Re: Limited User program permissions



Dave wrote:
I am new to Xp pro. I would like to give a limited user permission to run a program that can write to the directory where the hosts file is. The best I have been able to do is set it up so that the user has to enter the administrator password.

Is there anything I can do to set permissions to allow this program to run without the user needing to enter a password?

Thanks.




You may experience some problems if the software was designed for Win9x/Me, or if it was intended for WinNT/2K/XP, but was improperly designed. Quite simply, the application doesn't "know" how to handle individual user profiles with differing security permissions levels, or the application is designed to make to make changes to "off-limits" sections of the Windows registry or protected Windows system folders.

For example, saved data are often stored in a sub-folder under the application's folder within C:\Program Files - a place where no inexperienced or limited user should ever have write permissions.

It may even be that the software requires "write" access to parts of the registry or protected systems folders/files that are not normally accessible to regular users. (This *won't* occur if the application is properly written.) If this does prove to be the case, however, you're often left with three options: Either grant the necessary users appropriate higher access privileges (either as Power Users or local administrators), explicitly grant normal users elevated privileges to the affected folders and/or part(s) or the registry, or replace the application with one that was properly designed specifically for WinNT/2K/XP.

Some Programs Do Not Work If You Log On from Limited Account
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q307091

Additionally, here are a couple of tips suggested, in a reply to a
different post, by MS-MVP Kent W. England:

"If your game or application works with admin accounts, but not with limited accounts, you can fix it to allow limited users to access the program files folder with "change" capability rather than "read" which is the default.

C:\>cacls "Program Files\appfolder" /e /t /p users:c

where "appfolder" is the folder where the application is installed.

If you wish to undo these changes, then run

C:\>cacls "Program Files\appfolder" /e /t /p users:r

If you still have a problem with running the program or saving settings on limited accounts, you may need to change permissions on the registry keys. Run regedit.exe and go to HKLM\Software\vendor\app, where "vendor\app" is the key that the software vendor used for your specific program. Change the permissions on this key to allow Users full control."


--

Bruce Chambers

Help us help you:
http://dts-l.org/goodpost.htm
http://www.catb.org/~esr/faqs/smart-questions.html

They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety. -Benjamin Franklin

Many people would rather die than think; in fact, most do. -Bertrand Russell
.



Relevant Pages

  • Re: Sharing Programs between users
    ... Quite simply, the application doesn't "know" how to handle individual user profiles with differing security permissions levels, or the application is designed to make to make changes to "off-limits" sections of the Windows registry or protected Windows system folders. ... "If your game or application works with admin accounts, but not with limited accounts, you can fix it to allow limited users to access the program files folder with "change" capability rather than "read" which is the default. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Letting a program run with administrator rights
    ... sections of the Windows registry or protected Windows system folders. ... application's folder within C:\Program Files - a place where no ... inexperienced or limited user should ever have write permissions. ... limited accounts, you can fix it to allow limited users to access the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Adding a program for a limited user
    ... Quite simply, the application doesn't "know" how to handle individual user profiles with differing security permissions levels, or the application is designed to make to make changes to "off-limits" sections of the Windows registry or protected Windows system folders. ... "If your game or application works with admin accounts, but not with limited accounts, you can fix it to allow limited users to access the program files folder with "change" capability rather than "read" which is the default. ...
    (microsoft.public.windowsxp.newusers)
  • Re: cant run pgms as Lowly User
    ... sections of the Windows registry or protected Windows system folders. ... application's folder within C:\Program Files - a place where no ... inexperienced or limited user should ever have write permissions. ... limited accounts, you can fix it to allow limited users to access the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to allow user permissions over system folders
    ... make changes to "off-limits" sections of the registry. ... Start Menu folder and Desktop folder shortcuts from the user profile ... inexperienced or limited user should have write permissions. ... limited accounts, you can fix it to allow limited users to access the ...
    (microsoft.public.windowsxp.security_admin)