Solved

DC User 500pt

Posted on 2006-06-20
7
200 Views
Last Modified: 2010-04-18
I have users on my dc.

I loged in 1st time with a user and on his local machine I tried to install software it wouldn't let me install it.

what persmission does this user have to have on the DC?
0
Comment
Question by:intellie_ex
  • 4
  • 3
7 Comments
 
LVL 83

Expert Comment

by:oBdA
ID: 16945406
On the DC? NONE!
If anything, the user needs *LOCAL* administrator rights on "his" workstation (by joining his domain account to the Administrators group on the workstation).
But you should avoid it to give a user these permissions; it's a security hole, unless there is a good reason for the user to have administrative rights.
You usuall can install software when logged on as (domain) administrator, then the user should be able to use the software as well.
0
 

Author Comment

by:intellie_ex
ID: 16945457
So if I log on to the clients machine as dc admin. Install, ms office and any other software I want that user to use. Then I log in as that user, and I'll be able to use ms office, configure outlook and run all the software I just installed as the DC admin?
0
 

Author Comment

by:intellie_ex
ID: 16945507
But you see the problem is that the company uses a program that the local client machines connect to . This program gets updated. So if the server was updated and the user tries to login, it will tell him to update. they click ok and it will auto install the update localy. But with no right it will not. so how do i go around thaT?
0
Highfive + Dolby Voice = No More Audio Complaints!

Poor audio quality is one of the top reasons people don’t use video conferencing. Get the crispest, clearest audio powered by Dolby Voice in every meeting. Highfive and Dolby Voice deliver the best video conferencing and audio experience for every meeting and every room.

 
LVL 83

Accepted Solution

by:
oBdA earned 500 total points
ID: 16945553
Yes, that's how it should be, and is in most cases (Office is no problem at all).
You might stumble over some ancient software or something written by someone still unaware of the fact that operating systems with restricted permissions do exist, which might throw some problems when started by a regular user. These are usually permission problems that can be fixed in most cases.
In a case like that, to find out which permissions are missing where, get FileMon (http://www.sysinternals.com/ntw2k/source/filemon.shtml) and RegMon (http://www.sysinternals.com/ntw2k/source/regmon.shtml) from Sysinternals.
Log on as a regular user without additional rights. Start FileMon and RegMon using runas and an administrative account. Filter both to log only the application.
Start the application, check for errors. Adjust NTFS or registry (using regedt32) permissions until you can run the software as user.
But as I said, most software works okay under a user account.

As for your special program, you need to find out which permissions are needed; either through the company that wrote the software, or through the mechanism described above.
Otherwise, if the program can be updated manually (without the user logging on, by executing a program), you can use a *startup* (not logon) script in a GPO to run the command; this will run with system permissions.
Another possibility is to try to give the user Power User permissions; this should be (more than) enough for an update.

0
 

Author Comment

by:intellie_ex
ID: 16945570
That's another thing. I don't have Power User in my DC.
0
 
LVL 83

Expert Comment

by:oBdA
ID: 16945612
As before: your user do NOT need any additional permissions on the DC; Power Users is a local group on the workstations.
0
 

Author Comment

by:intellie_ex
ID: 16945653
Ok I think i got it. will play around... also if you can help me here

http://www.experts-exchange.com/Databases/Microsoft_SQL_Server/Q_21892599.html
0

Featured Post

IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
Recently, I had the need to build a standalone system to run a point-of-sale system. I’m running this on a low-voltage Atom processor, so I wanted a light-weight operating system, but still needed Windows. I chose to use Microsoft Windows Server 200…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now