Solved

How do you run a program which needs a higher permissions level when you dont wish to raise the overall permissions level for the user?

Posted on 2003-11-13
5
188 Views
Last Modified: 2010-04-13
This machine is not on a 2000 domain
using local security on a 2000 workstation,
I have a user who belongs to the "user" group
I dont wish to raise their permission level to "power user"
i have a program which needs to be run on the "power user" level.
how can i assign permissions to that program to run at a higher level level?
or
can i run the program as another user without having a password prompt?
or
is there a way i can enable registry changes in the local policy editor snap in in the mmc?
or
can i create a custom group with the permissions i need?
0
Comment
Question by:oweesta
5 Comments
 
LVL 4

Expert Comment

by:darth_wannabe
ID: 9741688
psexec might help you out http://www.sysinternals.com/ntw2k/freeware/pstools.shtml

also maybe RUNAS, although I think you get prompted for the password

RUNAS USAGE:

RUNAS [/profile] [/env] [/netonly] /user:<UserName> program

   /profile        if the user's profile needs to be loaded
   /env            to use current environment instead of user's.
   /netonly        use if the credentials specified are for remote access only.
   /user           <UserName> should be in form USER@DOMAIN or DOMAIN\USER
   program         command line for EXE.  See below for examples

Examples:
> runas /profile /user:mymachine\administrator cmd
> runas /profile /env /user:mydomain\admin "mmc %windir%\system32\dsa.msc"
> runas /env /user:user@domain.microsoft.com "notepad \"my file.txt\""

NOTE:  Enter user's password only when prompted.
NOTE:  USER@DOMAIN is not compatible with /netonly.
0
 
LVL 83

Accepted Solution

by:
oBdA earned 125 total points
ID: 9741959
Find out which permissions are missing.
Turn on auditing on your machine (local security policy -- auditing policy: turn on auditing for rights usage and object access).
Then enable auditing on the usual suspicious folders (using Windows Explorer, folder properties/Security/Advanced/Auditing): The program folder of the program, %AllUsersProfile%, and %CommonProgramFiles%.
Turn on auditing as well for HKLM\Software (using regedt32).
(Do I need to mention that you only need to audit failures?)
Log on as the user you're auditing; use runas.exe to start the event log (runas /user:administrator "mmc eventvwr.msc"), then start the program.
Look in the security event log for access violations and adjust the necessary rights until the program can be run by the user. (Note: some of the violations there are "normal" and can be ignored. Look especially at the ones related somehow to the program in question.)
It's sort of a tedious job, but you'll soon gt the hang of it ...
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
An analysis of the phishing scam that has been affecting Google users, along with steps to take for protection, as well as what to do if you receive one of the emails.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now