<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>jaybaz [MS] WebLog : Admin vs. Normal User</title><link>http://blogs.msdn.com/jaybaz_ms/archive/tags/Admin+vs.+Normal+User/default.aspx</link><description>Tags: Admin vs. Normal User</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>RANU: Running Admin Tasks easily</title><link>http://blogs.msdn.com/jaybaz_ms/archive/2004/07/14/183134.aspx</link><pubDate>Wed, 14 Jul 2004 17:01:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:183134</guid><dc:creator>jaybaz_MS</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/jaybaz_ms/comments/183134.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jaybaz_ms/commentrss.aspx?PostID=183134</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jaybaz_ms/rsscomments.aspx?PostID=183134</wfw:comment><description>&lt;P&gt;&lt;FONT face=Tahoma&gt;A while back I &lt;A href="http://blogs.msdn.com/jaybaz_MS/archive/2004/06/21/161724.aspx"&gt;described the set of shortcuts&lt;/A&gt; I use to run things as Administrator, even though I'm logged on as a Limited User.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I've packaged them up for &lt;/FONT&gt;&lt;A href="http://www.danfernandez.com/view/view.aspx?ID=40"&gt;&lt;FONT face=Tahoma&gt;dowload&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Tahoma&gt;.&amp;nbsp; Enjoy.&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=Tahoma&gt;
&lt;P&gt;
&lt;HR id=null&gt;
&lt;/P&gt;
&lt;H2&gt;Overview&lt;/H2&gt;
&lt;P&gt;Logging on as a restricted user greatly increases security, protecting you from certain virus &amp;amp; trojan horse attacks, and adheres to the "principle of least priviledge". 
&lt;P&gt;However, if your domain user account is a normal user on your machine, it can be challenging to perform certain administrative tasks, like: 
&lt;UL&gt;
&lt;LI&gt;Control Panel applets 
&lt;LI&gt;Administative Tools 
&lt;LI&gt;Install software from Corpnet 
&lt;LI&gt;Edit HKLM reg keys &lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;This collection of shortcuts make it easier to run these tools as Administrator. 
&lt;HR&gt;

&lt;H2&gt;Setup:&lt;/H2&gt;
&lt;P&gt;I like to use it as a toolbar on my Windows Task Bar. &lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;I&gt;(Optional)&lt;/I&gt; Copy to your local machine 
&lt;LI&gt;RClick on the Windows Task Bar 
&lt;LI&gt;Select Toolbars-&amp;gt;New Toolbar 
&lt;LI&gt;Point to the Admin Tasks folder &lt;/LI&gt;&lt;/OL&gt;
&lt;P&gt;Also, it's a good idea to teach windows to run each explorer window as a separate process. This way you can have both Administrator and User explorers open at the same time. See &lt;A href="http://blogs.msdn.com/Aaron_Margosis"&gt;Aaron Margosis&lt;/A&gt;' blog&amp;nbsp;for more info.
&lt;HR&gt;

&lt;H2&gt;Details:&lt;/H2&gt;
&lt;H3&gt;CMD&lt;/H3&gt;
&lt;P&gt;Launch a command prompt as Administrator &lt;/P&gt;
&lt;P&gt;CMD w Network Launch a command prompt as Administartor, but with your network credentials 
&lt;H3&gt;Explorer w Network&lt;/H3&gt;
&lt;P&gt;Launch explorer.exe as Administartor, but with your network credentials. Requires setting ExplorerSeparateProcess (see above). &lt;/P&gt;
&lt;H3&gt;Page Defrag&lt;/H3&gt;
&lt;P&gt;A sysinternals tool that I like for defragmenting my pagefile. &lt;/P&gt;
&lt;H3&gt;Regedit&lt;/H3&gt;
&lt;P&gt;Runs regedit as Administrator (relies on a possibly undocumented option to regedit). &lt;/P&gt;
&lt;H3&gt;Task Manager&lt;/H3&gt;
&lt;P&gt;Runs Task Manager as Administrator &lt;/P&gt;
&lt;H3&gt;Control Panel&lt;/H3&gt;
&lt;P&gt;Runs CPL control panel applets. &lt;/P&gt;
&lt;H3&gt;Administrative Tools&lt;/H3&gt;
&lt;P&gt;MMC Snap-ins that appear in Control Panel-&amp;gt;Administrative Tools &lt;/P&gt;
&lt;H3&gt;Administrative Tools-&amp;gt;More&lt;/H3&gt;
&lt;P&gt;Most of these appear under the the Computer Management MMC snap-in, but here you have direct access to them &lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=183134" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jaybaz_ms/archive/tags/Admin+vs.+Normal+User/default.aspx">Admin vs. Normal User</category></item><item><title>RANU: smarter CPL and MSC </title><link>http://blogs.msdn.com/jaybaz_ms/archive/2004/06/21/161724.aspx</link><pubDate>Mon, 21 Jun 2004 20:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:161724</guid><dc:creator>jaybaz_MS</dc:creator><slash:comments>7</slash:comments><comments>http://blogs.msdn.com/jaybaz_ms/comments/161724.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jaybaz_ms/commentrss.aspx?PostID=161724</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jaybaz_ms/rsscomments.aspx?PostID=161724</wfw:comment><description>&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;I wish that .CPLs and .MSCs were smarter about normal users.&amp;nbsp; I want to be a normal user, open a &lt;A href="http://support.microsoft.com/?kbid=313808"&gt;Control Panel applet&lt;/A&gt;, and have it prompt me for credentials if needed.&amp;nbsp; Same thing for the administrative tools.&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;Here's what I do instead.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;I create a set of shortcuts in a folder called &amp;#8220;Control Panel&amp;#8221;:&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /user:Administrator "control access.cpl"&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;I even set the icon by pointing it back at the .CPL file.