RE: local admin vs group policy and apps...

From: Don Gray (don_gray_at_busdk12.com)
Date: 01/16/05

  • Next message: Sergey V. Gordeychik: "RE: local admin vs group policy and apps..."
    Date: Sat, 15 Jan 2005 17:12:49 -0800
    To: <focus-ms@securityfocus.com>
    
    

    Have you figured why these programs need admin rights? I have circumvented
    many apps by adjusting security on:

    Thier program directory ie c:\legapp (users - modify)
    their .ini ie %systemroot%\legapp.ini (users - modify)
    all users application data allusers\application data\legapp (users - modify)
    %systemroot%\legapp (users - modify)

    I have even had to give (users - modify) rights on %systemroot% (this folder
    only) for a paticular app to run correctly, although I feel it makes a nice
    hole for spyware and viri (theese systems are reimaged every summer)

    About the only app I have that I have to give admin rights on is on that has
    to register dll's via an updater utility.

    -----Original Message-----
    From: Stegman, William [mailto:Bill.Stegman@transcore.com]
    Sent: Fri 1/14/2005 12:01 PM
    To: Murad Talukdar
    Cc: focus-ms@securityfocus.com
    Subject: RE: local admin vs group policy and apps...
     
    If you're using Active Directory, gpo's at the ou level could not be
    rescinded by a local admin account. If a normal user logs in with their
    domain account, all the site/domain/ou gpo's relevant to that computer and
    user would apply. The gpo setting, prohibit access to the control panel, is
    only available under the user configuration, and reads that disabling it
    prohibits users from starting the control panel. I've tested this and when
    you try a runas with the local admin account, the control panel does not
    open.

    -----Original Message-----
    From: Murad Talukdar [mailto:talukdar_m@subway.com]
    Sent: Thursday, January 13, 2005 10:11 PM
    To: focus-ms@securityfocus.com
    Subject: local admin vs group policy and apps...

    Hi,
    We have two apps (even calling them legacy seems to attribute some
    undeserved elegance to them) which must run at admin level to function
    properly. I am trying to find out whether the fact that users are allowed to
    be local admins, or even given the runas power to run the app can still be
    locked out of control panel etc through GPOs.

    I mean, if I let people runas then they know the admin password so can
    rescind any GP settings, can't they? How can I shut that possibility out?

    Yes I have asked for the possibility of then apps being recoded to function
    under power users but the development team are of the starving waif variety
    due to under resourcing...this consideration is not high on the list.

    Kind Regards
    Murad Talukdar

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Sergey V. Gordeychik: "RE: local admin vs group policy and apps..."

    Relevant Pages

    • Problems with image on Windows XP - How XP behaves after a Restore
      ... Create TestUser(what I use to run/test all apps) and log in as that user - ... Customize the office settings - once I have all the settings ... Now the problem - when I restore the image to an identical or same machine ... Sometimes when a non admin user logs in and then runs IE the Windows ...
      (microsoft.public.windowsxp.general)
    • RE: How to block users from installing other apps
      ... admin password. ... How to block users from installing other apps ... It's not hard to manipulate permissions for your apps so that these users ... |> SBC Yahoo! ...
      (Focus-Microsoft)
    • Re: RUNAS command
      ... Why do you need to be admin. ... Defending our democracy', ... > This app starts some different apps, which should run all under admin ...
      (microsoft.public.windowsxp.general)
    • Re: Norton Internet Security 2005 Personal Firewall slows down Windows XP startup
      ... I run windows xp pro as admin always, you can't install apps as ... > runs as a User account all the time. ...
      (comp.security.firewalls)
    • Re: Renaming Admin ID - Making Sys Admins Accountable
      ... they then need to be able to administer the server from the console as well ... that power user to do admin tasks because the apps have to always be running. ... > possibly need Domain Admin credentials, I don;t believe they need that. ...
      (microsoft.public.win2000.active_directory)