Step 2: Now that the program is available on your device, boot your PC and attach your device to your PC and press the F12 key when your PC boots-up. Choose your device from the boot menu. Step 3: On the following screen, enter a number that is associated with your Windows installation and hit enter. Mar 23, 2013 Allow Domain Users to install without password prompt. Allow apps from the Store only. Choose Allow apps from the Store only if you want to block all the other software from being installed on your machine by any user. Feb 13, 2017 I am new to Server 2012, and I am trying to figure out how to allow a non-administrator the ability to install and modify software on a computer joined to the domain (or domain controller). You can't have local users/groups on a domain controller so using Restricted Groups in. Oct 04, 2016 / Configuring Office 365 Software Download Settings for End User and BYOD Installs. Configuring Office 365 Software Download Settings for End User and BYOD Installs. Or who want to full manage the installation process and not allow users to install the software at all. By using the following methods, an administrator can enable a nonadministrator user to install managed applications. Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly.
Active3 years, 10 months ago
How would I go about allowing a 'domain user' to install software on their computer. I have active directory and group policy in place. Is there a setting in group policy that would allow this? I don't really want to make the domain users domain admins as well. There is a way to do this by adding the user to their local admins group under computer management. I need this for about 50 users so that gets to be a long process with that many users.
Server: Windows Server 2008 R2Client Machines: Windows 7
EEAA103k1616 gold badges151151 silver badges224224 bronze badges
Christa
3 Answers
Caveat: You really don't want your users to be 'Administrators' on their PCs. You want to find a method to automate the distribution of software (see Mass installation on networked Windows computers? amongst other Server Fault answers) in lieu of allowing users to install the software themselves. (There are a variety of reasons why you don't really want this-- exposing the company to liability for unlicensed software, being able to install malicious software, and just plain screwing-up their computers are a few good ones.)
Having said that, Restricted Groups functionality in Group Policy is what you're looking for. It'll automate the group nesting on an arbitrary number of computers.
Instead of creating a nightmare for yourself later (not to mention a political situation where you can't ever take back the users' 'Administrator' rights) I'd recommend you think strongly about learning how to centrally deploy software first.
Edit:
My answer re: managing updates for Adobe Reader is the same answer I'd give to you re: managing updates for the JRE and other 'necessary evil' software like it. I'd develop a coordinated process of installing the software with Group Policy and updating it by deploying new packages when patches are released.
Community♦
Permission To Install Software
Evan AndersonHow To Allow Software Installation Iphone
Evan Anderson137k1515 gold badges178178 silver badges316316 bronze badges
Best practice is to only allow them to install permitted applications. If you let them install any application, they could install lots of things you don't want them to (like viruses, limewire, keystroke loggers, etc.)
To permit them to install allowed applications, create a software installation in Group Policy. Set the installation type as published.
Here's a decent enough article describing the process:
http://www.windowsnetworking.com/articles_tutorials/Group-Policy-Deploy-Applications.html
Jason BergJason Berghttp://www.windowsnetworking.com/articles_tutorials/Group-Policy-Deploy-Applications.html
16.5k66 gold badges3333 silver badges5454 bronze badges
I would have to recommend Manage-engine Desktop Central, it scans all machines and then collects programs installed on the domain. You can then easily deploy software on either msi or exe files with there prefigured scripts (command lines). Makes my life a hell of a lot easier especially with adobe and java updates all the time.By the way its free for upto 25 machines and is accessible from a browser.
jammerjammer
protected by sysadmin1138♦Sep 24 '12 at 21:50
Thank you for your interest in this question. Because it has attracted low-quality or spam answers that had to be removed, posting an answer now requires 10 reputation on this site (the association bonus does not count).
Would you like to answer one of these unanswered questions instead?
Would you like to answer one of these unanswered questions instead?