Group Policy (GPO) Scripts run from 2012 domain run as admin/elevated

Hello all!

We are using a a Powershell script that maps a drive. Running the script locally (non-elevated) works perfectly. Running the script using group policy does not work as expected.

I've put the script in User Configuration | Policies | Windows Settings | Scripts | Logon

When running the script from the GPO, the script completes but does not map drives in an accessible manner. No errors come up. Looking in Windows Explorer the mapped drive is not there. However, if I run "net use" from an elevated command prompt I see the drive. For some reason that I can't put my finger on, the script is running with an admin token when running from GPO. It maps the drive, but elevated, so I can't access it without elevating everything.

The script is just a batch file that runs this command:

powershell.exe -NoProfile -ExecutionPolicy bypass -command ScriptName.ps1

The Powershell script runs a net use command (among other things) to map the drive. Again, if it is run locally (without any elevation) the drive maps with no issue, accessible from Windows Explorer, etc.

The script is running on a Win8.1x64 machine on a Windows 2012 AD domain.
robklubsAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Cliff GaliherCommented:
UAC strikes again. Don't use logon scripts. Use group policy preferences instead. It's designed for such things.
0
robklubsAuthor Commented:
Thanks for the comment. Can you point me in the right direction with group policy preferences? I'm not sure what you mean.
0
Cliff GaliherCommented:
Technet has blogs on the subject. They've been around since Vista. They are easy to figure out.
0
Acronis True Image 2019 just released!

Create a reliable backup. Make sure you always have dependable copies of your data so you can restore your entire system or individual files.

robklubsAuthor Commented:
I think you're referring to User Configuration | Preferences | Windows Settings | Drive Maps

If so, I don't think that would work as the Powershell script we run enumerates the path based on information for which the script prompts. It also generates a user specific location with other variables as well for Office365.
0
robklubsAuthor Commented:
Just to be clear, the method provided will not work. It's for predetermined network shares.

Really my question boils down to this - how does one run a script at login via GPO that does not run with an admin token?
0
robklubsAuthor Commented:
You cannot map network drives via powershell via GPO logon script as described. UAC and/or admin token does not allow the drive to be mapped in a usable fashion in Windows Explorer. The exact reason has eluded me. If anyone can shine a light on this I'd love to know the why/how this happens.

However, adding the powershell script (or a batch file calling a powershell script) to the Active Directory | Profile | Logon script WILL allow the script to run as intended. It successfully maps the drive as a "normal" or un-elevated user.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
robklubsAuthor Commented:
No expert solutions were given that were reasonable, found this workaround on my own. Gave plenty of time for experts to chime in - question do not receive all that much attention.
1
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2012

From novice to tech pro — start learning today.