Page 1 of 1 1
Topic Options
#152617 - 2005-12-01 11:53 AM Modify Registry Permission with login script
pdiddy Offline
Lurker

Registered: 2005-12-01
Posts: 3
Hi guys, it's my first post on here and I am new to Kixtart.

I need to change permissions on my W2K and XP machines registries.

My users run a kix script at log on and I would like to use this to make the changes, as I do not want to walk round and fix over 200 machines manually!!

I just want to allow "Everyone" full control to HKLM

Any ideas ???

Many thanks

Top
#152618 - 2005-12-01 12:19 PM Re: Modify Registry Permission with login script
Mart Moderator Offline
KiX Supporter
*****

Registered: 2002-03-27
Posts: 4673
Loc: The Netherlands
Quote:


....
I just want to allow "Everyone" full control to HKLM
....




Are you sure? Securety risks just around the corner.


Logon script run under the users privileges that is loggin on.
So unless you do some kind of runas this is never going to work. Do you have AD? If so a startup script and regini could do this.
_________________________
Mart

- Chuck Norris once sold ebay to ebay on ebay.

Top
#152619 - 2005-12-01 12:25 PM Re: Modify Registry Permission with login script
pdiddy Offline
Lurker

Registered: 2005-12-01
Posts: 3
Quote:

Quote:


....
I just want to allow "Everyone" full control to HKLM
....




Are you sure? Securety risks just around the corner.


Logon script run under the users privileges that is loggin on.
So unless you do some kind of runas this is never going to work. Do you have AD? If so a startup script and regini could do this.




They way things are set up here all users have local admin privileges on their machines.

We do have AD but only limited access to it as we are a small office in a single global domain.

Top
#152620 - 2005-12-01 12:33 PM Re: Modify Registry Permission with login script
Mart Moderator Offline
KiX Supporter
*****

Registered: 2002-03-27
Posts: 4673
Loc: The Netherlands
Well if all users are local admin then there is no need to set these users to have full access on HKLM cause they already have this cause they are local admin afaik.

[edit]
PS: A scheduled task could also do this. Have a look in the UDF forum for the taskscheduler UDF.
[/edit]


Edited by Mart (2005-12-01 12:40 PM)
_________________________
Mart

- Chuck Norris once sold ebay to ebay on ebay.

Top
#152621 - 2005-12-01 12:41 PM Re: Modify Registry Permission with login script
pdiddy Offline
Lurker

Registered: 2005-12-01
Posts: 3
The thing is for some reason or another the registry permissions are up the wall.

The reason for all this is SMSM 2003 will not install to selected machines, when I have changed the reg permissions to Full Control it works no problem.

Even when I try to connect remotely to a mchines regisrty as a Dom Admin it will not let me set permission on HKLM and gives me errors while trying to open the reg keys.

Top
#152622 - 2005-12-01 01:55 PM Re: Modify Registry Permission with login script
Richard H. Administrator Offline
Administrator
*****

Registered: 2000-01-24
Posts: 4946
Loc: Leatherhead, Surrey, UK
You need to fix the access problem rather than just kludge the permissions on HKLM which is asking for trouble.

You will continue to have problems with these machines until you resolve the issue.

Make sure that the problem machines are joined to the domain properly.

Make sure that the domain admins are in the local admins group.

Top
#152623 - 2005-12-01 07:26 PM Re: Modify Registry Permission with login script
NTDOC Administrator Offline
Administrator
*****

Registered: 2000-07-28
Posts: 11631
Loc: CA
100% agree with Mart and Richard.

Fix your Admin issues. If the permissions were totally screwed up by someone that did not know what they were doing (not pointing fingers, but if you move forward with setting ALL USERS FULL CONTROL then you will be placed into that category of being an Incompetent Administrator) they can be repaired by an Admin by running the correct procedures to restore the system rights.


How to restore the default NTFS permissions for Windows 2000

Default NTFS Permissions in Windows 2000
 
Use NETDOM to verify TRUSTS
 
If as you say all your users are local admins then they should be able to do anything to their system. There are some minor things they can't do by default, but even those things can be altered by an Admin to be allowed - these things are stuff that relate to the SYSTEM account and typically are not needed by the Admin account.
 

Top
#152624 - 2005-12-01 09:34 PM Re: Modify Registry Permission with login script
Mart Moderator Offline
KiX Supporter
*****

Registered: 2002-03-27
Posts: 4673
Loc: The Netherlands
Amen!
_________________________
Mart

- Chuck Norris once sold ebay to ebay on ebay.

Top
#152625 - 2005-12-01 10:05 PM Re: Modify Registry Permission with login script
Chris S. Offline
MM club member
*****

Registered: 2002-03-18
Posts: 2368
Loc: Earth
Quote:

The reason for all this is SMSM 2003 will not install to selected machines, when I have changed the reg permissions to Full Control it works no problem.

Even when I try to connect remotely to a mchines regisrty as a Dom Admin it will not let me set permission on HKLM and gives me errors while trying to open the reg keys.




If you are performing a Client Push installation you should configure the account used for the client push to be a domain user account that has local admin rights on the workstation. Also, File and Print sharing needs to be enabled on the client computer for a Client Push installation.

If you are performing a "logon script-initiated" installation, if the user has administrative rights the install will install the client from the CAP or Management Point directly. If the user does not have administrative rights, a CCR will be created and SMS will attempt to install the client.

Some gotchas may be an improperly configured SLP or CAP/MP, if the PC is not joined to the domain (i.e. workgroup or stand-alone), or other issues. In general, I'd have to agree with the others; fix the issue, but don't open a huge security hole. That is like using a sledgehammer on a finish nail.

Top
Page 1 of 1 1


Moderator:  Jochen, Allen, Radimus, Glenn Barnas, ShaneEP, Ruud van Velsen, Arend_, Mart 
Hop to:
Shout Box

Who's Online
1 registered (Allen) and 781 anonymous users online.
Newest Members
Sir_Barrington, batdk82, StuTheCoder, M_Moore, BeeEm
17886 Registered Users

Generated in 0.082 seconds in which 0.037 seconds were spent on a total of 12 queries. Zlib compression enabled.

Search the board with:
superb Board Search
or try with google:
Google
Web kixtart.org