Windows OS Hub
  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux
  • Home
  • About

Windows OS Hub

  • Windows
    • Windows 11
    • Windows 10
    • Windows Server 2025
    • Windows Server 2022
    • Windows Server 2019
    • Windows Server 2016
  • Microsoft
    • Active Directory (AD DS)
    • Group Policies (GPOs)
    • Exchange Server
    • Azure and Microsoft 365
    • Microsoft Office
  • Virtualization
    • VMware
    • Hyper-V
    • Proxmox
  • PowerShell
  • Linux

 Windows OS Hub / Windows 11 / Fix: The System Administrator Policies Prevent the App Installation

September 9, 2025

Fix: The System Administrator Policies Prevent the App Installation

The following error may occur when attempting to install a program using the MSI installation package on a workstation with local administrator permissions: “The system administrator has set policies to prevent this installation“. I tried running other MSI files, but they did not install either. How can this problem be fixed, and how can these security policies be disabled or bypassed?

Error installing MSI: The system administrator has set policies to prevent this installation

The error “The system administrator has set policies to prevent this installation” may appear when installing or updating apps from MSI packages or EXE installers on a Windows computer. This indicates that the computer has software installation restriction policies enabled.

If your account has local administrator privileges, you can install the application using a simple workaround without modifying the system’s security policy settings.

  • If it is an installer packaged in an *.EXE file, click on it and select Run as administrator.
  • If this is an MSI package, open a Command Prompt window as an administrator and run the installation using the following command: msiexec.exe /i C:\Install\MyAppInstaller.msi

Install MSI from elevated cmd using msiexec.exe

If the program still does not install, even with elevated privileges, check the computer’s Group Policy settings. You can use the rsop.msc graphical snap-in or the gpresult command to view the resulting GPO settings on a computer. Check if there are any configured policy settings under Computer Configuration -> Administrative Templates -> Windows Components -> Windows Installer.

The following GPO options can be used to prevent software installation via the MSISERVER service.

  • Turn off Windows Installer
  • Prohibit non-administrators from applying vendor-signed updates
  • Prevent users from using Windows Installer to install updates and upgrades

GPO: Turn off Windows Installer

If these policies are configured, open the local GPO editor (gpedit.msc), navigate to the section specified above, and change the policy setting:

  • Turn off Windows Installer: Enabled with option Never
  • Prohibit non-administrators from applying vendor signed update: Disabled
  • Prevent users from using Windows Installer to install updates and upgrades: Disabled
The policy allows administrators to enable or disable the ability of non-admins to update already installed apps (policy is disabled by default). If the installed app is running in privileged mode (with SYSTEM privileges), you must additionally enable the following GPO option:

  • Allow users to patch elevated products: Enabled

After making changes, run the command to apply the new GPO settings:

gpupdate /force

Never disable Windows Installer via GPO

If a computer is missing a local Group Policy Editor (for example, if it is a Windows Home edition) or if the restrictions are applied directly through the registry, you need to modify the registry. Navigate to the HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer registry key and set the parameter values as follows:

DisableMSI = 0
DisablePatch = 0
DisableLUAPatching=0
AllowLockdownPatch=1

Create these registry items manually if they are missing.

DisablePatch and DisableMSI registry parameters

Note that, unlike desktop editions of Windows, the default Turn off Windows Installer policy value in Windows Server is “For managed applications only“. Therefore, apps that are already installed cannot be updated using a user account on Windows Server.

"Turn off Windows Installer" GPO on Windows Server by default set to For managed applications only

For example, this causes an error when updating some Autodesk products under a user who is not a member of the local Administrators group:

This installation is forbidden by system policy. Contact tour system administrator.

This installation is forbidden by system policy. Contact tour system administrator
The policy must be disabled to allow non-admin users to install app updates. Or run updates with local administrator permissions.

Restrictions on installing programs can also be implemented using Software Restriction Policies or AppLocker. Check the resulting Group Policy settings under:

  • Computer Configuration -> Windows Settings -> Security Settings -> Software Restriction Policies
  • Computer Configuration -> Windows Settings -> Security Settings -> Application Control Policies -> Applocker

If this error occurs while installing or updating the Google Chrome browser, reset the browser policy settings by deleting the HKLM\SOFTWARE\Policies\Google registry key.

Learn more about resetting Group Policy settings in Windows.
0 comment
0
Facebook Twitter Google + Pinterest
Questions and AnswersWindows 10Windows 11Windows Server 2022
previous post
Fix: Slow Startup of PowerShell Console and Scripts
next post
Clean Up ETL Log Files in ProgramData

Related Reading

Configuring RemoteApps Hosted on Windows 10/11 (without Windows...

January 25, 2025

Disable BitLocker Automatic Drive Encryption in Windows 11

October 16, 2024

Disable and Completely Remove Widgets from Taskbar in...

September 26, 2024

Fix: Windows Update Tab (Button) is Missing from...

December 16, 2024

Check the Software Installation/Removal History in Windows

October 8, 2024

Bridging Multiple Network Interfaces on Windows

November 21, 2024

How to Cast/Mirror Android Screen to Windows PC

September 11, 2024

How to Prefer IPv4 over IPv6 in Windows...

April 15, 2025

Leave a Comment Cancel Reply

join us telegram channel https://t.me/woshub
Join WindowsHub Telegram channel to get the latest updates!

Recent Posts

  • Fix: Slow Startup of PowerShell Console and Scripts

    September 3, 2025
  • DPI Scaling and Font Size in RDP (RDS) Session

    August 27, 2025
  • Proxmox: Share a Host Directory with VMs via VirtioFS

    August 18, 2025
  • How to Find AD Users with Blank Passwords (Password-Not-Required)

    July 24, 2025
  • Run Elevated Commands with Sudo on Windows 11

    July 16, 2025
  • Find a Process Causing High Disk Usage on Windows

    July 15, 2025
  • Fix: Microsoft Defender Not Updating Automatically in Windows

    July 8, 2025
  • Create a Windows Server VM on Proxmox (Step-by-Step)

    July 7, 2025
  • How to Detect Which User Installed or Removed a Program on Windows

    June 23, 2025
  • Encrypt Any Client-Server App Traffic on Windows with Stunnel

    June 12, 2025

Follow us

  • Facebook
  • Twitter
  • Telegram
Popular Posts
  • Fix: Windows Update Tab (Button) is Missing from Settings
  • Permanently Disable Driver Signature Enforcement on Windows 11
  • How to Add or Reinstall the Microsoft PDF Printer on Windows
  • Fix: Your IT Administrator Has Limited Access to Virus & Threat Protection
  • Fix: Multiple Connections to a Server or Shared Resources by the Same User
  • VMware Workstation: Slow VMs Performance on Windows
  • How to Add or Delete Fonts in Windows 11/10
Footer Logo

@2014 - 2024 - Windows OS Hub. All about operating systems for sysadmins


Back To Top