Re: Permissions for remote control



Dan,

SMS remote.exe actually does two checks by default -when started without the
/sms:nosql switch remote.exe first tries to connect to the specified SMS
Site in order to check if the user who started remote.exe is allowed to
remote control clients. Therfore the user needs to be a member of the local
SMS Admins group on the SMS site and the user needs appropriate rights in
SMS in order to remote control clients. In case you use the /sms:nosql
switch remote.exe will skip this step.
Next remote.exe tries to connect to the client. The client (wuser32) then
tries to check if the user who tries to establish a remote connection is a
member of the permitted viewers (configured in SMS remote control agent
settings, stored locally in the registry of each client). If the user is a
member of the permitted viewers remote.exe continues - otherwise it displays
a message that you've insufficient rights and you're pormpted to provide
sufficient credentioal in order to use remote control (as example a user
account/password with locak admin rights on the machine you try to control).


--
Regards,

Stefan Geisler
Microsoft Deutschland GmbH

Disclaimer: Die Inhalte der in dieser Newsgroup eingestellten Inhalte
stammen von Dritten. Microsoft kann daher für die Richtigkeit und
Vollständigkeit der Inhalte keine Haftung übernehmen. Bitte beachten Sie,
daß Ihnen an den Inhalten keinerlei Rechte eingeräumt werden (Please note
this is not a direct translation of the English version as a result of
German Law).
Info: Dieser Mail-Account wird nur für Newsgroup Postings genutzt und nicht
auf eingehende Mails geprüft.

"Dan5265" <Dan5265@xxxxxxxxxxxxxxxxxxxxxxxxx> schrieb im Newsbeitrag
news:3F7C19BD-0535-46F8-B16C-6480E1E437A9@xxxxxxxxxxxxxxxx
> Windows 2003 server, with SMS 2003 SP1 and Advanced Clients.
>
> We provide our Help Desk folks a simple batch file which launches
> remote.exe
> (we copy the SMSADMIN folder to their machine) with the following
> parameters..
>
> remote.exe <ip address> \\<site_server_name>\
>
> Can anyone tell me the appropriate permissions to apply on the site server
> which will allow a user to establish a remote control session with a
> client?
>
> Just to let you know where I'm at now, I created an AD group which
> contains
> my test user account, then added this group to Remote Tools Client Agent
> security properties. Interestingly, if I launch the batch file while
> logged
> on with this account I get a "A database could not bet found with the name
> supplied" error message. However, if I use the /sms:nosql switch in place
> of
> \\<site_server_name>\ in the batch file the remote control session
> establishes successfully.
>
> Any pointers are greatly appreciated!


.



Relevant Pages

  • Re: SMS 2.0 remote.exe and XP SP 2
    ... check the SMS ... >database and see if you have rights to remote control ... >>>Client loads automatically on our NT and Win 2000 Pro ... >>>Have to load the client manually on our new Win XP Pro ...
    (microsoft.public.sms.admin)
  • Re: Remote Agent Not Starting
    ... Sounds like your problem are with your MP on your SMS ... server, the client isn't downloading the policy regarding Remote control. ...
    (microsoft.public.sms.tools)
  • Re: SMS 2003 Remote control denied with /SMS:NOSQL parameter
    ... remote.exe tries to establish anonymous connection and get information from the machine. ... > move from a subnet to another: the IP adress is not yet recorded in the SMS ... > database so that remote control is rejected. ... > "to allow direct connection to the client without using data in the SMS site ...
    (microsoft.public.sms.admin)
  • RE: SMS Advanced Client refuses to do its job
    ... [Configuration - Client Properties] ... SMS SMBIOS Serial Number Identifier=43004E0055003700340034003000460050004A00 ... SMS Hardware Identifier=4BE9C601019A00EA ... policy update with 0 assignments" This is correct as there are no adv's for ...
    (microsoft.public.sms.swdist)
  • RE: SMS Advanced Client refuses to do its job
    ... Advanced tab? ... does it have a value for SMS Unique ... SMS client preloaded; you should have run stopped the SMS Client server, ... policy update with 0 assignments" This is correct as there are no adv's for ...
    (microsoft.public.sms.swdist)