Quick answer: ClickOnce applications must use asInvoker for installation. If your application needs administrator privileges at runtime, remove requireAdministrator from the ClickOnce application manifest and launch the application or a separate elevated process with administrator privileges.

This issue occurs when a ClickOnce application requests the requireAdministrator execution level.

1. Change the requested execution level

Open the application’s manifest and change requestedExecutionLevel from requireAdministrator to asInvoker.

Set ClickOnce requestedExecutionLevel to asInvoker

2. Elevate the application only when required

If a feature requires administrator privileges, start a separate elevated process using the Windows runas verb. This allows the ClickOnce application itself to remain compatible with ClickOnce deployment.

private static void AdminLauncher()
{
    if (!IsAdmin())
    {
        var proc = new ProcessStartInfo
        {
            UseShellExecute = true,
            FileName = Application.ExecutablePath,
            Verb = "runas"
        };
        Process.Start(proc);
    }
}

private static bool IsAdmin()
{
    using var identity = WindowsIdentity.GetCurrent();
    var principal = new WindowsPrincipal(identity);
    return principal.IsInRole(WindowsBuiltInRole.Administrator);
}
ClickOnce security settings

ClickOnce supports asInvoker for installation; applications that need elevation should request it separately at runtime.

See more

Visual Studio Marketplace

SSIS Catalog Migration Wizard

Extend Visual Studio with an easy way to migrate SSIS Catalog projects.

Kunal Rathi

With over 15 years of experience in data engineering and analytics, I've assisted countless clients in gaining valuable insights from their data. As a dedicated supporter of Data, Cloud and DevOps, I'm excited to connect with individuals who share my passion for this field. If my work resonates with you, we can talk and collaborate.