?
Solved

Problem in Programs permission

Posted on 2009-06-28
6
Medium Priority
?
230 Views
Last Modified: 2013-11-25
Dear ,

After restricting the users in my company some programs not working. and sure in this case you need to grant full permission to the same folder of that program. the problem is some of the programs working and some still the same issue.

How i can know to which folders or files i must to grant full permission ?

pls. help urgently..

regards,
0
Comment
Question by:Bilalsharar
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 

Expert Comment

by:Vatharian
ID: 24734214
You have to determine which files are in use by your software. Excellent software to do this is Dependency Walker. (http://www.dependencywalker.com). Point it to executable of a program and let it display list of files used by the program. You don't have to worry about dlls in system folders (like c:/windows), but other like program files\common files, etc. There is some software that requires administrator's rights, but it should be stated in documentation. Most modern software, when it's compatible  with Vista's UAC should run fine without admin rights.
0
 

Author Comment

by:Bilalsharar
ID: 24734446
thanks for your replay

my other issue i am using CACLS script to grant the permissions to the users. now my quistion is if there is any command to let this script to run even if the user already restricted ?
0
 

Expert Comment

by:Vatharian
ID: 24734473
To the CACLS utility there is /e switch, which only edits the permissions, instead the normal rewrite. I'm not sure what do you mean by already restricted user. The restricted user cannot grant him/herself permissions to a file, it must by done by administrator-level user. The /e switch should be enough, if you only want to add i.e. write/execute permissions.
0
 

Author Comment

by:Bilalsharar
ID: 24734564
i am using this command through login script. and this script will run in Restricted-level user.this is what i mean and check below an example of my command script

CACLS C;\folder /E /T /C /G "%username%":F

if this script wiil work if it is runing in ristricted mode ? and how i can do it ?
0
 
LVL 23

Accepted Solution

by:
Mohamed Osama earned 2000 total points
ID: 24741868
I do not believe login scripts will do when run with a limited user credentials, what you need is a machine startup script
as for the dependencies checking, dependency walker should show you only the DLL binary dependencies that are hard coded in your executable, you will still need to find any permissions on register COM+ objects, Data sources ,etc..
for this task use Process monitor aka Procmon
filter only to show your program & look for ACCESS DENIED Messages when run by the limited user profile
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting to know the threat landscape in which DDoS has evolved, and making the right choice to get ourselves geared up to defend against  DDoS attacks effectively. Get the necessary preparation works done and focus on Doing the First Things Right.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …
Suggested Courses

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question