Windows 8 UAC and Server domain issue

Posted on 2013-01-11
Medium Priority
Last Modified: 2013-02-06
I have a problem with Windows 8 UAC.

A client has some golf club related applications on a number of client PCs with the data held in Windows server 2008. When the applications are run they ask to be run as administrator. This has not happened under XP or Windows 7 and the program developers have not changed this aspect of the applications.

The result of this is that in order to run the apps the user has to enter the server administrator user name and password (i.e. Administrator). Clearly not a good idea apart from being a nuisance.

I have tried moving the UAC slider down to the bottom level but since the user is logged on to the server domain UAC greys out the bottom two levels on the slider and says you have to be logged in as an administrator to change to these levels.

I have tried adding the users to the administrator group on the server via Active Directory but this has no effect.

Can anyone think of a way to get round this so as to get the slider down to the bottom but without disabling all the metro type apps (as per a registry tweak I found on the Internet)?

Or some other approach?
Question by:grapey100
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 38766299
Reinstalled the application and install the application in windows 8 with user login.

Author Comment

ID: 38766384
djsharma: Thanks, I did install the application with the server domain user login.

Do you mean with the local PC domain user login?

Expert Comment

ID: 38766573
Try installing the software into another folder you create on the root of the drive, eg c:\golf_apps\xxxxxxx.

Usually programs will need Admin access if they are writing to protected areas on the hard disk, or need to have direct access to hardware attached.
Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

LVL 56

Expert Comment

ID: 38766795

You can adjust that behavior by creating a so-called shim.
The runasinvoker shim is a tiny code applied to the client that only tells it not to request admin rights for that very program and no more. Easy to produce and apply, even domain wide deployment can be scripted. Did this several times in your situation.

PS: You wrote "have tried moving the UAC slider down to the bottom level but since the user is logged on to the server domain UAC greys out the bottom two levels on the slider and says you have to be logged in as an administrator to change to these levels."
That's wrong. Domain membership does not invoke this behavior. We have win8 here domain joined and could adjust that setting. Of course all UAC adjustments are system wide, so you have to be admin anyway, same with win7.

Author Comment

ID: 38785107

Thanks for your suggestion. I tried it and it appeared to work in that the program didn't immediately ask for an administrator level user name and password. Problem was that the program just didn't start!

Re your PS, unfortunately that's what happens. At the lower two levels on the slider it says you have to be signed in as an administrator and the Next button is greyed out.

Not sure where I go next!
LVL 56

Expert Comment

ID: 38785145
Please upload a screenshot of the slider and the message you have quoted.
LVL 56

Expert Comment

ID: 38785157
You could also try to analyse if that program does indeed try to write to protected areas of the registry or file system on launch. Use procmon to monitor that.

Author Comment

ID: 38786181
McKnife - I will get you a screenshot but I am not at client site for a few days.

Accepted Solution

grapey100 earned 0 total points
ID: 38843186
I finally came up with an answer on this - rather embarrassing really! What I didn't do was to add the client user account as an Administrator using Manage User Accounts, within Control Panel. Once I had done this the problem went away! I did this while logged in to the client user account on each PC attached to the server.

Author Closing Comment

ID: 38858678
While this appeared to be a problem caused by the subtle changes to UAC from Windows 7 to Windows 8, it turned out to be a simple step that I should have carried out when setting up or upgrading the PCs to Windows 8.

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
The viewer will learn how to successfully download and install the SARDU utility on Windows 8, without downloading adware.
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…
Suggested Courses

765 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question