On a home Windows device, a standard user cannot be turned into an effective administrator without actually granting administrator rights. To let a standard user install or change software without giving them full admin rights, an administrator must use one of the supported elevation methods.
Options available in the provided information:
- Use User Account Control (UAC) prompts
- Sign in with an account that is a member of the local Administrators group.
- When the standard user tries to install software, Windows shows a UAC prompt: “Do you want to allow this app to make changes to your device?”
- An administrator must approve this prompt (by clicking Yes and, if required, entering admin credentials). The install then runs with elevated privileges while the user otherwise remains standard.
- UAC is enabled by default; it can be configured only by an administrator. See the overview of UAC behavior and consent prompts in the User Account Control documentation.
- Have an administrator run the installer as administrator
- An administrator can download the installer file (for example, a .EXE or .MSI), right‑click it, and select Run as administrator.
- When the UAC prompt appears, the administrator approves it. The software installs with elevated privileges, even if the primary user of the device is a standard user.
- Use Windows Installer advertising and Group Policy (managed environments)
- An administrator can advertise an application for per‑machine installation using Group Policy or by advertising the MSI directly on the device.
- When a non‑administrator installs an advertised package that is configured for per‑machine installation, Windows Installer can run that installation with elevated privileges.
- Non‑administrator users cannot install unadvertised packages that require elevated privileges.
- (Enterprise/managed) Use Endpoint Privilege Management (EPM) via Intune
- In an organization using Microsoft Intune with Endpoint Privilege Management, users can run as standard users while EPM policies selectively allow elevation for specific apps or tasks.
- This lets users complete certain admin‑level actions (like approved installers) without being local admins, following least‑privilege principles.
- Avoid unsafe policies like AlwaysInstallElevated
- An administrator can technically set the AlwaysInstallElevated policy for per‑user and per‑machine installations so that MSI packages run with elevated privileges for standard users.
- This is explicitly documented as a security risk because it allows non‑administrators to run arbitrary MSI installations with full system access (including SystemFolder and HKLM registry). It should not be used on home or secure systems.
In summary, a standard user cannot independently bypass admin requirements. A legitimate path is for an administrator to approve UAC prompts or run installers as administrator, or in managed/enterprise scenarios, to use Group Policy, Windows Installer advertising, or Intune Endpoint Privilege Management to allow specific elevated operations while keeping the account itself standard.
References: