Granting a non-administrative user rights to manage ALL services, not just selective services


howdy,

i'm having hard time request.  user needs able manage services through non-administrative account.  request needs future services included developing new services every day , testing purposes.  know can use security templates or modify individual services via gpo, need more 'blanket' fix here.  i'd love if there option in user-rights entitled "manage services," there isn't.  there else can facilitate request?

what else can suggest possible fix?  considering encrypted "runas services.msc" shortcut on desktop, that's little unclean.  user not have administrative account, might way go if there isn't funky registry hack or administrative template workaround gurus know.

client windows 7 in 2008 active directory environment.

any surely appreciated.

i've referenced following documents (and more), of point selective service adjustment:

http://support.microsoft.com/kb/256345

http://social.technet.microsoft.com/forums/zh/winservergp/thread/27300cbf-3d41-420e-9e4b-9eea9163cf30

http://www.windowsecurity.com/articles/understanding-windows-security-templates.html

thanks,

mike

hello mike,

said, there no specific privilege change service permissions.

what do, create shutdown-script changes permissions of every service.

there maybe powershell-script ... 

tool change service permissions subinacl.

you might able pipe 1 command other command:

http://www.computerperformance.co.uk/powershell/powershell_service.htm#example_1:_list_all_the_services_on_your_computer

 

anyway, changing system services administrative task, therefore there no
built-in way solve issue.


mvp group policy - mythen, insiderinfos und troubleshooting zum thema gpos: let's go, use gpo!




Windows Server  >  Group Policy



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file