AllowLockdownPatch

HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer

Data type Range Default value
REG_DWORD 0 | 1 0 0

Description

Permits all users to install patches, even when an installation program is running with elevated system permissions.

Patches are updates or upgrades that replace only those program files that have changed. Because patches can be easy vehicles for malicious programs, some installations prohibit their use. By default, only system administrators can apply patches during installations running with system permissions, such as installations offered on the desktop or displayed in Add/Remove Programs.

This entry stores the setting of the Enable user to patch elevated products Group Policy. Group Policy adds this entry to the registry with a value of 1 when you enable the policy. If you disable the policy, Group Policy sets the value to 0. If you set the policy to Not configured, Group Policy deletes the entry from the registry and the system behaves as though the value is 0.

Value Meaning
0 (or not in registry) The policy is disabled or not configured. Users cannot install patches when installing with system permissions.
1 The policy is enabled. Users can install patches when installing with system permissions.

Change method

To change the value of this entry, use Group Policy. This entry corresponds to the Enable user to patch elevated products policy (Computer Configuration\Administrative Templates\Windows Components\Windows Installer).

Tip Image Tip

For detailed information about particular Group Policy settings, see the Group Policy Reference (Gp.chm) on the Windows 2000 Resource Kit companion CD.

For general information about Group Policy, see Group Policy in Windows 2000 Help.

To see a table associating policies with their corresponding registry entries, see the Group Policy Reference Table.

Related Entries

Page Image