Administrators Group Access to All things without any prompting


i have windows server 2008 r2 hosts websites. have 2 user:

1-user1 can connect remotely , run batch files create dns records ,create new  website and....

2-user2 can connect remotely , update our websites application (replace files , execute scripts)....

i need control users actions via event viewer create user name per each user(2 user name) in administrators group.

but have problem when users use batch files or application execute actions(like replacing files),the action blocked uac,because prompt not appear.if manually action prompt appears , if click "continue" button file replaced.

by disabling uac problem solved need secure solution.

any idea?

you can try rightclicking program , on compatibility tab, there button - run elevated. bring uac popup each time starts program.

on other hand, disable uac @ all. local measure prevent "unreliable" or "stupid" powerful admins doing harm. if guys responsible , not browsing odd web pages or downloading content not relevant job on web servers, wouldn't hesitate disabling uac. rather consider not allowing them being in local administrators. may there way how allow them job without letting them being local amdins.

ondrej.

 



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS