garethEds Posted January 19, 2021 Posted January 19, 2021 Good morning all, On our staff laptops - Microsoft Teams needs to update and as we are using the MSI it is proving a little bit difficult as staff users do not have permissions to install software. Is it possible to allow one application to install but stop others? I have the application .exe name but naturally when the application tries to install the restricted staff users is stopped from installing. If we were in work I would fix it but as we are away from the school campus I cannot help every member of staff remotely. Any advice appreciated. Thanks Gareth
3s-gtech Posted January 19, 2021 Posted January 19, 2021 Do you know what part of it is failing to install? Staff will be able to run the Teams installer, and Teams only installs to AppData which won't need UAC authorisation to write to. Is it an Applocker rule that's stopping it? MS recommend a Publisher whitelist - I've just whitelisted the Teams exes and the installer executable too. Staff still can't install it as FSRM doesn't allow them to save .exe! That's easy to fix.
garethEds Posted January 19, 2021 Author Posted January 19, 2021 Do you know what part of it is failing to install? Staff will be able to run the Teams installer, and Teams only installs to AppData which won't need UAC authorisation to write to. Is it an Applocker rule that's stopping it? MS recommend a Publisher whitelist - I've just whitelisted the Teams exes and the installer executable too. Staff still can't install it as FSRM doesn't allow them to save .exe! That's easy to fix. Hi Pal - that's what I thought. So I've tested and removed all Teams from my laptop and gone to install again. It downloads a file called Teams_windows_x64.exe which I can run. One would hope it would upgrade in the background (come on Microsoft) - but it doesn't. We've not blocked anything - so must be at LEA level. Strange. I assumed it would install to the profile too. Gareth
computer_expert Posted January 19, 2021 Posted January 19, 2021 (edited) What path is logged in the applocker event log when that prompt appears? https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/applocker/using-event-viewer-with-applocker Edited January 19, 2021 by computer_expert
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now