Process Monitor Error – Capture requires Administrators group membership

By | December 9, 2019

This article is to explain the fix for Procmon logs capture issue on Windows operating systems. We had an issue where we were unable to collect Process Monitor (Procmon.exe) logs for the investigation.

It give the error “Capture requires Administrators group membership” even if you run with admin privilege.

Fix for this issue is to give SeLoadDriverPrivilege (Load and unload device drivers) to run this tool. This can be fixed either by not defining the below setting or if already enabled then add the admin group/user in this setting to allow the admins to load and unload drivers.

Leave a Reply

Your email address will not be published. Required fields are marked *