    September 30, 2025
  • How to Get Windows 10 Extended Security Updates After End-Of-Life

    September 24, 2025
  • Blocking NTLM Connections on Windows 11 and Windows Server 2025

    September 23, 2025
  • Windows Stucks at ‘Getting Windows Ready, Don’t Turn Off Computer’

    September 15, 2025
  • Clean Up ETL Log Files in ProgramData

    September 9, 2025
  • Fix: Slow Startup of PowerShell Console and Scripts

    September 3, 2025
  • DPI Scaling and Font Size in RDP (RDS) Session

    August 27, 2025

Follow us

  • Facebook
  • Twitter
  • Telegram
Popular Posts
  • Converting Windows 10 to Enterprise LTSC Without Losing Data
  • Permanently Disable Driver Signature Enforcement on Windows 11
  • Fix: Windows Update Tab (Button) is Missing from Settings
  • How to Add or Reinstall the Microsoft PDF Printer on Windows
  • Fix: Your IT Administrator Has Limited Access to Virus & Threat Protection
  • How to Remove ‘Some Settings are Managed by Your Organization’ on Windows 11 or 10
  • How to Pause (Delay) Update Installation on Windows 11 and 10
Footer Logo

@2014 - 2024 - Windows OS Hub. All about operating systems for sysadmins


Back To Top