?
Solved

Group Policy Administrator approved programs VISTA

Posted on 2007-11-20
7
Medium Priority
?
1,078 Views
Last Modified: 2008-05-31
Is there a Group Policy that I can set that will allow a standard user on Vista to run an approved program as an administrator without any prompts for security elevation?

Thanks
0
Comment
Question by:Mikal613
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
7 Comments
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 20321564
There sure is and it's explained here:  http://technet2.microsoft.com/WindowsVista/en/library/00d04415-2b2f-422c-b70e-b18ff918c2811033.mspx#BKMK_AdminUAC

Essentially you want to have the program "Run as Administrator" all the time.

Jeff
TechSoEasy
0
 
LVL 48

Author Comment

by:Mikal613
ID: 20321622
Ok I read that article many times. Where does it say that From Windows Server 2003 (Active Directory) I can set a group policy that A Vista machine running as a standard user can run a specific program as an administrator without any interaction or knowledge from the standard user.

thank you
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 20321785
In the section titled:  "Administering UAC with the local Security Policy Editor and Group Policy"

Jeff
TechSoEasy
0
NEW Veeam Agent for Microsoft Windows

Backup and recover physical and cloud-based servers and workstations, as well as endpoint devices that belong to remote users. Avoid downtime and data loss quickly and easily for Windows-based physical or public cloud-based workloads!

 
LVL 48

Author Comment

by:Mikal613
ID: 20321807
0
 
LVL 74

Expert Comment

by:Jeffrey Kane - TechSoEasy
ID: 20323456
Since Vista no longer uses .adm files for it's Group Policy settings (it uses .admx) you need to configure this from a Vista machine.  You can load the Domain Group Policy Management Console on one of the Vista machines and configure the domain's policies from there.

Jeff
TechSoEasy
0
 
LVL 48

Author Comment

by:Mikal613
ID: 20323471
I cant have any modification from a Vista machine. I need a straight up solution from Server 2003 if there is any. If not then i guess the answer is no.

Thanks
0
 
LVL 74

Accepted Solution

by:
Jeffrey Kane - TechSoEasy earned 1500 total points
ID: 20323649
You don't understand what I'm saying.   Group Policy Object Editor on Windows Server 2003, Windows XP, or Windows 2000 machines will not display new Windows Vista Administrative Template policy settings that may be enabled or disabled within a GPO.

You don't have to go to every Vista machine to do this, but you need to run the Domain's Group Policy Manager from one of them to configure the policies.  

You can read more about this here:  http://technet2.microsoft.com/WindowsVista/en/library/02633470-396c-4e34-971a-0c5b090dc4fd1033.mspx?mfr=true

So, the answer isn't "NO", it's just slightly different than you are perceiving it should be.

Jeff
TechSoEasy
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question