
CChong2 (Flexera) asked a question.
Run Elevated vs. RunAs??
Hi, all.
I have a msi that needs to write to HKLM, and I'm having a problem getting privileges to do so.
As a n00b at this packaging business, I'm confused with the AlwaysInstallElevated property.
In RobertDickau's book, Admin's Intro to Application Repackaging , it states that if the policies for run elevated are set (computer and user) then your msi will run as LocalSystem, with full control. (if I'm understanding correctly...:confused: )
However... I'm seeing on these forums that if you need to write to system areas, you need to use RunAs. (which works, but is a workaround?)
The question, then, in a nutshell is: Does an AD policy elevated msi actually run as LocalSystem or not? If not, what is it good for? If it does, what have I got misconfigured to cause it not to run elevated?
TIA,
--Bob
Thanks for the reply.
Even with your advice, I'm afraid things are still not working correctly. :(
I set up my group policies for always install elevated to enabled on the Default domain policy, and on the target ou policy (both user and machine, do not block policy inheritance).
I even checked that the HKLM and HKCU registry entries for AlwaysInstallElevated = 1.
The application shows up as it should in Add/Remove Programs (published)
A non-privileged user will see the program run, and it reports having successfully run, but it does not modify the registry and files it is supposed to.
When I log in as an admin user, the msi runs correctly.:confused:
Looking at the logfiles of the two events, I see:
Successful:
1: PublishFeatures 2: Publishing product features 3: Feature: [1]
1: PublishProduct 2: Publishing product information
There is then a long logfile detailing the install.
Failed:
1: PublishProduct 2: Publishing product information
Then a one-line log repeating the same information.
I assume that PublishFeatures is at the heart of this, but I don't understand why PublishFeatures doesn't work for a basic user.
Help!?
Thanks,
--Bob