Re: File Explorer That Executes In Different User Context

From: Joshua Heslinga (jheslinga@attbi.com)
Date: 06/22/02


From: "Joshua Heslinga" <jheslinga@attbi.com>
Date: Sat, 22 Jun 2002 14:05:36 -0400


Well, yes, you can do what you're suggesting to some extent, but that's the
wrong way to go if your goal is better virus protection, and it will also
cause you far more problems than it will solve (confusion over 2 sets of
accounts, users using accounts that are not stored & managed centrally,
etc.).

My understanding of the reason Windows Explorer won't launch as a different
user is that when you have the Windows desktop up, you're actually running
the explorer process and that that somehow prevents you from running another
instance as a different user. I might be wrong, but I don't think you can do
it.

I know that you can run a command prompt as another user. I haven't tried it
with IE.

If you start something with Run As, it will run with whatever permissions
apply to the account you used to run it-- you don't need to do anything to
make that happen. Keep in mind, however, that Windows is really designed
(IMHO) for everyone to have one account with the permissions they're
supposed to have and the trusts in place to grant cross-domain access-- not
for people to juggle multiple accounts.

If your goal is better virus protection, you need 3 things:
1) Gateway (especially e-mail) virus protection.
2) Virus protection on your file servers.
3) Managed virus protection on your clients.
This will be far more effective and far less of a headache than trying to
jury-rig some sort of scheme where users don't really log on to the network.
Symantec and Network Associates both make products for all 3 of these.

Joshua Heslinga
MCSE, CISSP

"CHANGE username to just westes" <DELETE_westes@uscsw.com> wrote in message
news:ORCmyXbGCHA.2516@tkmsftngp13...
> After being hit by one too many viruses, we are trying to find a way to
make
> Windows more secure than it is.
>
> One idea was to have users login to their computers with a local user
> account (not a domain account), but to then find a way for them to open an
> Explorer window that runs with the context of a domain login account.
>
> I tried this as an experiment by making a shortcut to Explorer on my
> desktop, and then setting the checkbox "Run as Different User". I
started
> this Explorer shortcut, logged in as a domain account, and then found that
> this feature is completely broken. The Explorer that I started this way
> did NOT execute in the context of the user that started it up. I was
> prompted for a userid and password whenever I went to domain shares to
which
> the userid that I authenticated as has access.
>
> Is there any way to:
>
> - Start a file explorer
> - Start a command line shell
> - Start a browser window
>
> all in a context of a different domain user, but then have that user's
> security privileges take effect for the explorer, shell, or browser?
>
> --
> Will
>
> NOTE: To reply, CHANGE the username to westes AT uscsw.com
>
>



Relevant Pages

  • Re: Adding a New User Account with no Internet of E-mail Access
    ... In order to access the Security tab in Windows XP Home Edition ... To start in Safe Mode, reboot your computer and start tapping ... Make sure you logon with an account that is a Computer ... Navigate to the C:\Program Files\Internet Explorer folder. ...
    (microsoft.public.windowsxp.newusers)
  • Re: Denying access to Windows Explorer
    ... If I deny access to explorer.exe for the limited user ... account using gpedit.msc, ... Windows - it just shows the wallpaper and hangs. ... >> Explorer. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Denying access to Windows Explorer
    ... MS-MVP Windows Media Center\Windows Powered Smart Display ... I have successfully created a limited user ... > account for kids, certain relatives, etc. ... > Explorer. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Denying access to Windows Explorer
    ... Explorer is the process that also provides the Windows shell, so restricting it stops the shell from loading. ... Doug Knox, MS-MVP Windows Media Center\Windows Powered Smart Display ... > account using gpedit.msc, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Error in copying files from old HDD My Documents folder?
    ... Your description is somewhat confusing re: which is the permanent C-drive etc., but if you turn off simple file sharing (Tools-Folder Options-View in Windows Explorer) and check Properties-Security-Advanced on \Main User\, you can see who the owner is and what permissions it has. ... When I move files to a new computer, I temporarily make the user account an admin account and use that account to copy over all files so that it is the owner. ... As there is a lot of data rather than burn to DVD and then copy that way I thought I would connect each old HDD one at a time into the new PC and just use Explorer to copy the relevant data. ... I managed to setup the Main User folder as shared and now I can see all the other folders in it but am unable to copy anything because of this error access denied business. ...
    (microsoft.public.windowsxp.general)

Quantcast