use of compmgmt.msc to create/manage remote shares + ntfs permissions

From: Andy S (smithers_at_altavista.net)
Date: 04/28/05

  • Next message: MAP: "RE: vsmon.exe taking too much processor time"
    Date: 28 Apr 2005 00:39:23 -0700
    
    

    Hi,

    As part of head office security recommendations, we are setting up our
    helpdesk staff to use RUNAS to launch various tasks (e.g. user
    creation) only when they need to carry out those tasks. This allows
    their logon account to be a non-admin.

    A small problem I have encountered with Computer Management
    (compmgmt.msc). It has this great feature to allow the ntfs
    permissions to be set on a remote computer whilst creating a share.
    This is a really useful feature, which works great for me because I'm
    a Domain Admin.

    However, for our helpdesk team, who are NOT members of the local
    administrators group on these remote servers (they are server
    operators however), they are unable to do the ntfs management part. It
    seems to me that this is because compmgmt.msc is using the root $
    shares (C$ etc) to connect on the fly to the remote server, which they
    obviously don't have admin rights to.

    They DO however have full management rights to all the data on these
    remote servers, via non-hidden 'admin' shares that we created for
    them.

    Is there any way to get compmgmt.msc to use other shares than C$/D$
    etc DURING the share creation phase??

    It's a nice to have, I know (they can use explorer via Runas to
    connect to their 'admin' shares after the user share has been
    created), but for streamlining of their processes, it would be good if
    we could modify this behaviour in some way.


  • Next message: MAP: "RE: vsmon.exe taking too much processor time"

    Relevant Pages

    • Re: DC Admin question
      ... If someone needed to manage file shares, I would say, there are these X ... I would prefer no printers on DCs nor even queues, ... enhanced rights to is for some, likely good, reason. ... solutions to the unacceptible obvious one of giving admin. ...
      (microsoft.public.windows.server.security)
    • Re: Accessing SBS 2003 Shares with XP Home
      ... can see in server in network neighborhood. ... I have tried user password and admin password. ... access shares very easily. ... of the Admin account that was assigned to that share. ...
      (microsoft.public.windows.server.sbs)
    • Re: Defautl Hidden Shares
      ... the admin shares do slightly simplify life for that rogue person that must ... It's an even bigger risk if you left the local admin password blank... ... Those only allow access by an admin account. ...
      (microsoft.public.win2000.security)
    • RE: Any way to remove ADMIN$ only?
      ... shares except for ADMIN$. ... modify it under the terms of the GNU GPL, as published by the Free Software ...
      (Focus-Microsoft)
    • Re: IIS IWAM permissions
      ... > rcmd resource kit utility on remote Servers. ... > make IWAM an admin. ... the command fails on the remote servers ... > execute such a task without making him an admin. ...
      (microsoft.public.inetserver.iis.security)