Windows 8 UAC and Server domain issue

Posted on 2013-01-11
Last Modified: 2013-02-06
I have a problem with Windows 8 UAC.

A client has some golf club related applications on a number of client PCs with the data held in Windows server 2008. When the applications are run they ask to be run as administrator. This has not happened under XP or Windows 7 and the program developers have not changed this aspect of the applications.

The result of this is that in order to run the apps the user has to enter the server administrator user name and password (i.e. Administrator). Clearly not a good idea apart from being a nuisance.

I have tried moving the UAC slider down to the bottom level but since the user is logged on to the server domain UAC greys out the bottom two levels on the slider and says you have to be logged in as an administrator to change to these levels.

I have tried adding the users to the administrator group on the server via Active Directory but this has no effect.

Can anyone think of a way to get round this so as to get the slider down to the bottom but without disabling all the metro type apps (as per a registry tweak I found on the Internet)?

Or some other approach?
Question by:grapey100
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions

Expert Comment

ID: 38766299
Reinstalled the application and install the application in windows 8 with user login.

Author Comment

ID: 38766384
djsharma: Thanks, I did install the application with the server domain user login.

Do you mean with the local PC domain user login?

Expert Comment

ID: 38766573
Try installing the software into another folder you create on the root of the drive, eg c:\golf_apps\xxxxxxx.

Usually programs will need Admin access if they are writing to protected areas on the hard disk, or need to have direct access to hardware attached.
Transaction Monitoring Vs. Real User Monitoring

Synthetic Transaction Monitoring Vs. Real User Monitoring: When To Use Each Approach? In this article, we will discuss two major monitoring approaches: Synthetic Transaction and Real User Monitoring.

LVL 55

Expert Comment

ID: 38766795

You can adjust that behavior by creating a so-called shim.
The runasinvoker shim is a tiny code applied to the client that only tells it not to request admin rights for that very program and no more. Easy to produce and apply, even domain wide deployment can be scripted. Did this several times in your situation.

PS: You wrote "have tried moving the UAC slider down to the bottom level but since the user is logged on to the server domain UAC greys out the bottom two levels on the slider and says you have to be logged in as an administrator to change to these levels."
That's wrong. Domain membership does not invoke this behavior. We have win8 here domain joined and could adjust that setting. Of course all UAC adjustments are system wide, so you have to be admin anyway, same with win7.

Author Comment

ID: 38785107

Thanks for your suggestion. I tried it and it appeared to work in that the program didn't immediately ask for an administrator level user name and password. Problem was that the program just didn't start!

Re your PS, unfortunately that's what happens. At the lower two levels on the slider it says you have to be signed in as an administrator and the Next button is greyed out.

Not sure where I go next!
LVL 55

Expert Comment

ID: 38785145
Please upload a screenshot of the slider and the message you have quoted.
LVL 55

Expert Comment

ID: 38785157
You could also try to analyse if that program does indeed try to write to protected areas of the registry or file system on launch. Use procmon to monitor that.

Author Comment

ID: 38786181
McKnife - I will get you a screenshot but I am not at client site for a few days.

Accepted Solution

grapey100 earned 0 total points
ID: 38843186
I finally came up with an answer on this - rather embarrassing really! What I didn't do was to add the client user account as an Administrator using Manage User Accounts, within Control Panel. Once I had done this the problem went away! I did this while logged in to the client user account on each PC attached to the server.

Author Closing Comment

ID: 38858678
While this appeared to be a problem caused by the subtle changes to UAC from Windows 7 to Windows 8, it turned out to be a simple step that I should have carried out when setting up or upgrading the PCs to Windows 8.

Featured Post

Major Incident Management Communications

Major incidents and IT service outages cost companies millions. Often the solution to minimizing damage is automated communication. Find out more in our Major Incident Management Communications infographic.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question