How to allow standard windows user to make changes to device without admin priviliges

Ved Iyer 0 Reputation points
2026-03-17T16:43:16.2833333+00:00

Standard user without admin. Need to download some software.

Windows for home | Windows 11 | Accessibility

Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Norah-L 11,410 Reputation points Microsoft External Staff Moderator
    2026-03-18T07:42:22.9666667+00:00

    Welcome Ved Iyer to the Q&A forum!

    From what you described, you’re using a standard Windows account and need to install software, but you want to do so without granting full administrator privileges.

    Unfortunately, standard user accounts on Windows cannot install software that makes system‑wide changes, such as modifying protected system folders, installing drivers, or affecting other users. Because of this built‑in security design (especially on Windows Home) a standard user cannot install this type of software without an administrator approving it.

    What is possible depends on how the application is designed. Apps that support per‑user installation (for example, Microsoft Store apps or software that installs only within the user profile) can usually be installed by standard users. However, if an installer triggers an elevation prompt, that means it requires admin rights, and someone with administrator credentials must approve it, there is no supported way around that.

    I know this isn’t the answer you were hoping for, but I hope it helps clarify the situation and saves you time from trying additional methods that may not resolve it.

    Thank you so much for your understanding!

    Yours sincerely.

    Was this answer helpful?

    1 person found this answer helpful.
  2. AI answer

    2026-03-17T16:43:35.4366667+00:00

    On a home Windows device, a standard user cannot be turned into an effective administrator without actually granting administrator rights. To let a standard user install or change software without giving them full admin rights, an administrator must use one of the supported elevation methods.

    Options available in the provided information:

    1. Use User Account Control (UAC) prompts
      • Sign in with an account that is a member of the local Administrators group.
      • When the standard user tries to install software, Windows shows a UAC prompt: “Do you want to allow this app to make changes to your device?”
      • An administrator must approve this prompt (by clicking Yes and, if required, entering admin credentials). The install then runs with elevated privileges while the user otherwise remains standard.
      • UAC is enabled by default; it can be configured only by an administrator. See the overview of UAC behavior and consent prompts in the User Account Control documentation.
    2. Have an administrator run the installer as administrator
      • An administrator can download the installer file (for example, a .EXE or .MSI), right‑click it, and select Run as administrator.
      • When the UAC prompt appears, the administrator approves it. The software installs with elevated privileges, even if the primary user of the device is a standard user.
    3. Use Windows Installer advertising and Group Policy (managed environments)
      • An administrator can advertise an application for per‑machine installation using Group Policy or by advertising the MSI directly on the device.
      • When a non‑administrator installs an advertised package that is configured for per‑machine installation, Windows Installer can run that installation with elevated privileges.
      • Non‑administrator users cannot install unadvertised packages that require elevated privileges.
    4. (Enterprise/managed) Use Endpoint Privilege Management (EPM) via Intune
      • In an organization using Microsoft Intune with Endpoint Privilege Management, users can run as standard users while EPM policies selectively allow elevation for specific apps or tasks.
      • This lets users complete certain admin‑level actions (like approved installers) without being local admins, following least‑privilege principles.
    5. Avoid unsafe policies like AlwaysInstallElevated
      • An administrator can technically set the AlwaysInstallElevated policy for per‑user and per‑machine installations so that MSI packages run with elevated privileges for standard users.
      • This is explicitly documented as a security risk because it allows non‑administrators to run arbitrary MSI installations with full system access (including SystemFolder and HKLM registry). It should not be used on home or secure systems.

    In summary, a standard user cannot independently bypass admin requirements. A legitimate path is for an administrator to approve UAC prompts or run installers as administrator, or in managed/enterprise scenarios, to use Group Policy, Windows Installer advertising, or Intune Endpoint Privilege Management to allow specific elevated operations while keeping the account itself standard.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

    1 person found this answer helpful.