<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx</link><description>Complete list of Aaron Margosis' non-admin / least privilege posts, for easy lookup.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>TweakUI</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#409558</link><pubDate>Tue, 19 Apr 2005 09:01:26 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:409558</guid><dc:creator>Norwegian</dc:creator><description>How about doing a piece on using TweakUI as non-admin? I'm getting it to work, but it doesn't save settings when you reboot.</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#409758</link><pubDate>Tue, 19 Apr 2005 22:06:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:409758</guid><dc:creator>Aaron Margosis</dc:creator><description>What TweakUI settings aren't persisting?  I haven't seen that problem.  Note that some settings are per-user settings.  Note that not all per-user settings are accessible to the user (e.g., policy settings).</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#411685</link><pubDate>Mon, 25 Apr 2005 14:57:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:411685</guid><dc:creator>Jonathan</dc:creator><description>Isn't this supposed to be implemented as post categories, instead of an odd &amp;quot;flashback&amp;quot; post?</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#411733</link><pubDate>Mon, 25 Apr 2005 15:15:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:411733</guid><dc:creator>Aaron Margosis</dc:creator><description>Jonathan -&lt;br&gt;Yes, it should, but for whatever reason the new server software doesn't show just titles and abstracts, so the desired view isn't available.  Also, this lets me put the items in a more coherent order.&lt;br&gt;Or maybe it's like when the record label releases a Greatest Hits album, feeling that the band's best days are over - which must mean that the double live album can't be far behind. :-)  And in fact, it isn't:  I'm presenting &amp;quot;Tips and Tricks for Running Windows with Least Privilege&amp;quot; at Tech*Ed in Orlando (June) and Amsterdam (July).  BTW, G. Andrew Duthie will be presenting the &amp;quot;Part II&amp;quot; of this topic in Orlando at least:  &amp;quot;Developing With Least Privilege&amp;quot;.  I highly recommend that all devs and dev managers (at least) attend his session.</description></item><item><title>How to secure the Administrator account access to your environment</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#432341</link><pubDate>Fri, 24 Jun 2005 20:15:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:432341</guid><dc:creator>Steve Lamb's Blog</dc:creator><description>The Administrator Accounts Security Planning Guide&amp;amp;amp;nbsp;has recently been posted to TechNet and hence...</description></item><item><title>How to add printers as a Print Operator</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#437890</link><pubDate>Tue, 12 Jul 2005 09:13:14 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:437890</guid><dc:creator>Alex</dc:creator><description>Last week at TechEd I mentioned to you an article I read about adding printer drivers as a non-admin. I thought it concerned members of the Users group, but this article describes how to give Print Operators the ability to add printer drivers. It’s by Kathy Ivens in the April 2004 issue of WindowsITPro. Look at tip 2 in &lt;a rel="nofollow" target="_new" href="http://www.windowsitpro.com/Article/ArticleID/42282/42282.html?Ad=1"&gt;http://www.windowsitpro.com/Article/ArticleID/42282/42282.html?Ad=1&lt;/a&gt; I hope it’s of use to you.</description></item><item><title>Running Thunderbird as Non-Admin</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#439951</link><pubDate>Mon, 18 Jul 2005 17:28:16 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:439951</guid><dc:creator>John Watson</dc:creator><description /></item><item><title>A Beginning with LUA</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#450276</link><pubDate>Thu, 11 Aug 2005 08:21:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:450276</guid><dc:creator>Listen...You Smell Something?</dc:creator><description>About a year ago I was reading something (blog, article, billboard, I&lt;br&gt;don't know what) that was talking...</description></item><item><title>Genuine Windows Validation fails for non-admin</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#451179</link><pubDate>Sat, 13 Aug 2005 09:59:42 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:451179</guid><dc:creator>Michael</dc:creator><description>SyncToy v1 Beta sounds pretty cool. To obtain the download, however, I need to validate Windows. The ActiveX required for the standard method fails silently after installation. I don't know but I guess the installation itself fails silently.&lt;br&gt;&lt;br&gt;The alternate Method also fails: The Validation Tool runs fine and returns some code. In the next window, I have to press continue (whatever sense this additional information makes). Then, another ActiveX-warning appears and on validate now, an hta-application is loaded which also fails, recommending that I contant my reseller.&lt;br&gt;&lt;br&gt;When I run MSIE as Admin, everything works fine.&lt;br&gt;&lt;br&gt;Does Microsoft encourage non-admin usage of windows? Obviously not.&lt;br&gt;&lt;br&gt;Michael</description></item><item><title>Running Thunderbird as Non-Admin</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#453144</link><pubDate>Thu, 18 Aug 2005 20:08:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:453144</guid><dc:creator>John Watson</dc:creator><description /></item><item><title>Working without Admin rights</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#454129</link><pubDate>Sun, 21 Aug 2005 04:37:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:454129</guid><dc:creator>Listen...You Smell Something?</dc:creator><description>In my previous post&lt;br&gt;I talked about how I started to work with a Limited User Account (LUA).&lt;br&gt;I've found...</description></item><item><title>Working without Admin rights</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#454130</link><pubDate>Sun, 21 Aug 2005 04:45:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:454130</guid><dc:creator>Listen...You Smell Something?</dc:creator><description>In my previous post I talked about how I started to work with a Limited User Account (LUA). I've found that as long as you have a couple of tools and a good idea of what is going on working without Administrative rights is not too bad. There are times that you need Administrative rights to get things done though.</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#455949</link><pubDate>Thu, 25 Aug 2005 03:23:17 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:455949</guid><dc:creator>John Galt</dc:creator><description>An excellent set of articles there, Aaron.  Kudos to you on the hard work and preparation.&lt;br&gt;&lt;br&gt;@Michael&lt;br&gt;re: Genuine Windows Validation fails for non-admin&lt;br&gt;&lt;br&gt;Did you try running the tool using run-as?</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#458269</link><pubDate>Wed, 31 Aug 2005 05:37:22 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:458269</guid><dc:creator>Layth</dc:creator><description>Hello Aaron&lt;br&gt;Can i use the privbar on SQL enterpris manager or query analyzer ???&lt;br&gt;&lt;br&gt;thanks&lt;br&gt;&lt;br&gt;Layth Shasha&lt;br&gt;layth.shasha@nzdf.co.nz</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#461422</link><pubDate>Tue, 06 Sep 2005 18:00:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:461422</guid><dc:creator>Aaron Margosis</dc:creator><description>Layth -&lt;br&gt;No - PrivBar extends only the Explorer/IE shell.  I've considered writing something to modify the title bars of other apps, but there is a much greater risk involved, since it would involve injecting code into every process on the desktop.</description></item><item><title>How to establish a Quarantine VPN connection using Least Privilege on Windows XP</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#544680</link><pubDate>Mon, 06 Mar 2006 22:17:52 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:544680</guid><dc:creator>Steve Lamb's Blog</dc:creator><description>Those of you who are taking advantage of the&amp;amp;amp;nbsp;Remote Access&amp;amp;amp;nbsp;Quarantine feature of Windows Server...</description></item><item><title>How to recover from Malware infestation? How to avoid getting malware in the first place</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#572590</link><pubDate>Mon, 10 Apr 2006 19:32:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:572590</guid><dc:creator>Steve Lamb's Blog</dc:creator><description>I encourage customers to architect machines such that data is stored in a separate partition of the hard...</description></item><item><title>How to mitigate the threat posed by malware and how Windows Vista will help in the long run</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#575827</link><pubDate>Thu, 13 Apr 2006 19:20:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:575827</guid><dc:creator>Steve Lamb's Blog</dc:creator><description>Many of us are concerned about the ever increasing threat to information security and business continuity...</description></item><item><title>&amp;amp;quot;How do I turn off that annoying User Account Control?&amp;amp;quot;</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#648166</link><pubDate>Tue, 27 Jun 2006 08:29:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:648166</guid><dc:creator>UACBlog</dc:creator><description>Are you thinking of turning off UAC? &amp;nbsp;Before you do...</description></item><item><title>UAP is blocking my ASP application</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#657778</link><pubDate>Thu, 06 Jul 2006 14:56:35 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:657778</guid><dc:creator>John</dc:creator><description>Hi,&lt;br&gt;&lt;br&gt;I have an ASP (not an ASP.NET) application accessing Sql Server 2005 database installed in Vista Beta 2 (Build : 5384). I am unable to access my application in server. UAP is blocking my application. I dont want to change system level UAP configuration using msconfig or secpol.msc. &lt;br&gt;Can any one suggest me some idea to change application level UAP configuration, so that I can access by ASP application.&lt;br&gt;&lt;br&gt;Thanks in Advance.&lt;br&gt;&lt;br&gt;-John-</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#889720</link><pubDate>Sat, 28 Oct 2006 18:08:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:889720</guid><dc:creator>Brian Hickman</dc:creator><description>&lt;p&gt;Aaron, &amp;nbsp;love your site and info. &amp;nbsp;you talk about the things desktop admins should know from day one and most don't know at all.&lt;/p&gt;
&lt;p&gt;i have a question and was wondering if you could point me in the right direction.&lt;/p&gt;
&lt;p&gt;in our environment (1400 locked down workstations, with gpo policies and a security template applied) we are having an issue with the xp sp2 upgrade.&lt;/p&gt;
&lt;p&gt;everything is fine until the user logs in after the upgrade.&lt;/p&gt;
&lt;p&gt;rundll32 runs calling an inf for mediaplayer customization. &amp;nbsp;it wants to write a key to hkcu\software\classes.&lt;/p&gt;
&lt;p&gt;i get the advanced inf install error.&lt;/p&gt;
&lt;p&gt;is there something simple i can do to fix this.&lt;/p&gt;
&lt;p&gt;i have been trying logon scripts running subinacle to set elevated rights but it just isnt working.&lt;/p&gt;
&lt;p&gt;why is mediaplayer wanting to write to this key? &amp;nbsp;you would think they would know about lua bugs more then anyone.&lt;/p&gt;
&lt;p&gt;the key it tries to create is:&lt;/p&gt;
&lt;p&gt;Software\Microsoft\MediaPlayer\Preferences: AcceptedPrivacyStatement=1&lt;/p&gt;
&lt;p&gt;thats my story and i am sticking to it.&lt;/p&gt;
</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#889968</link><pubDate>Sat, 28 Oct 2006 21:00:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:889968</guid><dc:creator>Brian Hickman</dc:creator><description>&lt;p&gt;looks like this is running and causing my issues as a locked down user:&lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\StubPath&lt;/p&gt;
&lt;p&gt;with a value of:&lt;/p&gt;
&lt;p&gt;rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub&lt;/p&gt;
&lt;p&gt;thinking about just moving or deleting this key/value.&lt;/p&gt;
&lt;p&gt;bh&lt;/p&gt;
</description></item><item><title>Living without antivirus software</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#1454086</link><pubDate>Fri, 12 Jan 2007 08:31:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1454086</guid><dc:creator>Exodus Development</dc:creator><description>&lt;p&gt;Ok, I'll admit it. I've been living dangerously for the last several years.&lt;/p&gt;
&lt;p&gt;Simply put, I refuse to install any kind of antivirus or personal firewall software on any of my systems. This includes a Windows XP Home system that was used by my children as&lt;/p&gt;
</description></item><item><title>Applying Mitigations for UAC Issues (LUA Bugs) on Windows Vista with Standard User Analyzer</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#1561898</link><pubDate>Wed, 31 Jan 2007 09:00:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1561898</guid><dc:creator>Evolving the Software Organism</dc:creator><description>&lt;p&gt;The story is all too familiar. Developing software as a standard user on your computer can be challenging&lt;/p&gt;
</description></item><item><title>Deploying and managing FireFox centrally</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#1685233</link><pubDate>Thu, 15 Feb 2007 21:42:50 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:1685233</guid><dc:creator>The things that are better left unspoken</dc:creator><description>&lt;p&gt;As an IT Professional you might get the question to deploy Mozilla's FireFox browser on the workstations&lt;/p&gt;
</description></item><item><title>Mission...not impossible...</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#3416413</link><pubDate>Wed, 20 Jun 2007 06:34:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3416413</guid><dc:creator>E-Bitz - SBS MVP the Official Blog of the SBS "Diva"</dc:creator><description>&lt;p&gt;&amp;amp;lt;duh duh da da duh duh music playing in the background&amp;amp;gt; Your job, Mr. Phelps is to devise a way&lt;/p&gt;
</description></item><item><title>And so this is Vista…</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#3615328</link><pubDate>Sat, 30 Jun 2007 06:38:06 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:3615328</guid><dc:creator>Aaron Margosis' "Non-Admin" WebLog</dc:creator><description>&lt;p&gt;What becomes of all my earlier non-admin tips, tricks and recommendations vis-&amp;#224;-vis RunAs, MakeMeAdmin, PrivBar and their interactions with IE and Explorer? The short answer is that Vista changes just about everything with respect to running with least&lt;/p&gt;
</description></item><item><title>Burning DVDs</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#4265591</link><pubDate>Mon, 06 Aug 2007 23:18:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4265591</guid><dc:creator>Mike</dc:creator><description>&lt;p&gt;What registry fix would be available to allow non-admins the ability to burn DVDs without installing Nero BurnRights?&lt;/p&gt;
</description></item><item><title>FAQ:  Why can’t I bypass the UAC prompt?</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#4317502</link><pubDate>Fri, 10 Aug 2007 06:59:30 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4317502</guid><dc:creator>Windows Vista Security</dc:creator><description>&lt;p&gt;Why Vista is better off without setuid or sudo.&lt;/p&gt;
</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#6907248</link><pubDate>Sun, 30 Dec 2007 14:02:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:6907248</guid><dc:creator>Frank</dc:creator><description>&lt;p&gt;Hi Aaron,&lt;/p&gt;
&lt;p&gt;I recently downloaded Explorer 7.0 and an having problems, I am using a dial-up connection, Windows Xp Sp-2 348mz &amp;amp; 384 ram, the problem is that after downloading Exp.7.0 my system acts sluggish. Takes forever to connect to a website, and just locks up sometimes, must use Esc. to regain control, the computer is protected McAfee security center against viris's and such.&lt;/p&gt;
&lt;p&gt;Is there any way that I could return to Exp.6.0, as I feel this rig is not up to date enought to use 7.0.&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Frank&lt;/p&gt;
</description></item><item><title>re: Table of contents, Aaron Margosis' non-admin blog</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#8410334</link><pubDate>Sat, 19 Apr 2008 21:20:44 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8410334</guid><dc:creator>Jerry</dc:creator><description>&lt;p&gt;This site and the one I found that led me here, &amp;nbsp;&lt;a rel="nofollow" target="_new" href="http://homepage.mac.com/corrp/windows/LUA/setup.html"&gt;http://homepage.mac.com/corrp/windows/LUA/setup.html&lt;/a&gt;, is something I've been looking for for several years, i.e. post Win XP inception.&lt;/p&gt;
&lt;p&gt;I have attempted to modify permissions because of the problem with a lot of my applications, that are pre Win XP, running under a limited user. My success has been limited.&lt;/p&gt;
&lt;p&gt;I am concerned that I may have compromised my limited user account. I have located several sites that supposedly return permissions to the original settings. I hope that this site will help me in that endeavor.&lt;/p&gt;
&lt;p&gt;Thanks in advance,&lt;/p&gt;
&lt;p&gt;Jerry Clasby&lt;/p&gt;
</description></item><item><title>I NEED HELP</title><link>http://blogs.msdn.com/aaron_margosis/archive/2005/04/18/TableOfContents.aspx#8590482</link><pubDate>Wed, 11 Jun 2008 00:57:53 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8590482</guid><dc:creator>Shirley</dc:creator><description>&lt;p&gt;I have no idea how I came across you, but you sound very intelligent, so maybe you can help me.&lt;/p&gt;
&lt;p&gt;We have a D-link Extreme N router in the den with the main computer. I installed the d-link DWA-552 Desktop Adapter into my computer. The problem sometimes it works a little sometimes it doesn't work at all. And, this is weird-It seems like when its trying not to work that my mouse hangs up and won't hardly work.&lt;/p&gt;
&lt;p&gt;Do you have any idea what I could be doing wrong. It is Windows XP with service pack 2. thank you factnurse@hotmail.com&lt;/p&gt;
</description></item></channel></rss>