Hello,
Thank you for posting in Q&A forum.
Yes, you can create a custom group through Active Directory and configure permissions to allow its members to only install security updates. To achieve this goal, you need to set appropriate permissions in the group policy. You can try the following steps to complete it:
Firstly, create a new security group in Active Directory, such as "SecurityUpdatesOnlyGroup".
Then, use the Group Policy Management Console to create a new Group Policy Object (GPO).
Edit this new GPO, navigate to "Computer Configuration">"Windows Settings">"Security Settings">"Local Policies">"User Rights Allocation".
Find the "Install and Uninstall Programs" permission in the right pane and configure it to only include the "SecurityUpdatesOnlyGroup" group.
Ensure that other permissions (such as "change system time", "shut down system", etc.) are not included in this group to restrict the permissions of group members.
This will ensure that only members of the "Security UpdatesOnlyGroup" group can install security updates and cannot perform other administrator tasks, such as installing. exe files.
Through this approach, you can achieve the goal of only allowing members of specific groups to install security updates. If you need more detailed guidance or have any other questions, please feel free to raise them.
Best regards,
Jill Zhou
If the Answer is helpful, please click "Accept Answer" and upvote it.