Re: Tighter security

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 05/14/04


Date: Fri, 14 May 2004 01:32:35 GMT

There is no magic place to look. You could use the Security Configuration and
Analysis tool via mmc snapin to run an analysis against the setup security.inf
template to get an idea how close to default you are. The compatws.inf template
basically changes ntfs and registry permissions to be that of a power user without
the extra rights granted to power user. Another alternative is to roll your own
permissions by using the free tools filemon and regmon form SysInternals to view
where permissions are being denied in the log while invoking those programs via runas
with admin credentials while logged onto the computer as a regular users trying to
run the application. When access denied is found you need to modify permissions to
that file/folder/reg key and try again. -- Steve

http://www.sysinternals.com/ntw2k/source/filemon.shtml
http://www.lokbox.net/SecureXP/secAnalysis.asp

"TJ" <anonymous@discussions.microsoft.com> wrote in message
news:9BF6F125-7D12-4386-8888-85A970339160@microsoft.com...
>
> Currently, everyone on their W2k Pro workstations are set as administrators because
they would not be able to run a couple of their applications. Sloppy programming, I
guess, because these are not old programs.
>
> I'm considering applying the compatws security template because I understand I
could take away their administrator status and return to "user" status and folks
could run those applications.
>
> How can I determine the current security template on any given W2k/XP workstation?
It's most likely the default, but I would like to be able to know the exact status.
>
> Thanks.
>
> TJ



Relevant Pages

  • Re: How do I give an application different privileges than user?
    ... Security) ... > security permissions in the program file or folder properties\security ... > Check those permissions not checked in the resticted user to ... > either an administrator or a power user. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Resetting C-drive permissions w/o damaging data, apps, user pr
    ... I believe the KB article will use a security template that is in the ... You could compare the two security templates with the Security ... switch to change just file permissions. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Regedit Permissions
    ... Double check each child registry key below it when done to make ... sure that change in permissions has propagated to them also. ... new blank security template, then save template] from the compatws.inf ... with the user having power user rights to the desktop. ...
    (microsoft.public.win2000.security)
  • RE: What server hardening are you doing these days?
    ... permissions on their data, and Microsoft encourages ISVs to minimize ... I've been able to discuss ACLs and other security issues in Windows with ... Control or DAC (which is what you're referring to by the "stupid ...
    (Focus-Microsoft)
  • Re: Windows Firewall Wont Stay On
    ... I have come up with a solution that does not disable Security Center, ... By changing the Permissions of that key, ... settings from being changed again. ... the firewall alert settings in Security Center get ...
    (microsoft.public.windowsxp.help_and_support)