A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Security and Administration with Windows XP
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

SRP and Run As...



 
 
Thread Tools Display Modes
  #1  
Old January 6th 08, 12:14 AM posted to microsoft.public.windowsxp.security_admin
Sunny[_2_]
external usenet poster
 
Posts: 2
Default SRP and Run As...

Is it possible to configure XP Pro SP2 such that RunAs privileges are
applied before Software Restriction Policy is evaluated?

Take the example of an executable stored in c:\temp. Software
Restriction Policy prevents execution of anything in c:\temp by ordinary
users, but is not enforced for local administrators.

SRP works as expected for the primary logon - local admins can execute
programs from c:\temp, ordinary users cannot - however RunAs does not
permit running programs from c:\temp as admin while logged in as an
ordinary user. The system issues the "Blocked by SRP" error before it
even checks the admin account credentials provided (you still get an SRP
error if you supply a bad admin password).

It seems to me XP is doing things backward here - I can get around it by
using RunAs to start a command prompt, then executing programs from
there, but it would be much more convenient to use RunAs directly.

Ads
  #2  
Old January 9th 08, 12:09 AM posted to microsoft.public.windowsxp.security_admin
Sunny[_2_]
external usenet poster
 
Posts: 2
Default SRP and Run As...

Sunny wrote:
Is it possible to configure XP Pro SP2 such that RunAs privileges are
applied before Software Restriction Policy is evaluated?

Take the example of an executable stored in c:\temp. Software
Restriction Policy prevents execution of anything in c:\temp by ordinary
users, but is not enforced for local administrators.

SRP works as expected for the primary logon - local admins can execute
programs from c:\temp, ordinary users cannot - however RunAs does not
permit running programs from c:\temp as admin while logged in as an
ordinary user. The system issues the "Blocked by SRP" error before it
even checks the admin account credentials provided (you still get an SRP
error if you supply a bad admin password).

It seems to me XP is doing things backward here - I can get around it by
using RunAs to start a command prompt, then executing programs from
there, but it would be much more convenient to use RunAs directly.


Anyone?
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off






All times are GMT +1. The time now is 05:33 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.