Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
If Windows 11 says “You need permission from TrustedInstaller”, the file is protected by a Windows service identity rather than by an ordinary user account. TrustedInstaller protects system files so that applications and people cannot casually replace them.
You can recover access by changing the owner and, if necessary, granting an administrator account the required NTFS permissions. These are separate operations: changing ownership does not automatically give you Full control.
Use the graphical method for one file or folder. Use takeown and icacls from an elevated terminal when you need to process a directory tree.
Before changing TrustedInstaller permissions
Only do this when you have a specific reason, such as replacing a damaged system file, removing a leftover file, or repairing a folder whose permissions were deliberately changed. Modifying protected Windows files can prevent updates, repairs, applications, or the operating system from working correctly.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Do not apply these instructions casually to C:Windows, C:WindowsWinSxS, or C:Program FilesWindowsApps. WindowsApps is especially sensitive: changing its owner or ACLs can cause Microsoft Store apps, preinstalled apps, and Store games to stop working.
Before proceeding:
- Back up the file or create a restore point where practical.
- Work on the specific file or folder, not its entire parent directory.
- Close any application that may be using the file.
- Remember the original owner and permissions if you intend to restore them later.
Method 1: Change the owner in File Explorer
This method is suitable for a single file or a small folder.
- Right-click the file or folder and select Properties.
- Open the Security tab.
- Select Advanced.
- In Advanced Security Settings, find Owner and select Change.
- In the object-name box, enter:
NT ServiceTrustedInstaller - Select Check Names. Windows should resolve the entry. Select OK.
- If you are changing a folder and want the change to apply to its contents, enable Replace owner on subcontainers and objects. Use this carefully because it affects every item below that folder.
- Select Apply, then OK until all property windows close.
TrustedInstaller may not appear as a normal selectable user named simply “TrustedInstaller.” Entering NT ServiceTrustedInstaller is the important part.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Grant yourself access after changing ownership
If Windows still displays “Access is denied,” that is expected in some cases. The owner and the access-control list (ACL) are different things. The owner can generally change the discretionary ACL, but ownership alone does not necessarily grant Read, Write, Modify, or Delete rights to the interactive user.
- Open the file or folder’s Properties.
- Select Security and then Advanced.
- Select Add, then Select a principal.
- Enter your Windows account name, or the Administrators group, and select Check Names.
- Choose the required permission. For a temporary repair, select Full control only when it is genuinely necessary.
- Apply the entry to the current folder, subfolders, and files only if you need recursive access.
- Select Apply and OK.
Granting Full control is broader than granting Modify or Write. If you only need to edit a file, use the narrowest permission that completes the job.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Method 2: Use Windows Terminal or Command Prompt
For a directory tree, open Windows Terminal (Admin) or Command Prompt (Admin). Search for Terminal in Start, right-click it, and select Run as administrator.
The following commands assume an English-language Windows installation and make the built-in Administrators group the owner. Replace the example path with the exact path to your file or folder.
Take ownership of a folder and its contents
takeown /f "C:PathToFolder" /a /r /d y
icacls "C:PathToFolder" /grant Administrators:F /t /c
What the switches do:
| Switch | Command | Purpose |
|---|---|---|
/f |
takeown |
Specifies the target file or folder. |
/a |
takeown |
Assigns ownership to the Administrators group instead of the currently logged-on user. |
/r |
takeown |
Processes subfolders and files recursively. |
/d y |
takeown |
Answers the conditional directory prompt. This option is used with /r. |
/grant Administrators:F |
icacls |
Grants the Administrators group F, meaning Full access. |
/t |
icacls |
Processes the complete directory tree. |
/c |
icacls |
Continues after individual errors while still reporting them. |
takeown only recovers ownership. It does not automatically give the administrator Full control, which is why the icacls /grant command is separate.
Take ownership of one file
Do not use recursion for a single file:
takeown /f "C:PathToFile.ext" /a
icacls "C:PathToFile.ext" /grant Administrators:F
After the commands complete, try the intended operation again. If the file is still being used, changing its ACL will not make an active process release it.
Restore TrustedInstaller as the owner
After completing the repair, you can restore TrustedInstaller as the owner of a folder and its contents:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
icacls "C:PathToFolder" /setowner "NT SERVICETrustedInstaller" /t /c /q
For one file, omit the recursive options:
icacls "C:PathToFile.ext" /setowner "NT SERVICETrustedInstaller"
This changes ownership only. It does not remove the Full control entry previously granted to Administrators, reset inheritance, or restore every original ACL entry. If you used /grant, review the folder’s Security settings and remove the deliberate extra entry when it is no longer needed.
Do not substitute icacls /reset as a general restoration command. /reset replaces ACLs with default inherited ACLs; /setowner changes the owner. They perform different jobs, and resetting ACLs on a protected Windows directory can create another permissions problem.
Example: restoring ownership of WinSxS
Microsoft’s Windows Update troubleshooting guidance uses this owner syntax for the component store:
icacls "%windir%WinSxS" /setowner "NT SERVICETrustedInstaller" /t /c /q
%windir% normally expands to C:Windows. This command is for a targeted servicing repair, not a general command to run whenever a Windows folder is inaccessible. Avoid manually granting broad permissions to WinSxS unless a documented repair procedure specifically requires it.
Why the commands can report failures
Recursive commands may process thousands of objects and still report errors. Common causes include:
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- A file is locked: Windows, an application, antivirus, or a filter driver may have it open.
- Protected servicing activity: Windows Update or another maintenance task may be using the directory.
- Security software interference: third-party antivirus or endpoint-security filter drivers can block access even after ownership and ACL changes.
- The terminal was not elevated:
takeownand ACL changes require administrator privileges. - The path is wrong: spaces require quotation marks, and a copied path may contain a different filename or drive letter.
The /c option tells icacls to continue after individual errors; it does not make locked files writable. A nonzero “Failed processing” count therefore does not automatically mean that the entire operation failed. Read the individual error lines and identify which objects were affected.
If a particular file is locked, close the related program and try again. For a Windows component, restart and retry after Windows Update has finished. If security software is implicated, follow your organization’s procedure rather than permanently disabling protection.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Check the resulting owner and permissions
To inspect the current ACL from an elevated terminal, run:
icacls "C:PathToFile.ext"
For a folder, this displays the folder’s access entries. In File Explorer, use Properties → Security → Advanced to check both the Owner field and the permission entries. Confirm that:
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →- the intended owner is shown;
- the required account or group has the required permission;
- you did not accidentally apply Full control to an unnecessarily broad directory;
- the TrustedInstaller owner was restored if the change was intended to be temporary.
If the problem is limited to one application or document, repairing that file’s permissions is safer than changing ownership on its parent system folder.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
FAQ
Is TrustedInstaller a normal Windows user account?
Usually not. Windows represents it as the service account NT SERVICETrustedInstaller. Enter that exact name in the owner dialog and select Check Names; it may not appear as a browseable user named simply “TrustedInstaller.”
Does takeown give me full permission?
No. takeown changes ownership. If access remains denied, use an ACL operation such as icacls /grant or add the necessary permission through Advanced Security Settings.
Can I restore TrustedInstaller with icacls /reset?
No. /reset resets ACLs to default inherited permissions, while /setowner changes the owner. To restore the owner, use icacls ... /setowner "NT SERVICETrustedInstaller" and review any permissions you deliberately added.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesWhy does icacls say some files failed?
Files may be locked by Windows, an application, antivirus, or a filter driver. With /c, icacls continues processing other objects and reports the individual failures. Close the program using the file and retry, or investigate the specific error.
Is it safe to change ownership of WindowsApps?
It is high risk. Changing ownership or permissions on C:Program FilesWindowsApps can break Microsoft Store apps, preinstalled apps, and Store games. Use a more targeted repair whenever possible.
The Bottom Line
For the graphical fix, go to Properties → Security → Advanced → Owner → Change and enter NT ServiceTrustedInstaller. If you need to recover access, use an elevated terminal with takeown followed by icacls /grant. Treat ownership, permissions, and restoration as separate steps, and avoid broad changes to Windows system folders unless a documented repair specifically calls for them.
Reference documentation: Microsoft takeown, Microsoft icacls, and Windows access control.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

