Solved

Kixtart Script Runas Administrator

Posted on 2008-06-12
2
3,219 Views
Last Modified: 2011-04-19
In a Windows 2003 Active Directory environment, how can I get my kixstart script to runas administrator or user with admin rights when executing on client pc's?
See attached Code Snippet.
The "Call" statement below will run a subroutine that changes the location of the client workstation printer to a different print server. I need this script to run on client pc as a user with admin rights.	

;=====================================================================

	; Change default print server if needed.

		If (InGroup(Finance)) = 1 Or (InGroup(IS_Staff)) = 1

	  		Call "@lserver\netlogon\Print_server.scr"

		EndIf

	;=====================================================================

Open in new window

0
Comment
Question by:ei00004
2 Comments
 
LVL 15

Assisted Solution

by:Raisor
Raisor earned 200 total points
ID: 21779675
Hi,

The only secure way to do what you're up to is using the AdminScriptEditor at: http://www.adminscripteditor.com/editor/scriptpackager/

... everything else will force you to leave passwords at maybe unsecure places!


Best regards,
Raisor
0
 

Accepted Solution

by:
ei00004 earned 0 total points
ID: 21901919
Thanks, I was able to create a GPO that allows me to add Domain Users to the local admin group on their local PCs. I accomplished this by creating a new policy, then selecting Edit. Select > Computer Configuration\Windows Settings\Security Settings\Restricted Groups. Right-click Restricted Groups then click Add Group.

Click Browse > select the local computer, then select the group that you want to add to the local Administrators group (in this case, the "Domain\Domain Users" group)  click ADD, and then click OK.

This security rights change also allows me to execute a GPO Logon/Logoff batch file that copies a (.ini) file from a shared folder on the server to a folder on the client PC's C:\ drive.

It also allows the kixtart script to execute properly as administrator and changes the printers on the client pc's from one print server to another.

I know this is not the best secure way because all users are now local admins on all PCs, however this is temporarily running just long enough for the changes to be pushed out. I then can use the GPOs > Computer Configuration > Windows Settings > Security Settings > File System option to change file/folder perms to allow the Domain Users group modify permissions.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A short article about a problem I had getting the GPS LocationListener working.
If you’re thinking to yourself “That description sounds a lot like two people doing the work that one could accomplish,” you’re not alone.
Viewers will learn how to properly install Eclipse with the necessary JDK, and will take a look at an introductory Java program. Download Eclipse installation zip file: Extract files from zip file: Download and install JDK 8: Open Eclipse and …
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

943 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

3 Experts available now in Live!

Get 1:1 Help Now