Skip navigation

How can I use Group Policy to disable the Windows Installer rollback functionality?

A. Depending on the actions performed by the Windows Installer file, the space required to store temporary rollback information about the installation, as described in the FAQ "What's the Windows Installer rollback functionality?", might be very large. If the installation is interrupted, these temporary files remain on the system, and a user could access them to gain information about your computer. Keep in mind that if you apply a Group Policy Object (GPO) to disable the rollback functionality and an installation fails, your computer could be left in a compromised state.

To use Group Policy to prevent Windows Installer from creating the rollback information, perform the following steps:

  1. Open the relevant GPO. For example, open the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in, right-click the organizational unit (OU) or domain, select Properties, select the Group Policy tab, select the GPO, then click Edit.
  2. Expand Computer Configuration, Administrative Templates, Windows Components, Windows Installer.
  3. Double-click "Prohibit rollback."
  4. Select Enabled.
    Click here to view image
  5. Click OK.

You can also configure this setting on a per-use basis by navigating to User Configuration, Administrative Templates, Windows Components, Windows Installer in Step 2 above. When you enable the setting in either area, it overrides any "Disabled" setting.

Hide comments

Comments

  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.
Publish