Re: Administrators Account cannot install updates and programs (Administrator can)

From: John7 (NoSp_at_mm.com)
Date: 07/19/05


Date: Tue, 19 Jul 2005 23:18:54 +0200

Steven, thx for responding.

Solved a bad block in his paging file but this did not solve the issue
(could be the source tho).

Checked & OK: his account is member of Administrators (alsway been,
nevertheless verified).
Not yet checked: his account is also member of groups with Deny settings.

Good suggestion. how do I turn on Auditing ?
I think I need to start from there while keeping your other suggestions in
mind.

John7

"Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
news:uO5EfPKjFHA.3348@tk2msftngp13.phx.gbl...
> More than likely the administrator account has a user right or permission
> that the administrators group does not which somebody or something may
have
> modified at one time. You can use Local Security Policy to see the user
> rights assignments. Also his user account could also be a member of a
group
> that has deny permissions/user right. So check the membership of his user
> account to see if it is a member of groups other than
users/administrators.
> It may also help to enable auditing of user privilge for failure in Local
> Security Policy and then look in the securty log via Event Viewer to ses
if
> there are any failues after he tries and fails with his user account.
> SysInternals makes a couple of free tools called filemon and regmon that
> also should help as they will record when access has been denied to a
> registry key or a folder/file when they are being run when this happens. A
> more drastic resort would be to use the secedit command to restore
security
> settings bacl to defualt defined levels as shown in the KB article
> below. --- Steve
>
> http://support.microsoft.com/default.aspx?scid=kb;EN-US;313222
> http://www.sysinternals.com/ --- link to SysInternals
>
> "John7" <NoSp@mm.com> wrote in message
> news:dbirkd$eom$1@news6.zwoll1.ov.home.nl...
> > Hi,
> >
> >
> > A friend has an account (member of group Administrators) but cannot
> > install
> > Windows updates or programs.
> > They abort with message "errors occured, will be terminated, logbook
entry
> > will be created" (no error codes),
> > but logbook has no such entries ? #$^&*
> >
> > The Administrator itself can install updates and programs flawlessly.
> >
> > Any clues how to fix?
> >
> > TIA,
> > John7
> >
> >
> > System: AMD Athlon XP 2400+ 1GB, 120GB, Win2K + SP4 + all updates
> >
> >
>
>



Relevant Pages

  • Re: Default Shares on Member Servers
    ... Are you by chance using an account (i.e. logging into the test-from ... see this if the test to the member is the first thing done after logging ... the local Administrators group contains ... If the C$, etc. are indeed the administrative shares, then the ...
    (microsoft.public.windows.server.security)
  • Re: Error 4957 trying to install SMS_MP_Control_Manager
    ... Running in standard security and the smsservice account is a member of the ... which is of course a member of the Administrators ... Administrators group, I think because we modified the schema for the AD ... This is an SMS 2003 single ...
    (microsoft.public.sms.admin)
  • Re: Help with User Groups (XP Pro)
    ... the Administrators, Power Users, Users groups. ... likely see the account you changed in the groups you expect. ... Then Removed the Administrators. ... > Welcome sign on it shows that the User is a member of an unknown group. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Default Shares on Member Servers
    ... It turns out the password for the local admin account on the member server ... the local Administrators group contains ...
    (microsoft.public.windows.server.security)
  • Re: Does not permit login interactively
    ... administrators listed in the logon locally user right and have the deny logon locally ... If you can logon to a domain member computer as a domain administrator, ... adminpak on that computer from the install cdrom for Windows 2000 Server in the /I386 ... Security Policy to configure logon locally user right to have the administrators ...
    (microsoft.public.win2000.group_policy)