Showing results for 
Show  only  | Search instead for 
Did you mean: 
Level 4

Struggling with folder access rights in IS 2019


I'm trying to limit the access to some of the installed folders (BasicMSI project) to administrators only.

In my installation, I set "Destination Permissions" to deny access "Read" for [%USERDOMAIN]\Users. Unfortunately the result is that I can't even access the folder as administrator anymore unless I take ownership of the folder.

It seems to me the problem is that InstallShield sets the logged on non-admin user as owner of all files even though the setup requires administrator rights. When read access is denied to normal users, Windows seems to have problems because the owner himself can't read the folder anymore.

Is there any trick to avoid this problem or is the only way to use icacls in a custom action? Of course I'd prefer to use standard functionality of InstallShield instead of custom actions.

Labels (1)
0 Kudos
1 Reply

Hi @Pizzamampf ,

There are two ways InstallShield sets the folder permissions. See which one is working for you. 

Custom InstallShield handling—InstallShield adds a custom table and custom actions to your project to set permissions on the target system. This is the default value.
Traditional Windows Installer handling—InstallShield uses the LockPermissions table in the .msi database to store permissions information for your product.

You can find more information in the below links:


If the above options are not working, then you can try SetObjectPermission or icacls through installscript custom action.

0 Kudos