Solved

Needing GPO (scripts (logon/logoff)) to run with administrator rights

Posted on 2008-06-13
8
2,941 Views
Last Modified: 2008-06-24
How can I get Group Policy (scripts (logon/logoff)) to run with administrator rights?
0
Comment
Question by:ei00004
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
8 Comments
 
LVL 6

Expert Comment

by:raptorjb007
ID: 21783004
There are four types of scripts that can be configured in GPO.

Computer: Startup & Shutdown
User: Logon & Logoff

Out of these four types, only the user logon script type runs as the user, the other three run as LocalSystem. If LocalSystem rights are not enough, you could incorporate a script that elevates itself using the runas command, however this would be insecure due to the fact that the password would be stored unencrypted in the script, and to run the user would require read access to the script itself thus creating the possibility for users to obtain admin credentials.

What is it you are trying to script that requires admin rights? Perhaps there is a way to accomplish the task with a limited access account.
0
 

Author Comment

by:ei00004
ID: 21783932
Thanks for the explantion, I have changed the script to run as Startup in the GPO, but I'm still not sure it is executing on the client pc. I only need to execute a simple batch file that copies a (.ini) file from a shared folder on the server to a folder on the client PC's C:\ drive. I need to check a few client PC's to verify the file has been copied there.

I also need to run a kixtart script using AdminScriptEditor (ASE) as administrator to change the printers on the client pc's from one print server to another. I know I can use the runas command but I'm not sure of the syntax. I'm not too worried about the local admin password being displayed in clear text because this script will only run for a short time, then the lines of code will be deleted.
0
 
LVL 6

Accepted Solution

by:
raptorjb007 earned 500 total points
ID: 21784037
You can use a vb script to delete the current printer and add the new one. The code is below, and should be able to run with limited rights.

-Source: Microsoft Script repository
http://www.microsoft.com/technet/scriptcenter/scripts/default.mspx?mfr=true

Also, the computer->startup scripts run when the PC boots up, before the logon prompt is displayed. As such it would be hidden from view.

====Begin code to remove a printer connection====
 
Set objNetwork = WScript.CreateObject("WScript.Network")
objNetwork.RemovePrinterConnection "\\PrintServer\xerox3006"
 
 
===end code to remove a printer connection===
 
 
===Begin Code to add a printer connection===
 
Set WshNetwork = CreateObject("WScript.Network")
 
WshNetwork.AddWindowsPrinterConnection "\\PrintServer1\Xerox300"
WshNetwork.SetDefaultPrinter "\\PrintServer1\Xerox300"
 
===End code to add a printer connection===

Open in new window

0
Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

 
LVL 6

Expert Comment

by:raptorjb007
ID: 21824962
Any luck?
0
 

Author Comment

by:ei00004
ID: 21825683
Yes thank you, I was able to create a GPO that allows me to add Domain Users to the local admin group on their local PCs. I accomplished this by creating a new policy, then selecting Edit. Select > Computer Configuration\Windows Settings\Security Settings\Restricted Groups. Right-click Restricted Groups then click Add Group.

Click Browse > select the local computer, then select the group that you want to add to the local Administrators group (in this case, the "Domain\Domain Users" group)  click ADD, and then click OK.


This security rights change also allows me to execute a GPO Logon/Logoff batch file that copies a (.ini) file from a shared folder on the server to a folder on the client PC's C:\ drive.

It also allows the kixtart script to execute properly as administrator and changes the printers on the client pc's from one print server to another.

I know this is not the best secure way because all users are now local admins on all PCs, however this is temporarily running just long enough for the changes to be pushed out. I then can use the GPOs > Computer Configuration > Windows Settings > Security Settings > File System option to change file/folder perms to allow the Domain Users group modify permissions.
0
 

Author Comment

by:ei00004
ID: 21830978
This has been resolved, thanks for your help.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question