Re: Windows Server 2003 Auto connect printers;



I removed the NT Authentication but then the user's don't have enough
permission to even login to the TS. What (minimum) rights would be required
then for a normal basic user to login to a TS without having NT
Authentication. Isn't some form of admin rights required for a non admin user
to login to a server?
I am glad we're almost there but now we just have to give the user more
rights in order to login without having NT Authentication.
THanks TP.

Paul


"paul" wrote:

> Thanks so much TP for your help. I'll try this as soon as I can when no users
> are on the TS. I'll let you know.
> Thanks
>
> Paul
>
>
> "TP" wrote:
>
> > That explains it. Users who are Administrators are able to see
> > all printers. "Normal" Users should not be a member of
> > administrators. This is very bad for security and stability of
> > the TS. Administrators can do all sorts of bad things to the
> > TS (intentionally & not), regardless of any group policies or
> > other measures you take to restrict them.
> >
> > In order to fix things you need to remove authenticated users
> > from the Administrators group. Then you are left to get your
> > software applications functioning properly with limited
> > permissions.
> >
> > You do this by granting only those permissions that are
> > absolutely necessary for each application to run. For example,
> > an application typically needs read access to its program
> > directory and registry keys at a minimum. Some applications
> > may need to read/write to their program directory as well as
> > subkeys of their main registry key. Other applications may
> > need you to use per-user class hives, etc.
> >
> > Logon to the server as an administrator and run filemon and
> > regmon from www.sysinternals.com. Then logon as a limited
> > user and run the problem app to see what areas of the file
> > system or registry it is being denied access to.
> >
> > Some applications can be a pain to get working properly
> > with limited permissions, but almost all will work. Others it
> > is a combination of permissions and setting the application's
> > data/save locations to different than default.
> >
> > If you have a specific app that you can't figure out, post
> > here and someone will help you.
> >
> > Thanks.
> >
> > -TP
> >
> > paul wrote:
> > > The Domain Users group is a member of the build in Users, that's it.
> > > Yes the TS is a member server, Authenticated Users is added to the
> > > local Admin group to give users local admin rights. We did this to
> > > solve some software issues. Would this be related to our printer
> > > issue and how? Where could I check again where we set the Permission
> > > Compatibility to?? Thanks for helping out, greatly appreciated.
> > >
> > > Paul
> > >
> >
> >
> >
.



Relevant Pages

  • Re: Security question ..
    ... > If you use NT authentication, a user's permissions to a database are ... Your assertion that a user's permissions are independent of the application ... Even using Access and "exploring" will require an ODBC login to SQL Server. ...
    (microsoft.public.sqlserver.server)
  • Re: You are not authorized to view this page
    ... Download following tool and make sure you have set the permissions and policies correctly as Q812614. ... Authentication and Access Control Diagnostics 1.0: ... This posting is provided "AS IS" with no warranties, and confers no rights. ... the web site has been set to use Anonymous access and Integrated Windows authentication is selected. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Normal user login now logs off immediately [w/o administrator
    ... The login begins in a normal fashion: ... >> problem I happened to give my normal user account administrator rights, ... > Right click on MountedDevices and select "Permissions". ... Thanks for the reply WTC. ...
    (microsoft.public.windowsxp.general)
  • Re: unable to login as oracle user
    ... As I have been looking through log files, this is the only thing "weird" I have found. ... Feb 2 08:22:14 orarac1 login: PAM unable to dlopen ... PAM is the authentication system that comes with all Linux these days. ... The file is there, with permissions 755 root:root. ...
    (RedHat)
  • Re: permissions not working
    ... I imagine that there is some unexpected rights that your user has that you ... I understand that this is a Windows login you are testing. ... have this login as a member?" ... and have created some new roles and assigned permissions to the ...
    (microsoft.public.sqlserver.security)