Least Privledge and Browsing Network Share Issues
Windows Vista Forum
Home      Members   Calendar   Who's On
Welcome Guest ( Login | Register )
      



Least Privledge and Browsing Network Share...Expand / Collapse
Author
Message
Posted 2/16/2007 8:26:35 AM
 

Group: Forum Members
Last Login: 2/18/2007 10:54:39 AM
Posts: 2, Visits: 3
the scenario:

Running Vista Business on a domain.  I have two accounts U (user) and DA (domain admin).  the U account is what i use on my local machine and is only a user on the pc.  The DA is a domain admin and inheritly has admin rights to the same computer.

The issue:

I am logged in as the normal U account and trying to access resources (via network browsing) that the U account does not have permissions to BUT the DA does.  So in short, i am trying to do a "run as" to browse with.  has anyone found a way to do this?

So far, this is a huge flaw in microsoft's least priveledge theory.  I know Vista was designed to prompt for adding rights when needed, but i am taking this a step further and refuse to roll out Vista at the office until i do.  I do not want users able to install applications and such at all which minimizes the issues i will have out of the computers in the future.

Thanks to any help anyone can lend.

Post #4378
Posted 2/18/2007 10:55:12 AM
 

Group: Forum Members
Last Login: 2/18/2007 10:54:39 AM
Posts: 2, Visits: 3
bump
Post #4519
Posted 2/19/2007 11:29:24 PM


Administrator

Administrator

Group: Administrators
Last Login: 11/11/2008 9:24:04 PM
Posts: 2,103, Visits: 2,251
What kind of resources are they? Computers? Printers?

AMD64 X2 5200+ 2.60GHz | 3GB DDR 667 | RAID 0 SATA3.0 WD Caviars 320GB total | Foxconn MCP61VM2MA-RS2H Geforce 6100 nforce400 chipset | Vista Ultimate x86
Post #4612
Posted 2/20/2007 2:55:38 PM


Vista Advisor

Vista AdvisorVista AdvisorVista AdvisorVista AdvisorVista AdvisorVista Advisor

Group: Forum Members
Last Login: 4/30/2008 10:14:36 AM
Posts: 156, Visits: 198
Im not sure it can be done, I thought logging onto a local user account only gave access to that machines resources, so a "Run as" would still only be local as there is no way for the account to see the domain due to the fact its not actually connected to the domain. confused? dont worry so am I!

Post #4650
Posted 2/24/2007 8:22:38 PM


Administrator

Administrator

Group: Administrators
Last Login: 11/11/2008 9:24:04 PM
Posts: 2,103, Visits: 2,251
Well it wouldn't make sense to allow users to use "run as admin" it's contradicts the idea of a leaste privileged account. Which is why regular users on the domain cannot use the run as admin?? I'm confused.

AMD64 X2 5200+ 2.60GHz | 3GB DDR 667 | RAID 0 SATA3.0 WD Caviars 320GB total | Foxconn MCP61VM2MA-RS2H Geforce 6100 nforce400 chipset | Vista Ultimate x86
Post #4977
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse
Active Users: 0 (0 guests, 0 members, 0 anonymous members)
No members currently viewing this topic.
Forum Moderators: Jason, blackhat, kingofnexus, Camride, MafiaLord91, WAW8, Walker, MrMagic, PC509, AmericanNightmare

PermissionsExpand / Collapse

All times are GMT -6:00, Time now is 3:55pm

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.109. 9 queries. Compression Enabled.