Re: unable to access non-trusted resource by default - why?



You can only use the C$ as an administrator. If the user is trying to access
the other path as a regular user he probably does not have enough rights for
the application which is bad news if it is on a domain controller. I suggest
you try regmon from Microsoft to see if you can determine what registry keys
the user is being denied access to and then tweak registry permissions to
give that user or users needed access. Logon as a regular user and then
start regmon using runas with admin credentials and the log should show what
registry key is causing the problem when you look for deny or failed entries
in the log. You might also try contacting the publisher of the application
about the error you are getting to see if they can advise you OTHER than
making the user an administrator.

Steve

http://www.microsoft.com/technet/sysinternals/utilities/Regmon.mspx ---
regmons filter option can help you track pertinent events

"seeker01" <seeker01@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4AD73C73-8BF7-499D-9996-8197EABF6953@xxxxxxxxxxxxxxxx
Steve,
Thanks for your good feedback. The environment is small, so the current DC
is also the application server. I mapped to \\domain\app as \\domain\user
logon successfully but got this error when clicking the application
""vision
startup wrapper - V utilities Build 7 - could not create registry tree:
computer :192.x.x.x \software\varian\os\systems\varis\71" But this error
will
go away once I mapped to \\192.x.x.x\c$. Checked the share permission is
"Everyone full control" & NTFS permission is "user with read, write &
delete
permission". Hope you know why. thanks.

"Steven L Umbach" wrote:

Sharing the C or any drive drive of a domain controller is a very bad
idea,
particularly when giving a user domain administrator access. It is best
if a
domain controller not do any function other than being a domain
controller.
If that is not possible for some reason then share only the folder that a
user needs access to and then give the user needed access to the shared
folder as a regular domain user and not a domain administrator. If the
user
is trying to access from a non trusted domain the user possibly still can
access if the user uses credentials [user account/password] of a user
account in the domain that access is needed in though the user may need
to
specify user name as domain\user.

Steve


"seeker01" <seeker01@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:499B84F8-110F-4A79-A19E-85D7DAAFECBA@xxxxxxxxxxxxxxxx
hi there,
How I enable a Windows XP Professional user to access a network
application
from a non-trusted Windows 2000 domain controller is bad, so need to
fix
it
ASAP. XP user (from VLAN 1) is a member of a NT4 domain (from VLAN2).
For
it
to work today, first I added W2K application server name (from VLAN3)
to
host
and lmhost.sam files. Then I do map network drive to the Windows 2000
domain
controller C:\ root drive using the server IP address and domain
administrator password. The network access of both VLAN 1 & VLAN 3 are
fully
opened; VLAN1 & VLAN2 are fully opened; no access between VLAN2 &
VLAN3.
Is
there a seamless solution without exposing the root administrator
password?





.



Relevant Pages

  • Re: ASP.NET security issue
    ... In fact everything works fine if an administrator is FIRST to run the ... administrator has to run the app first in order to let the 'regular user' ... >>the internet. ... > first time, without ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Administrator account
    ... Once you have setup a regular user with Admin privileges, the account ... and enter the explicit name Administrator there ... >it won't install. ...
    (microsoft.public.windowsxp.general)
  • Re: Dvorak Online: Killing Linux?
    ... >> machines we have is running XP Home. ... Logged out and tried to run it as a regular user. ... >> run unless it was as administrator. ... No power user in XP Home that I could ...
    (alt.os.linux.suse)
  • Help with junction creation permissions
    ... As an administrator, I am able to mount drive D as a directory on my C ... I would like to extend this ability to a regular user. ... the following NTFS permissions are set on junctions. ... Domain\Administrators: Full Control ...
    (microsoft.public.windowsxp.general)
  • Help with junction creation permissions
    ... As an administrator, I am able to mount drive D as a directory on my C ... I would like to extend this ability to a regular user. ... the following NTFS permissions are set on junctions. ... Domain\Administrators: Full Control ...
    (microsoft.public.windowsxp.security_admin)