Sign in with
Sign up | Sign in
Your question

How to have group policy apply to Runas user

Last response: in Windows 2000/NT
Share
Anonymous
September 15, 2005 7:29:34 PM

Archived from groups: microsoft.public.win2000.group_policy (More info?)

Is it possible to apply a group policy to a Runas user? We apply AD group
policies to users and computers but the do not appear to apply to users
running applications with Runas. For instance; if a user launches Word and
tries to save a .doc with Runas we want to prevent them from seeing certain
drives like them do if they just logged into our Windows machines normally.
This is possible by modifying the Default user profile (ntuser.dat) but that
is not an ideal solution for us.
Any ideas appreciated,
Jim
Anonymous
September 16, 2005 12:23:25 PM

Archived from groups: microsoft.public.win2000.group_policy (More info?)

If the user runs Word as another user, Word is looking at the network drives
as the "Runas" user. Being that's the case, it'll allow them to save to the
folders the Runas user is allowed access to.

Why are users utilizing "Runas" for Word?
kb

"Jims" <biz@neocasa.net> wrote in message
news:etBtOviuFHA.3596@TK2MSFTNGP15.phx.gbl...
> Is it possible to apply a group policy to a Runas user? We apply AD group
> policies to users and computers but the do not appear to apply to users
> running applications with Runas. For instance; if a user launches Word
> and tries to save a .doc with Runas we want to prevent them from seeing
> certain drives like them do if they just logged into our Windows machines
> normally. This is possible by modifying the Default user profile
> (ntuser.dat) but that is not an ideal solution for us.
> Any ideas appreciated,
> Jim
>
Anonymous
September 17, 2005 1:07:56 AM

Archived from groups: microsoft.public.win2000.group_policy (More info?)

We're installing an SSO app that runs on our locked down kiosks and the SSO
app
runs applications using runas. We don't have a problem seeing drives, we
are trying to hide drives. We don't allow users to see the local drives,
only their network drives that are mapped when they login. Not a problem
with standard windows login and group policy but apparently our restricive
group policies don't apply when an app is launched by runas the user - which
is how this sso app works.
Thanks,
jim


"Ken B" <none@microsoft.com> wrote in message
news:eq4RxlruFHA.3400@TK2MSFTNGP14.phx.gbl...
> If the user runs Word as another user, Word is looking at the network
> drives as the "Runas" user. Being that's the case, it'll allow them to
> save to the folders the Runas user is allowed access to.
>
> Why are users utilizing "Runas" for Word?
> kb
>
> "Jims" <biz@neocasa.net> wrote in message
> news:etBtOviuFHA.3596@TK2MSFTNGP15.phx.gbl...
>> Is it possible to apply a group policy to a Runas user? We apply AD
>> group policies to users and computers but the do not appear to apply to
>> users running applications with Runas. For instance; if a user launches
>> Word and tries to save a .doc with Runas we want to prevent them from
>> seeing certain drives like them do if they just logged into our Windows
>> machines normally. This is possible by modifying the Default user profile
>> (ntuser.dat) but that is not an ideal solution for us.
>> Any ideas appreciated,
>> Jim
>>
>
>
!