Deny interactive login

Deny interactive login

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Deny interactive login JayH 08-30-2005
Posted by =?Utf-8?B?SmF5SA==?= on August 30, 2005, 11:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I am trying to setup an acount that is a local admin to a group of
workstations but is not allowed to login. I need it to work under the runas
command though. I work at a school and am setting up the nesest version of
the java sdk which seems to require a admin acount to run it correctly. By
using the runas command with a account that has admin rights it does work but
I want to take away the ability for them to login to the machine with that
account. I have tried usoing the deny login policy but then it doesnt work
at all. Are there any other ways to prevent this acount from being used
other then for the runas batch file I have already setup. We are using a
2000/2003 domain with 500+ workstations on it.

Posted by Roger Abell [MVP] on August 31, 2005, 8:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Use of RunAs from within an interactive session requires that the
"runas" account has interactive login rights.
There is no way to obscure the credentials for a "runas" invocation
when encoded within a script so that they cannot be obtained.
You should get regmon and filemon from www.sysinternals.com
and analyze where the failures are when the java sdk is used by
a standard user account and adjust the missing permissions.
--
Roger

>I am trying to setup an acount that is a local admin to a group of
> workstations but is not allowed to login. I need it to work under the
> runas
> command though. I work at a school and am setting up the nesest version
> of
> the java sdk which seems to require a admin acount to run it correctly.
> By
> using the runas command with a account that has admin rights it does work
> but
> I want to take away the ability for them to login to the machine with that
> account. I have tried usoing the deny login policy but then it doesnt
> work
> at all. Are there any other ways to prevent this acount from being used
> other then for the runas batch file I have already setup. We are using a
> 2000/2003 domain with 500+ workstations on it.



Similar ThreadsPosted
Restricting interactive login only to terminal services May 10, 2007, 7:17 am
Disabling Interactive Logon Against Security Group August 14, 2006, 6:43 am
Gurus, does NPLogonNotify ever receive auth type "Kerberos:Interactive"?!?! June 28, 2005, 5:02 pm
Deny access to certain IP address August 30, 2005, 12:11 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:41 pm
How to deny access to some internet sites November 10, 2005, 8:40 am
Allow to read the file, but deny rename it ? June 11, 2006, 9:14 am
Deny sending attachment through Internet October 5, 2006, 3:08 pm
Deny change of email address February 8, 2007, 3:48 pm

The site map in XML format XML site map

Contact Us | Privacy Policy