Windows Server 2008 UAC

Discussion in 'Server Security' started by Franz Chernjak, Apr 1, 2009.

  1. hi all,

    we have a problem. A User that is added to the local administrators can use
    second drive D: if the connect over mstsc.

    error: acced denied

    now we check security - all correct (administrators is inherited on drive D)

    now we disable UAC reboot and the user can access drive D:

    Franz Chernjak, Apr 1, 2009
  2. Hello Franz,

    That's UAC by design. UAC will prevent all administrative groups to work
    without using RUNAS. The only account that can work without that is the administrator.
    So you have 2 options disable UAC or live with it.

    For UAC also check this GPO, there are also some others:
    Computer configuration, windows settings, security settings, local policies,
    security options, "User account control: Behavior of the elevation prompt
    for administrators in Admin Approval Mode", choose "Elevate without prompting".

    This will ofcourse lower the security immense.

    Best regards

    Meinolf Weber
    Meinolf Weber [MVP-DS], Apr 1, 2009
