If you understand the simple method of RunAsAdmin,
it is easy to use this tool very efficient for various purposes
on a single workstation up to a large domain environment.
RunAsAdmin.exe is a graphical interface to install the service of RunAsRob and set the allowed directories into the registry path of RunAsRob.
If a limited user start an application by a shortcut, created from RunAsAdmin, or the user drag an drop the application over RunasRob.exe,
the service of RunAsRob compare its registry setting, if this is an allowed application.
If it is allowed, the service of RunAsRob start it with system account or as administrator, according the logon option you set in the RunAsAdmin interface.
Default read only permissions on microsoft systems, avoid that a limited user manipulate registry settings or files in the default program location.
In collaboration with directory permissions, OUs or Group Policies, RunAsAdmin can be a versatile tool in a big domain.
Launch an application as administrator with system rights from a standard user account.
Run application as administrator from standard user with environment of this limited account.
In screenshot below, i share three central folders software, updates, taxlaw on a network server
and i set appropriate read rights for the specific group >Region admins<, >Users<, and >Accountants<,
and all computer clients in domain by group >Domain Computers<.
On share taxlaw i resctrict the allowed call to computer group > Accountants Computers<.
Finally i authorize on clients this network directories in RunAsAdmin.
Now users of the specific group can run applications from their appropriate folder via RunAsRob with system or administrator account.
Please note following network rules for the understanding
- the local system account is the Active Directory computer object in the domain with the name of the machine.
- that a network share permission of a folder and a permission from a folder are completely separate from each other. You should always configure both access permissions on your shared folder.
Network share permissions on Server, in this screenshot as example of the folder taxlaw
Folder permissions on Server of the shared folders sofware, updates and taxlaw
Finally, authorize network share on client computer in RunAsAdmin
Here you see the registry values of RunAsRob with AllowedPath and LogonFlag, which will be set by RunAsAdmin and checked from RunAsRob, if an application should start via RunAsRob.
You can also edit them by policy or manually.
You can download this RunAsRob Group Policy admx und adml files on RunAsRobPolicy.zip
On Screenshot you see an OU Finance, i assign the PolicyRunAsRob and add the allowed directories >> \\appsrv\software\;\\appsrv\updates\;\\appsrv\taxlaw\ << to computers of this OU.
To differentiate which users or groups of this computers may run applications from this directory i use the folder permissions i described above.
Configure a folder path for a standard user to run applications with local administrator rights from this directory.
By this way you can share a folder in a domain for applications, scripts, updates, patches...
for limited users, which can install software themselves as they become available in this folder.
When required, the domain administrator must only copy the according application file to this folder and inform the user.
You can also specified a local program path, its applications you want to allow to start under administrator rights from a standard user account.
Description:
In video example 1, i authorize limited users to run applications over RunAsRob from system32 directory with system rights.
In video example 2, i authorize limited users to install applications over RunAsRob from a network share.
In video example 3 i will show you how to configure very specific restrictions by an easy way in an enterprise domain.
I authorize a group of limited users to run applications over RunAsRob with administrator rights from a specified network share on computers in a specific department.
For any suggestions, errors, questions, specific requirements or adjustments please contact:
runas@robotronic.net
RunasRob is only free for private use.
For companies and other organisations we deliver a licensed version, registered to the organisation name.
Order RunasRob >>>
Download RunasRob >>>
Date: 2024-08-26
Data protection
Imprint