Solved

Urgent

Posted on 2007-11-28
8
192 Views
Last Modified: 2013-12-04
Hi all,

I am new to this site an wonder if someone can help me with an issue I have?
We have several applications, over 100, that require Administrative rights to install. I have allowed users to be Power Users, but even with this, they cannot install applications they need. I cannot make them Administrators of their XP Computers. What can I do, to ensure any applications can be installed, without granting higher than Power User access?
Solution ideally would be non AD involved, but if that is the only way then it will do I guess.
Thanks in advance all
0
Comment
Question by:sunilsh2008
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
8 Comments
 
LVL 3

Accepted Solution

by:
top_gizmo earned 500 total points
ID: 20367501
There is no simple answer.  You will not be able to enable users to install software without admin rights.

You can push out software with several AD tools like group policy or SMS.

If you dont have access to these tools, you can still script a solution by installing software as a scheduled task using the local admin account.

Lastly, and I say lastly because it is the least secure.  You can create a wrapper that has admin rights and point it to the software to install.
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 20369121
""""Solution ideally would be non AD involved, but if that is the only way then it will do I guess

That Statement worries me big time! why non AD?
0
 

Author Comment

by:sunilsh2008
ID: 20370566
Sorry, what is a wrapper?
0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 

Author Comment

by:sunilsh2008
ID: 20370571
THANK YOU SO MUCH FOR YOUR HELP, I HAVE FALLEN IN LOVE WITH THIS SITE ALREADY
0
 

Author Comment

by:sunilsh2008
ID: 20370582
Non - AD because this is a tempory solution and we have many applications and few users in compaison. We intend to use AD / SMS for this soon, but was after a woraround before then
0
 
LVL 3

Expert Comment

by:top_gizmo
ID: 20370600
What I mean by a wrapper is to create a script that contains the admin user name and password that runs the install as the admin.

Of course, nothing is absolutely secure.  A vbscript could be easily read by anyone and is not recommended.  There is a scripting solution that is more secure than vbscript, but it to is not fail safe from hackers.  Check out AutoIt at http://www.hiddensoft.com it is a free.  It does take some scripting but has a really great help file.  AutoIt scripts are compiled, and you can encrypt them with a pass phrase so it can not be decompiled without the pass phrase.
0
 

Author Comment

by:sunilsh2008
ID: 20370608
How about psexec? from sysinternals?
0
 
LVL 48

Expert Comment

by:Jay_Jay70
ID: 20370644
psexec is a great option - still manual to a point, but you can run it as a user with the approp rights and fire it off at machines
0

Featured Post

Ransomware: The New Cyber Threat & How to Stop It

This infographic explains ransomware, type of malware that blocks access to your files or your systems and holds them hostage until a ransom is paid. It also examines the different types of ransomware and explains what you can do to thwart this sinister online threat.  

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Let's recap what we learned from yesterday's Skyport Systems webinar.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question