How do I restrict access to REGEDIT to regular User?

Page 3 of 4 FirstFirst 1234 LastLast

  1. Posts : 5,478
    2004
       #21

    Standard users don't have full access to regedit.

    They can change things in the current user (i.e. their user) hive but not other hives (local machine etc) as they aren't authorized.
      My Computer


  2. Posts : 5,899
    Win 11 Pro (x64) 22H2
       #22

    Yes, the changes would (should) only apply to the local account but I'm guessing the OP doesn't want those changed as well.
      My Computers


  3. Posts : 419
    Win 7 Pro/32, Win 10 Pro/64/32
       #23

    To prevent unauthorized persons from running certain programs, just change the name of the program.
    I've used that many times in the past, even on my Commodore 64. :)

    Cheers Mates!
    TechnoMage

    PS: To change a file's name, you will probably have to "Take Ownership" of that file.
    The program "Grant Admin Full Control" will do that for you. It's FREE!
      My Computer


  4. Posts : 36
    Win 10 Pro
    Thread Starter
       #24

    So nobody knows why Windows 10 is allowing for a regular user account to have access to the registry?
    I mean, this was not the case in previous Windows OS..access to the registry has always been Admin access ONLY.
      My Computer


  5. Posts : 1,345
    Windows 10 Pro 64-bit
       #25

    macster2075 said:
    So nobody knows why Windows 10 is allowing for a regular user account to have access to the registry?
    --- If we could call on the MSFT gods, I'm sure they know but I doubt they'd let us know.
    I mean, this was not the case in previous Windows OS..access to the registry has always been Admin access ONLY.
    --- I believe you are correct but I don't know which was the last version it worked that way.
    According to this article "Running commands like Regedit as a standard user"
    Running commands like Regedit as a standard user
    it states "I can view and change values under "Current User", but only can view values under "Local Machine" (cannot change)."
    --- Although it's for Windows 7, test it out on your Windows 10.
    --- Look for values in hives other than Local Machine and see if that statement is true.
    --- Determine whether or not viewing and changing values are only possible under Current User.
    BTW, Ix07 & sygnus21 have mentioned those items (maybe also others on previous pages but I don't know how to go back to double-check while posting this information).
    --- So hopefully a standard user really is has limited capabilities
    --- If you do evaluate what that article points out, please let us know what you find out.

    EDIT: I just created a local account and the statement "it states "I can view and change values under "Current User", but only can view values under "Local Machine" (cannot change)." appears to be true. I really didn't want to make changes since I don't know what I would want to experiment with on what to change.
    --- However, the ability to change values under "Current User" makes sense
    --- Delving into Local Machine brought "xxx cannot be opened" which amounts to being unable to make changes.
    Checking the remaining hives, it appears to be able to modify some of the folder contents but I wasn't about to play with any of them.
    --- If you find something in the remaining hives to modify an entry your way: please let us know how it goes.
    Last edited by MeAndMyComputer; 13 Jul 2017 at 20:17.
      My Computer


  6. Posts : 3,257
    Windows 10 Pro
       #26

    macster2075 said:
    So nobody knows why Windows 10 is allowing for a regular user account to have access to the registry?
    I mean, this was not the case in previous Windows OS..access to the registry has always been Admin access ONLY.
    Correct, nobody knows why it's doing that... because it doesn't. I promise you, your normal users do not have full access to regedit. They can only edit the HKEY_CURRENT_USER hive. They cannot edit HKEY_LOCAL_MACHINE hive.
      My Computer


  7. Posts : 12
    Windows 10 Pro for Workstations v21H2
       #27

    macster2075 said:
    My problem is that if I log into the regular user account.. I can go straight into regedit without any prompts at all and it has full access.. however, if I try to access gpedit.msc, I am prompted to enter admin password.
    Thank you.
    Although this is an old post, there is a definite need for this solution in regards to Parental Controls.

    I should point out that although a Standard User can open the Registry Editor by default, they DO NOT have full access. They can make changes that they normally could using the GUI. For example, try accessing the HKEY_LOCAL_MACHINE and you'll find yourself being denied access.

    Aside from setting up my eldest sons profile as a Standard User and setting up the Family Group in order to leverage the limited parental controls Microsoft currently is capable of for Windows 10, I disabled the Registry Editor as well to thwart any attempts to bypass my restrictions. https://account.microsoft.com/family/about

    How to disable the Registry Editor in Windows 10?

    Assuming you have an Admin account or the built-in Administrator enabled and password protected [highly recommended]...

    The easiest way is using the Local Group Policy Editor.


    1. Sign in using the Standard Account you wish to restrict
    2. Press the Windows logo key (or click the Start button) and type gpedit.msc
    3. Right-click on gpedit.msc and select Run as administrator
      • Enter your Admin credentials when prompted

    4. Navigate to and select Local Computer Policy > User Configuration > Administrative Templates > System
    5. in the right pane, double-click on Prevent access to registry editing tools
      • Click the Enabled radio button
      • Verify under Options that the drop-down has Yes selected and then click OK

    6. Press the Windows logo key (or click the Start button) and type reg
      • Click Registry Editor from the search results and you should be presented with a message indicating the "Registry editing has been disabled by your administrator".
      • Now you can close the Local Group Policy Editor and log off of the Standard User account.


    When you need to manage the Registry under the Standard User account, you need only run it as an administrator like you would anything else.

    Keep an eye out for any related issues that might occur under normal User related usage. If you identify that the User cannot make User related changes, this may be due to this policy restriction. It's a good idea to test it out by making some simple changes like display settings, folder viewing options and so forth.
    Last edited by zero269; 01 May 2020 at 19:58. Reason: Spelling, grammar and added content...
      My Computer


  8. Posts : 16,946
    Windows 10 Home x64 Version 22H2 Build 19045.4170
       #28

    zero,

    All discussion is worthwhile but -

    zero269 said:
    How to disable the Registry Editor in Windows 10?
    Your procedure only applies to Windows 10 Pro

    zero269 said:
    ...or the built-in Administrator enabled and password protected [highly recommended]...
    No, enabling the BuiltIn Admin account is not highly recommended but should only be done when necessary and never when connected to the internet.
    No, password protecting, or making any other changes to, the BuiltIn Admin account is not highly recommended

    Denis
    Last edited by Try3; 02 May 2020 at 07:42.
      My Computer


  9. Posts : 5,048
    Windows 10/11 Pro x64, Various Linux Builds, Networking, Storage, Cybersecurity Specialty.
       #29
      My Computer


  10. Posts : 1,680
    X
       #30

    Disabling regedit is easy.

    Delete the regedit.exe file.
    Keep a copy of regedit on your keychain thumb drive.

    You have it, but other users don't.
    Users smart enough to have their own copy on a thumb drive can evade this scheme ... but they'd evade the other suggestions too. So?
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:14.
Find Us




Windows 10 Forums