Vista to allow ActiveX installation

Microsoft is to give Windows Vista an option for users to install ActiveX controls without the need for administrator approval, the company has revealed.

The move is in response to beta tests, which found that administrators had a hard time keeping up with updates to ActiveX controls, Microsoft said.

User Account Control (UAC), a feature to be introduced in Vista, places strict limits on standard users, including barring them from installing ActiveX controls without authorization from an administrator.

The feature's constant prompts for authentication have been heavily criticized by industry observers.

Chris Corio, a UAC program manager, said specifically that companies involved in the Technical Adoption Program (TAP) testing Vista had problems with numerous ActiveX controls used in day-to-day business.

Because users couldn't install the control updates themselves, administrators were being overloaded, he said.

"These ActiveX controls were being updated regularly, and the corporations couldn't package and deploy them to their users quickly enough," Corio said in a document describing the upcoming feature, on Microsoft's MSDN developer Web site.

The solution Microsoft is proposing is called the ActiveX Installer Service, consisting of a Windows service, a Group Policy administrative template, and a few changes in IE, according to Corio. The aim is to allow administrators to define group policies establishing URLs from which standard users can install ActiveX controls.

The feature will be an optional component with the Ultimate, Business and Enterprise versions of Vista, Microsoft said, and will only be enabled on clients where it is installed.

If the feature is enabled, and IE encounters a needed ActiveX control or update, the browser asks the service to carry out installation. The service checks to see if the control's host URL is defined, allowed and listed in group policy.

If it is, the service creates an installer object. If group policy doesn't specify that the control is allowed, Vista reverts to its default behavior, which is to ask for authentication, according to Corio.

So far, the service works with controls packaged as .cab, .dll or .ocx files, but Microsoft plans to enable MSI (Microsoft Installation) packages as well.

Microsoft demonstrated the service at last week's TechEd developer conference, and Ben Fathi demonstrated it as part of his security keynote there, the company said.

The feature will be included in Vista's the next public release, Release Candidate 1, according to Microsoft.

Not all administrators are thrilled with the idea of allowing constant updates of ActiveX controls. One administrator, writing on a MSDN discussion board, said developers shouldn't feel free to release buggy software and then release often disruptive fixes on a regular basis.

"Isn't this just a new excuse for the designers of said ActiveX controls to keep on releasing patches without thought of testing them before the fact?" he wrote. "The last thing I want to learn is that someone's falsified WebEx's certificate and is pushing malware under my nose. Or that WebEx released an update with a bug that results in privilege escalation."

Another admin commented that the feature is probably "a necessary evil."

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Matthew Broersma
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender’s best-in-class security solutions have been awarded Product of the Year. Get cybersecurity that 500 MILLION users already have and trust!

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?