RE: Group Policy denies access to some programs

From: Starks, Brad (BStarks@co.marin.ca.us)
Date: 04/08/02


From: "Starks, Brad" <BStarks@co.marin.ca.us>
To: "'emann@questinc.org'" <emann@questinc.org>, "'comprepsrv@yahoo.com'" <comprepsrv@yahoo.com>, "'focus-ms@securityfocus.com'" <focus-ms@securityfocus.com>
Date: Mon, 8 Apr 2002 14:47:28 -0700 

I've run into this problem from time to time and while the quick fix is to
grant the user local admin rights on the box, that potentially opens up an
entirely new set of problems. We prefer not to use blanket-type solutions
like that (no offense to those that choose to) and prefer to only enable the
needed security where required and no where else.

What I've found is that you can contact the vendor for the affected programs
and they can provide you with the needed rights for each file and directory
both during an install and for running the program post-install. A perfect
example of this scenario involved the Passport emulation software (no
relation to Microsoft's Passport). After
contacting the vendor via email, they provided me with a complete list of
the files and directories accessed and the rights users needed in order to
run the software and after implementing that list, all users were able to
run the program without further incident and did not have to be granted
unneeded administrator rights to the rest of the machine.

Hope that helps,
Brad

-----Original Message-----
From: emann@questinc.org [mailto:emann@questinc.org]
Sent: Monday, April 08, 2002 11:39 AM
To: comprepsrv@yahoo.com; focus-ms@securityfocus.com
Subject: RE: Group Policy denies access to some programs

From my experience, it depends entirely on the program and the way the
installer configuration was setup.

I've ran into programs that installed a bunch of .OCX files into
\winnt\system32 but never ACL'd the files properly and made them
Administrator only, and thus any user that did not have Administrator access
(local or domain) could not run the application. This was entirely an
installer error from what I gathered.

Other programs require registry access to write/modify certain keys. Your
group policies may not account for this and that could be why the
application is not working.

-----Original Message-----
From: comprepsrv@yahoo.com [mailto:comprepsrv@yahoo.com]
Sent: Monday, April 08, 2002 11:15 AM
To: focus-ms@securityfocus.com
Subject: Group Policy denies access to some programs

I have a w2000 server running AD which
authenticates w2000 Prof. clients. I have Group
Policy set up and my users are part of the Domain
Users group. When these users try to access
certain programs they get errors or access denied
errors. I used RUN AS to install and tried installing
under my admin account, placing a shortcut in the
ALL USERS desktop folder. When I run the
programs under Admin, they work fine.

So, how can I free certainm programs to run for the
users that need them?

thanks

dp



Relevant Pages

  • RE: Office tries to repair/reinstall
    ... Giving admin rights to everyone is not the solution. ... The file association issue should be also related to the Office 2007 installation. ... I will check the registry and install windows installer. ...
    (microsoft.public.office.setup)
  • Re: Granting all users Admin Rights
    ... I am a Network Admin for Cuesta College and we are dealing with the same ... Techs to go to install every little piece of software on users computers. ... I believe that giving users Power Users rights is the best way ...
    (microsoft.public.win2000.security)
  • Re: Printer Problems
    ... he had the user rights to disable ... (default install behavior on xp), and it failed because DeskJet needs it ... If you create another admin on that system, you could see the problem again, ... > I manage a small network at a downtown Denver hotel. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Impact of removing administrative rights in an enterprise running XP
    ... You can easily install patches without admin rights... ... WSUS can push out patches and the workstations do not need admin rights. ... Yes, there are success stories, but it's totally dependent on a managed network. ...
    (Focus-Microsoft)
  • Re: Should I still buy SBS 2003 Premium w/ ISA in light of XP SP2s ICF2?
    ... Admin rights is a very simple story. ... relying upon the firewall to block accordingly the access to workstations, ... don't have the same level of packet-filtering in your favor that ISA ...
    (microsoft.public.windows.server.sbs)