Results 1 to 3 of 3

Thread: GPO To Elevate User Rights

  1. #1
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Is it possible to create a GPO that elevates a users rights to Admin so they are allowed to install, and apply updates, to a single program?

    In our current environment, the employee computers are locked down to prevent them from installing unauthorized software. However, we have begun using a new application that requires frequent updates which generates additional help desk calls. So, if I could create a GPO that would allow them to have elevated rights for this application only, then the problem would be resolved.

    Thanks

  2. #2
    Eric is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    112

    Default

    There are a few different options to do this, but none of them are necessarily out of the box solutions.

    First, you can certainly figure out what files and registry keys the updates needs the ability to modify, and then modify the ACLs on all of those files to allow for that. You will most likely also need to grant rights to regsvr32.exe to allow for the registering of addtional .dll files. It's not a pretty solution, but you can change file ACLs with a GPO.

    You can use a freeware tool such as this one to launch the application in the first place, which has the potential to grant the elevated rights you are looking for:

    http://www.joeware.net/freetools/tools/cpau/index.htm

    If you change the shortcut to launch a script which uses this tool to elevate the rights, that might do the trick. Of course, there would be a script with a username and password somewhere on your system/network that someone could find and use.......

    There is also a third party GPO extension from a company called BeyondTrust that will do EXACTLY what you want. You can elevate the rights of a specific process to have administrative rights on a machine so that a user, who doesn't have elevated rights, could update the application.

    BeyondTrust, and other third party group policy solutions can be found here:

    http://www.gpanswers.com/solutions/

    Hope that helps

    Eric

  3. #3
    PreviousPoster is offline 100+ Helpful Posts! 50+ Helpful Posts
    Join Date
    Dec 1969
    Posts
    1,254

    Default

    Thanks for the help. I will look at both and have downloaded the eval version of BeyondTrusts Priviledge Manager

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO