Re: xp pro, granting domain user access to local resources?



geek-y-guy <noone@xxxxxxxxxxx> wrote:
Thanks for the quick reply. This is an older Plustek scanner and I
don't expect the manufacturer will provide any updates for it.

OK - that's the hardware. Do you have to use that *software* for it?

And
yes, the default user account locally has Admin rights, so you
probably nailed it.

You can test this by adding the domain user to the local Administrators
group....

I don't have any issues granting the domain user admin rights on the
workstation, unless it opens up other vulnerabilities beyond them
breaking something <g>.

Ain't that enough for you? Malware infestation can take a long long time to
clean up, as well as cause problems on the network. :-)

Short of that, what would I need to manually edit to grant access? do
you mean granting the domain user appropriate access to specific
folders they'd normally not have access to?

Yep - and registry keys. Do check out the Sysinternals tool. It's a good
thing to know how to use. Log in as the non-admin user, then launch the
Sysinternals tool using RunAs & providing valid local admin credentials.
Play with it a bit.

Thanks again!


"Lanwench [MVP - Exchange]"
<lanwench@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:%23Y0QXjKdIHA.5416@xxxxxxxxxxxxxxxxxxxxxxx
geek-y-guy <noone@xxxxxxxxxxx> wrote:
Hi All: I have an SBS2003 domain with a number of xppro sp2 clients.
All the computers are members of the domain, and I've set up domain
users for each computer.

I have a USB scanner installed on one computer, and when a user logs
on to the local machine, they can access the scanner, but if they
log on using the domain account, they get an error when the scanner
application tries to load the (presumably) USB drivers for the
scanner.
It seems like a local security policy issue, but I can't figure out
what privileges the domain user needs to have the same access the
local account has?

If the scanner is installed already, this is unlikely to be a driver
issue. More likely, the software you're using is expecting the user
to have administrative rights on the workstation in order to run the
app. First, I'd contact the software developer and ask for a workaround
which does *not* involve granting domain users admin rights - this
is sloppy code, and they need to fix it.

If you get nowhere with them, try downloading Process Monitor from
Microsoft (a cool Sysinternals tool) that will help you find out what
areas of the file system & registry the app expects to write to, so
you can manually edit/correct it.



.



Relevant Pages

  • Re: xp pro, granting domain user access to local resources?
    ... default user account locally has Admin rights, ... I don't have any issues granting the domain user admin rights on the ... I have a USB scanner installed on one computer, ...
    (microsoft.public.windowsxp.security_admin)
  • Domain user in local administrator group
    ... If I put the domain user into their xp local administrator group, ... I have users with scanner attach to their pc. ...
    (microsoft.public.win2000.group_policy)
  • Re: NT4->2003 Computer Account Migration Problem
    ... So a win2k3 domain user can join the computer to the win2k3 ... How do you know the computer is not joined to the win2k3 domain? ... I have admin rights to the OU where the computer is located in the AD. ... > add the user or group accounts to the "Add Workstations to the Domain" ...
    (microsoft.public.windows.server.migration)
  • Re: Privileges
    ... You stated that you created both a local user and a domain user and ... My assumption is that this is a Windows XP machine in a Windows 2000 ... What are you checking to see if the user has admin rights? ...
    (microsoft.public.windowsxp.security_admin)
  • local admin rights for domain user on member server ?
    ... local admin rights for domain user on member server? ... I have a windows 2000 domain running AD. ... I need a domain user to have full admin ... local list so I can allocate ADMIN rights to this user. ...
    (microsoft.public.win2000.security)