During the installation of CA Client Automation an error MSI error - 1625 This installation is forbidden by system policy. Contact your system administrator popup is displayed

Document ID : KB000044015
Last Modified Date : 14/02/2018
Show Technical Document Details


When installing CA Client Automation agents on Windows machines you may receive a MSI error 1625 popup message :

 1625 This installation is forbidden by system policy. Contact your system administrator.



CA Client Automation - All Versions



This issue can be caused because Windows Group Policy or User Account Control (UAC) is blocking administrator access to the install when running CA Client Automation setup.exe  

Note: The CA Client Automation install must be run via a user with Windows Administrator group privileges.



1. Check permissions for the user running the install or try elevating the setup when you start it by right
     clicking the setup.exe from the install media, then selecting "Run as Administrator".

2. Check the Group policy being enforced by doing the following 


Windows 7 or  8 :

  1. Hold down the Windows Key + R to bring up the Run window.
  2. On the Run window, type gpedit.msc, and then click OK.
  3. On the Local Group Policy window, browse to Local Computer Policy, Computer Configuration, Administrative Templates, Windows Components, and then Windows Installer.
  4. Double-click Prohibit non-administrators from applying vendor-signed updates.
  5. Click Disabled, and then click OK.
  6. reboot the computer


3. Check if the Windows installer is Disabled 

  1. On the Run window, type gpedit.msc, and then click OK.
  2. On the Local Group Policy window, browse to Local Computer Policy, Computer Configuration, Administrative Templates,
     Windows Components, and then Windows Installer.
  3. Edit the value Disable Windows Installer and change from enabled to disabled 
  4. Run on a command line type the command  "gpedit /FORCE" 
  5. Logout of the machine and then retry the installation


4. Define a Software restriction policy in local security policy 

1. Open the Control Panel - Control Panel\All Control Panel Items\Administrative Tools\Local Security Policy

2. Browse to Software restriction policies 

3. If none are define select ACTION from top of the screen and select "New Software restriction Policies "

4. Click on Enforcement

5. Select all users except Local administrators  

6. click OK 

7. Reboot the machine 


Additional Information:

For additional information on editing the registry or local Security POlicy please consult Microsoft Support or look over these article