Re: User rights assignment in XP Pro

From: Simon Pleasants (plesbit_at_hotmail.com)
Date: 03/11/04


Date: Thu, 11 Mar 2004 16:59:29 +0000

On Thu, 11 Mar 2004 08:16:06 -0800, "matt"
<anonymous@discussions.microsoft.com> wrote:

>I am having similar problems. Not sure if this answer helps you but I know that
>you can add various system rights to users and groups using the Local Security
>Policy console. This is located under Programs...Administrative Tools...Local
>Security Policy. You can add specific rights to a user or group that are not
>default without necessarily making users administrators on a machine. Create
>a new group, add your user to that group and then assign rights to that new
>group using the Local Security Policy console.

Thanks for the response. I have already tried this approach in full.
I am not too worried about, for example, changing the rights of an
individual user group at this stage (although I do know how to do it
should I want to). The problem is more the user groups to which the
users belong.

For example, all users are currently administrators. I want to demote
a specific user to a power user. How do I do it? Simple, in the
computer management console (Control Panel, Admin tools) I select the
user (under "users"), select "properties", the "member of" groups tab,
delete administrators from the list and add power users to it instead.
If you want to check it has worked, go to the groups option and check
the users listed as members in the properties of the power users
group. If the user you just added is listed there, it has worked.

The problem I have, is that XP is ignoring all user groups except
administrator and limited user. Since power users are not
administrators they are treated as limited users, rendering the
account useless. The only alternative I have at present is to set
them back to administrator and this is not acceptable under the
circumstances.

In short, I KNOW how to edit which users belong to which groups, and
even which groups can do what, but I cannot get Windows to recognise
anything except the limited users and administrators. Why not?

>By any chance would you know how to give users rights to manage system processes
>(suspend, kill, enable) without adding a user to the administrator group?

You could create a new group and allocate it the ability to do this
using the local security policy console. You can then assign the
user(s) you want to have this power to have membership of that group
(and cross check it by checking the user account seeing what groups it
is listed as being a member of).

Or so goes the theory - but since I can't get the damn thing to work
at all, it may be that you can't believe a word I said! It would work
in Win2k anyway!

Cheers
Simon



Relevant Pages

  • Re: CD Burner Rights
    ... > What do you do if the CD burning app that you use does not have a tool or ... > executable to assign burning rights to users other than administrators like, ... I would like to assign rights to Power Users. ... You could also assign rights globally to Power Users via the Control ...
    (microsoft.public.win2000.security)
  • Re: Remote Desktop Users and Least User Rights
    ... user accounts (no administrative rights on the local machine). ... have many users that are setup so that they can access their ... from the Administrators group, the list of authorized remote users ... Remote tab> Select Remote Users) gets wiped out. ...
    (microsoft.public.windowsxp.security_admin)
  • local security policy
    ... The local security database (at least the user rights ... After this you want to make sure that the policy is ... >the users group nor the admin group, ...
    (microsoft.public.win2000.security)
  • Broken Admini Rights
    ... It might be an "Ownershiop" problem, rather than an Admin ... HOW TO Take Ownership of a File or Folder in Windows XP: ... to "Administrators group" instead of "Object Creator". ... >Apparently my Admin rights are bent or broken. ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: New Organizational Unit for a new remote office.
    ... This posting is provided "AS IS" with no warranties, and confers no rights. ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... EVERY DOMAIN ADMIN IN THE FOREST ...
    (microsoft.public.win2000.active_directory)