Re: Drive Mapping Script Based on Group Membership Fails Due to LD



Poor word choice on my part. Logon on to the machine and run on the local
machine as the domain authenticated user and see if it works.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Nicholas Whitesel" <nicholas.whitesel@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message news:4AADAB49-59AF-4243-8D6E-1BE29F5709BB@xxxxxxxxxxxxxxxx
The script I am running is located on a network drive with read/excecute
priveleges granted to members of the Domain Users security group.

I am more interested in running the script as a domain user rather than a
local user. I have tried running the script using a raoming profile and a
local profile (both with non-elevated permissions.) I also tried using
the
ADSIEDIT.MSC tool to grant list and read priveleges to the Domain Users
group; however, the only thing that seems to work is adding the user to
the
Domain Admins security group. I must be missing something...

--
Nicholas Whitesel
MIS Support / Help Desk


"Paul Bergson [MVP-DS]" wrote:

The easiest way to test to see if a script can be run as a local user is
once logged on run it locally. I see no special calls in the script you
pointed to that require special rights.

Where is the script located that it is failing in the logon script?

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"wheresITat" <wheresITat@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D2628800-C136-4328-B3AA-DB9AFE0F70C3@xxxxxxxxxxxxxxxx
I recently tried to deploy a logon script using VBScript that uses an
LDAP
query to gain knowledge about the currently logged on user's group
membership. The script then maps drives based on the user's group
membership.

The problem I encountered is that when I try running the script as a
user
who is not a member of the Domain Admins security group, the script
fails.
When logged in as an administrator, the script runs to perfection.

What specific security setting can I change to allow members of the
Domain
Users security group permission to run the script?

Here is the URL of the article containing the script:
http://www.microsoft.com/technet/scriptcenter/resources/qanda/dec04/hey1210.mspx






.



Relevant Pages

  • Re: script interaction
    ... Security Group" and have the script create groups "DL Security Group 1" ... sAMAccountName, especially since the value must be unique in the domain. ... You can use the InputBox function to prompt for a name. ...
    (microsoft.public.scripting.wsh)
  • Re: network problems
    ... You say that the script runs ok when the user is member of the local Administrators security group, assuming yes, sounds that you have a permissions problem when using the logon script, perhaps the script needs to write or read access to some files or reg keys that are NOT available to members of that security group "Power Users" but available to members of the local administrators security group. ... This posting is provided "AS IS" with no warranties, and confers no rights. ...
    (microsoft.public.windows.server.active_directory)
  • Adding users to group
    ... the script will add the security group to the new group. ... That's fine but I really want to add just the members of ... line of csv file and passes info to funciton csvparse ...
    (microsoft.public.windows.server.scripting)
  • Re: Apache error_log
    ... Jason wrote: ... I answered this same thing in the other security group, ... your server up to port 443 will dodge all of it. ... by the person that started the script for some further exploitation. ...
    (comp.security.misc)
  • Re: Migrating Schema Extentions with AD Groups
    ... My guess is that you'll need to script out the custom stuff (potentially via ... the links that are in place between the groups and schema. ... extension and then a security group known in our application as a "role" ... with the AD Schema extension. ...
    (microsoft.public.windows.server.active_directory)