Windows Server 2008 UAC

Discussion in 'Server Security' started by Franz Chernjak, Apr 1, 2009.

  1. hi all,

    we have a problem. A User that is added to the local administrators can use
    second drive D: if the connect over mstsc.

    error: acced denied

    now we check security - all correct (administrators is inherited on drive D)

    now we disable UAC reboot and the user can access drive D:

    why
     
    Franz Chernjak, Apr 1, 2009
    #1
    1. Advertisements

  2. Hello Franz,

    That's UAC by design. UAC will prevent all administrative groups to work
    without using RUNAS. The only account that can work without that is the administrator.
    So you have 2 options disable UAC or live with it.

    For UAC also check this GPO, there are also some others:
    Computer configuration, windows settings, security settings, local policies,
    security options, "User account control: Behavior of the elevation prompt
    for administrators in Admin Approval Mode", choose "Elevate without prompting".

    This will ofcourse lower the security immense.



    Best regards

    Meinolf Weber
     
    Meinolf Weber [MVP-DS], Apr 1, 2009
    #2
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.