?
Solved

Windows Server 2003 Question

Posted on 2014-08-19
5
Medium Priority
?
94 Views
Last Modified: 2015-10-20
I have a 2003 domain and I would like to prevent users from updating software on the computer. E.g. adobe update, java, windows update etc.
Any updates should be prompted with a password. Is that a feature of windows or a third party software??
0
Comment
Question by:FalconTwo
5 Comments
 
LVL 8

Accepted Solution

by:
Shahnawaz Ahmed earned 1500 total points
ID: 40270758
Dear Falcon

You can use Group policy which restrict windows Installer use for a user.

Instructions

1. Click Start > Run. This opens the Run dialog box.
2.Type gpedit.msc in the "Open" text box in the Run dialog, and then click the "OK" button. This opens the Group Policy Editor.
3. Click to expand Administrative Templates > Windows Components under the Computer Configuration icon in the left-side navigation panel, and then click to select "Windows Installer." This opens the Windows Installer view in the right-side pane.
4. Double-click on "Prohibit User Installs" in the right-side pane. This opens the Prohibit User Installs Properties dialog box.
5. Click to select the radio box next to "Enabled," and then click to select the "Prohibit User Installs" option in the "User Install Behavior" drop-down menu. Click the "Apply" button, and then click the "OK" button to complete the process.
0
 

Author Comment

by:FalconTwo
ID: 40271009
Do you run this from the server?

Also if I (The admin) wants to  install/run update I am assuming I have to login to that machine?

I once saw on a computer where a login prompt prompt appeared if the login individual wants to install the software. Is it possible to get the restriction with a login prompt, so some the proper credentials is entered, the update can proceed

Thanks
0
 
LVL 11

Expert Comment

by:Paul S
ID: 40271052
what is the client OS version? Are these client users administrators or normal users on thir PCs?
0
 
LVL 38

Expert Comment

by:Mahesh
ID: 40271061
The feature you are looking for is available by default on win vista and above
Because User Access Controls (UAC) are enabled by default on these machines for standard users unless you disable them explicitly which prompt for elevation (admin username and password to do installation)

Windows updates will be controlled with GPO and with WSUS GPO you are forcing computers to sync with WSUS servers only
0
 

Author Comment

by:FalconTwo
ID: 40271176
Using windows 7 pro
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wouldn't it be nice if objects in Active Directory automatically moved into the correct Organizational Units? This is what AutoAD aims to do and as a plus, it automatically creates Sites, Subnets, and Organizational Units.
It’s time for spooky stories and consuming way too much sugar, including the many treats we’ve whipped for you in the world of tech. Check it out!
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question