Editing User Rights Policies in MMC

From: Kyle (kbfromvt@lycos.com)
Date: 05/13/02

From: "Kyle" <kbfromvt@lycos.com>
Date: Mon, 13 May 2002 06:48:09 -0700

Ok, I've tested the compatws.inf security template but
unfortunately it's not what i'm looking for. After
applying it, users on the test machine are able to run
legacy apps but are also able to install apps. Where as
before applying the template they could NOT run legacy

At this point I dont think any template has what i'm
lookin for. So, my question is this:

Does anyone know which specific policy I can edit so that
the Power Users group is NOT able to install anything but
can run legacy apps?

Any help is GREATLY appreciated. Thanks in advance.

-Kyle B.
D.C.S.E. '01-'02

Relevant Pages

  • Re: User Rights to Legacy Apps
    ... You do not want the comatws template if you do not what to give ... the users Power Users membership, ... is close to the current power users. ... > want my Users to be able to run legacy apps, ...
  • Re: Editing User Rights Policies in MMC
    ... I'm not sure exactly what permission the legacy apps ... are requiring, but taking a wild guess, you could try removing the power ... users permissions in the registry as described above. ... look at the settings in the template under Computer ...
  • Re: Editing User Rights Policies in MMC
    ... use the Security Templates MMC to remove the entry for Power ... Users from the root of the HK_Local_machine hive, then apply that template. ... power users no different from the Users group. ... > legacy apps but are also able to install apps. ...
  • Re: Roll-in a production DB to test with a name change
    ... We have a live machine running our main production DB called "mast" ... We also have a test machine, with a db called mast, ... I'm thinking that before we roll-in the mast2 database: ... Obviously you will need a big-endian template. ...
  • Re: Restrict service access
    ... template which defines ACLs for your services, ... You should try this on a test machine before you try it on any machine that ... > group or "Power User" group) full access or start and stop for couple ... > of services and restrict access for rest of the services. ...