Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Administration > How to make a "special" administrator in Vista?

Reply
Thread Tools Display Modes

How to make a "special" administrator in Vista?

 
 
Dave R.
Guest
Posts: n/a

 
      01-15-2007
We have some users that need to be able to install printers, change date
/ time, and install new hardware / drivers. In XP, we found workarounds
for the printer and date/time but since only administrators can install
new hardware / drivers we had to relent and give local administrator
accounts to these users.

In Vista, it looks like standard users can install printers and change
date/time, but cannot install new hardware / drivers (not that this is a
bad thing, mind you). Is it possible (and if so, how) in Vista to give
certain users the ability to install new hardware / drivers, but not
have full administrator capabilities, or will we have to relent and give
local administrator accounts to these users under Vista as well?

Regards,

Dave


 
Reply With Quote
 
 
 
 
Jimmy Brush
Guest
Posts: n/a

 
      01-15-2007
Hello,

There's two things you can do in Windows Vista to mitigate this problem.

1) Add pre-trusted drivers to the driver store

Drivers in the driver store can be installed by a standard user.
http://www.vistaclues.com/driver-sta...windows-vista/

2) Allow users to install signed drivers for certain device classes

Through group policy, you can assign users the privilege to install drivers
for specific classes of drivers.

- Open an mmc console (click start, type mmc, press enter)
- Click file -> add/remove snapin
- Add group policy object editor to the list and click ok
- browse to local computer policy -> Computer Configuration ->
Administrative Templates -> System -> Driver Installation
- Double-click "Allow non-administrators to install drivers..."
- Set to enabled and click Show...
- Add the GUID's of the classes of hardware you wish to allow non-admins to
install

To see the list of hardware class GUID's, open up the registry editor
(regedit) and browse to the following location:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class

Each subkey of "class" is a GUID, and if you click on that subkey, the text
in the Default value will tell you the friendly name of the class of
hardware that GUID refers to. To easily copy the GUID to the clipboard, you
can right-click it, click rename, right-click again and click copy, and then
click off of the guid.


--
- JB
Microsoft MVP - Windows Shell/User

Windows Vista Support Faq
http://www.jimmah.com/vista/

 
Reply With Quote
 
Dave R.
Guest
Posts: n/a

 
      01-15-2007

"Jimmy Brush" <> wrote in message
news:46932CBC-C566-4F7C-B53F-...
> Hello,
>
> There's two things you can do in Windows Vista to mitigate this
> problem.
>
> 1) Add pre-trusted drivers to the driver store
>
> Drivers in the driver store can be installed by a standard user.
> http://www.vistaclues.com/driver-sta...windows-vista/
>
> 2) Allow users to install signed drivers for certain device classes
>
> Through group policy, you can assign users the privilege to install
> drivers for specific classes of drivers.
>
> - Open an mmc console (click start, type mmc, press enter)
> - Click file -> add/remove snapin
> - Add group policy object editor to the list and click ok
> - browse to local computer policy -> Computer Configuration ->
> Administrative Templates -> System -> Driver Installation
> - Double-click "Allow non-administrators to install drivers..."
> - Set to enabled and click Show...
> - Add the GUID's of the classes of hardware you wish to allow
> non-admins to install
>
> To see the list of hardware class GUID's, open up the registry editor
> (regedit) and browse to the following location:
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\Class
>
> Each subkey of "class" is a GUID, and if you click on that subkey, the
> text in the Default value will tell you the friendly name of the class
> of hardware that GUID refers to. To easily copy the GUID to the
> clipboard, you can right-click it, click rename, right-click again and
> click copy, and then click off of the guid.
>


Thanks, I'll give that a go and see how it works for us. Just to
clarify, the second method only allows signed drivers, correct?

Best regards,

Dave


 
Reply With Quote
 
Jimmy Brush
Guest
Posts: n/a

 
      01-16-2007
That's correct, signed drivers only.


--
- JB
Microsoft MVP - Windows Shell/User

Windows Vista Support Faq
http://www.jimmah.com/vista/
 
Reply With Quote
 
Freak
Guest
Posts: n/a

 
      01-16-2007
It’s been my finding that you are either an administrator or you are
not. The only thing that "prevents" anyone from doing anything as
an administrator is the warning that pops up and most people ignore it
and continue on. I’m afraid that you will have to give these folks
full access.

Maybe you can set up an administrator’s account that has a generic
name and password (assuming you are on a network) and allow those
persons a certain amount of time to access as an administrator and do
what they have to do and when that time is up, go in and change the
password. Thus, ensuring that they can only access when you are aware
that they are doing so.

"Dave R." wrote:
> We have some users that need to be able to install printers,
> change date
> / time, and install new hardware / drivers. In XP, we found
> workarounds
> for the printer and date/time but since only administrators
> can install
> new hardware / drivers we had to relent and give local
> administrator
> accounts to these users.
>
> In Vista, it looks like standard users can install printers
> and change
> date/time, but cannot install new hardware / drivers (not that
> this is a
> bad thing, mind you). Is it possible (and if so, how) in
> Vista to give
> certain users the ability to install new hardware / drivers,
> but not
> have full administrator capabilities, or will we have to
> relent and give
> local administrator accounts to these users under Vista as
> well?
>
> Regards,
>
> Dave

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Invisible special XP folders like "My Music" and My Videos" in Vista. ceed Windows Vista General Discussion 10 08-14-2007 06:54 PM
"Run as Administrator" ... make default?? bilglas Windows Vista General Discussion 20 07-09-2007 06:16 AM
Special folder "Documents" missing after Vista install. ceed Windows Vista General Discussion 1 06-28-2007 05:15 PM
How to restore the special "Music" and "Pictures" icons. ceed Windows Vista General Discussion 2 12-27-2006 01:29 PM
"special folders" installation option for vista Steven Wabik Windows Vista Installation 0 09-17-2006 03:16 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59