User starting & stopping services

Archived from groups: microsoft.public.win2000.group_policy (More info?)

I want to be able to allow users to start/stop certain services. In this
case CISCO VPN. I was able to get the policy to work the first time but
after a complete shutdown and startup, niether the user nor the
administrator cannot start the service. A simple logoff does not affect the
policy. This is on a laptop so there is no domain controller involved. TIA
6 answers Last reply
More about user starting stopping services
  1. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    <snip>
    Did you try using security templates and the Security Configuration and
    Analysis snap-in?

    --
    Cheers,
    Marin Marinov
    MCT, MCSE 2003/2000/NT4.0,
    MCSE:Security 2003/2000, MCP+I
    -
    This posting is provided "AS IS" with no warranties, and confers no
    rights.

    "True knowledge exists in knowing that you know nothing."
    Socrates
  2. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    You may also want to try subinacl to assign user permissions to services as described
    in the KB below. --- Steve

    http://support.microsoft.com/default.aspx?scid=kb;en-us;288129

    SUBINACL /SERVICE \ServiceName /GRANT=UserName[=Access]
    "DCA" <dpca001@hawaii.rr.com> wrote in message
    news:zzqxc.16442$Ha2.11237@twister.socal.rr.com..> I want to be able to allow users
    to start/stop certain services. In this
    > case CISCO VPN. I was able to get the policy to work the first time but
    > after a complete shutdown and startup, niether the user nor the
    > administrator cannot start the service. A simple logoff does not affect the
    > policy. This is on a laptop so there is no domain controller involved. TIA
    >
    >
  3. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    Yes, it would work the first time I implemented but not after a warm or
    cold re-start. It seemed to corrupt the CISCO service where even as
    administrator, I couldn't start it. I'd have to unisntall and re-install
    the VPN client.

    What we're trying to achieve is to give the regular user the ability to
    start/stop the service so that when they're outisde the office environment
    on the laptop, they'll be able to start the service and use VPN from
    anywhere.


    "Marin Marinov" <mlmarinov@askme.ca> wrote in message
    news:MPG.1b3111255631ce27989889@msnews.microsoft.com...
    > <snip>
    > Did you try using security templates and the Security Configuration and
    > Analysis snap-in?
    >
    > --
    > Cheers,
    > Marin Marinov
    > MCT, MCSE 2003/2000/NT4.0,
    > MCSE:Security 2003/2000, MCP+I
    > -
    > This posting is provided "AS IS" with no warranties, and confers no
    > rights.
    >
    > "True knowledge exists in knowing that you know nothing."
    > Socrates
  4. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    Yes, I did. It created all kinds of problems. It would work the very first
    time I ran it but afterward a warm or cold start, it literally got messed up
    so bad, I had to uninstall & re-install the software again.

    Obviously I missed something along the way even I printed the microsoft
    instructions and had them next to me while I was doing this.

    "Marin Marinov" <mlmarinov@askme.ca> wrote in message
    news:MPG.1b3111255631ce27989889@msnews.microsoft.com...
    > <snip>
    > Did you try using security templates and the Security Configuration and
    > Analysis snap-in?
    >
    > --
    > Cheers,
    > Marin Marinov
    > MCT, MCSE 2003/2000/NT4.0,
    > MCSE:Security 2003/2000, MCP+I
    > -
    > This posting is provided "AS IS" with no warranties, and confers no
    > rights.
    >
    > "True knowledge exists in knowing that you know nothing."
    > Socrates
  5. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    I read the article and it appears that the user would still need
    administravie rights to run the program.

    "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message news:<2bPxc.22$Bm1.19@attbi_s04>...
    > You may also want to try subinacl to assign user permissions to services as described
    > in the KB below. --- Steve
    >
    > http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
    >
    > SUBINACL /SERVICE \ServiceName /GRANT=UserName[=Access]
    > "DCA" <dpca001@hawaii.rr.com> wrote in message
    > news:zzqxc.16442$Ha2.11237@twister.socal.rr.com..> I want to be able to allow users
    > to start/stop certain services. In this
    > > case CISCO VPN. I was able to get the policy to work the first time but
    > > after a complete shutdown and startup, niether the user nor the
    > > administrator cannot start the service. A simple logoff does not affect the
    > > policy. This is on a laptop so there is no domain controller involved. TIA
    > >
    > >
  6. Archived from groups: microsoft.public.win2000.group_policy (More info?)

    Yes, subinacl requires administrator access, but once the permissions are granted
    they stay that way unless they are changed back. It does not have to be run every
    single time. Any process to give users rights to services will require administrator
    rights. It could also be run as a startup script that runs in system context. ---
    Steve

    "Ralph" <dpca001@hawaii.rr.com> wrote in message
    news:a7bb52c5.0406141034.2831f9ac@posting.google.com...
    > I read the article and it appears that the user would still need
    > administravie rights to run the program.
    >
    > "Steven L Umbach" <n9rou@nospam-comcast.net> wrote in message
    news:<2bPxc.22$Bm1.19@attbi_s04>...
    > > You may also want to try subinacl to assign user permissions to services as
    described
    > > in the KB below. --- Steve
    > >
    > > http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
    > >
    > > SUBINACL /SERVICE \ServiceName /GRANT=UserName[=Access]
    > > "DCA" <dpca001@hawaii.rr.com> wrote in message
    > > news:zzqxc.16442$Ha2.11237@twister.socal.rr.com..> I want to be able to allow
    users
    > > to start/stop certain services. In this
    > > > case CISCO VPN. I was able to get the policy to work the first time but
    > > > after a complete shutdown and startup, niether the user nor the
    > > > administrator cannot start the service. A simple logoff does not affect the
    > > > policy. This is on a laptop so there is no domain controller involved. TIA
    > > >
    > > >
Ask a new question

Read More

Policy Windows