• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 903
  • Last Modified:

Windows 7: Deny install but allow software updates


We have Windows 7 installed on most of our staff computers. Currently staff (by default settings - not sure how it came to be) do not have access to install programs - which is the way we want it.

However users also do not have permission to allow updates to programs already installed, which we would like to allow them to do.

- How do I  give users permissions to allow updates for installed programs.

- Where are the settings that allow/deny Windows 7 users install rights.

All computers are run on a domain.
2 Solutions
I don't think users will be able to Install windows Update if they are denied the right to install programs. Windows Updates are controlled either by group policy or local policy. And to Modify the Group policy you either need to be a Domain Administrator or a Local Administrator (Here is the Policy where you can modufy settings for windows update: Computer Configuration\Adminstrative Templates\Windows Componets\Windows Update
User Configuration\Adminstrative Templates\Windows Componets\Windows Update)

The basic logic is that one needs to be either Domain Administrator or a Local Administrator on the Machine to install the updates.
DonNetwork AdministratorCommented:
The setting you are looking for is "Allow Non-administrators to Receive Update Notifications"

This policy specifies whether logged-on non-administrative users will receive update notifications based on the configuration settings for Automatic Updates. If Automatic Updates is configured, by policy or locally, to notify the user either before downloading or only before installation, these notifications will be offered to any non-administrator who logs onto the computer.

If the status is set to Enabled, Automatic Updates will include non-administrators when determining which logged-on user should receive notification.

If the status is set to Disabled or Not Configured, Automatic Updates will notify only logged-on administrators.

DonNetwork AdministratorCommented:

"The basic logic is that one needs to be either Domain Administrator or a Local Administrator on the Machine to install the updates."

couldnt be more wrong, the setting above allows non administrators(anyone) to install windows updates.
Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Jackie ManCommented:
According to the comment of abbright, it says:-

Using Microsoft System Center Configuration Manager (http://www.microsoft.com/systemcenter/en/us/configuration-manager.aspx) you can prepare update packages for installed software which users then can install without administrator privileges.

Source: http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/Windows_7/Q_26819017.html
DonNetwork AdministratorCommented:
You can also use Privilege Authority(For free) to allow updating of non Microsoft applications by restricted users.

I apologize for my comment. But the question is will it work without WSUS template ?

This policy is either meant for WSUS or SCCM. I don't think it will be applicable if WSUS or SCCM is not used.
DonNetwork AdministratorCommented:
"Allow Non-administrators to Receive Update Notifications"

Is a Automatic Updates policy. It doesnt matter if updates are applied by WSUS, SCCM or Microsoft Update(Automatic updates). So yes it is applicable if neither are used.

For explanation on all the settings see


take note of  ***** Rob’s notes: *****

Side note:

wuau.adm can still be used if WSUS or SCCM is not implemented.
This question has been classified as abandoned and is being closed as part of the Cleanup Program. See my comment at the end of the question for more details.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now