&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;I do something similar with a folder called &amp;#8220;Administrative Tools&amp;#8221;:&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN-LEFT: 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /profile /user:Administrator "mmc %windir%\System32\compmgmt.msc"&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="FONT-FAMILY: Tahoma"&gt;Both folders go into the &amp;#8220;Admin Tools&amp;#8220; folder, along with&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;CMD w/ network&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /env /user:Administrator "runas.exe /user:%USERDOMAIN%\%USERNAME% /env /netonly \"cmd\""&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;There&amp;#8217;s a bug in Windows XP where certain controls running in this mode just won&amp;#8217;t paint.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It seems to be fixed in Windows Server 2003.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Don&amp;#8217;t know about Windows XP SP2.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;CMD&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /env /user:Administrator "cmd"&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Explorer w/ network&lt;/B&gt;. Enable &amp;#8220;Launch folder windows in a separate process&amp;#8221;, as both yourself &amp;amp; Administrator.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /env /user:Administrator "runas.exe /user:%USERDOMAIN%\%USERNAME% /env /netonly \"explorer\""&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Task manager&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 0.5in"&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'"&gt;runas.exe /user:Administrator taskmgr.exe&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;Regedit&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt; TEXT-INDENT: 0.5in"&gt;runas.exe /user:Administrator regedit.exe &amp;#8211;m&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;The Admin Tools folder then becomes a toolbar on my taskbar.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;With all this in place, I can get by as a normal user.&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=161724" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jaybaz_ms/archive/tags/Admin+vs.+Normal+User/default.aspx">Admin vs. Normal User</category></item><item><title>RANU: Give me another TS session</title><link>http://blogs.msdn.com/jaybaz_ms/archive/2004/06/21/161711.aspx</link><pubDate>Mon, 21 Jun 2004 20:32:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:161711</guid><dc:creator>jaybaz_MS</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/jaybaz_ms/comments/161711.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jaybaz_ms/commentrss.aspx?PostID=161711</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jaybaz_ms/rsscomments.aspx?PostID=161711</wfw:comment><description>&lt;P&gt;&lt;FONT face=Tahoma&gt;If you want to user Windows Terminal Services, Microsoft says &lt;A href="http://www.microsoft.com/windowsxp/using/mobility/rdfaq.mspx"&gt;you need a server OS&lt;/A&gt;.&amp;nbsp; Seems like overkill.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I don't need my Windows XP-based email machine to support 500 concurrent users.&amp;nbsp; I shouldn't need a licensing server &amp;amp; a $1500 OS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;Here's what I really want Windows XP TS to do:&lt;/FONT&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT face=Tahoma&gt;Let me TS from the console to localhost, and get a&amp;nbsp;second session.&lt;/FONT&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;FONT face=Tahoma&gt;Let me TS in remotely to my machine, and select either the console or a second session.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I can almost do this with &lt;A href="http://blogs.msdn.com/oldnewthing/archive/2003/11/21/55799.aspx"&gt;Fast User Switching, but I'm on a domain&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;If I had this, I could keep Administrator logged in to the second session, and myself (User) in the console.&amp;nbsp; Minimal hassle.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;While I'm at it, let the second session &lt;A href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/ts_cmd_shadow.asp"&gt;shadow&lt;/A&gt; the console, and &lt;EM&gt;vice versa&lt;/EM&gt;. The Remote Assistance experience is very painful.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=161711" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jaybaz_ms/archive/tags/Admin+vs.+Normal+User/default.aspx">Admin vs. Normal User</category></item><item><title>RANT: Run as Normal User</title><link>http://blogs.msdn.com/jaybaz_ms/archive/2004/06/21/161609.aspx</link><pubDate>Mon, 21 Jun 2004 18:48:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:161609</guid><dc:creator>jaybaz_MS</dc:creator><slash:comments>8</slash:comments><comments>http://blogs.msdn.com/jaybaz_ms/comments/161609.aspx</comments><wfw:commentRss>http://blogs.msdn.com/jaybaz_ms/commentrss.aspx?PostID=161609</wfw:commentRss><wfw:comment>http://blogs.msdn.com/jaybaz_ms/rsscomments.aspx?PostID=161609</wfw:comment><description>&lt;P&gt;&lt;FONT face=Tahoma&gt;AKA &amp;#8220;Run as non-admin&amp;#8221;.&amp;nbsp; We call it &amp;#8220;RANU&amp;#8221; around here, or sometimes &amp;#8220;why would you do that?&amp;#8221;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I have a &lt;/FONT&gt;&lt;A href="http://www.uwsg.iu.edu/hypermail/linux/kernel/9604.3/0290.html"&gt;&lt;FONT face=Tahoma&gt;Linux background&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Tahoma&gt;.&amp;nbsp; There it seemed obvious to run as 'jbazuzi' sometimes and 'root' other times.&amp;nbsp; But making it work in Windows is just hard.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I don't mind that I can't install most software as a normal user.&amp;nbsp; That's something we'll get to in time.&amp;nbsp; Right now I'm just annoyed that I can't run most apps without being an admin.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I used to play a lot of Everquest.&amp;nbsp; Great game, terrible devs.&amp;nbsp; They save your player-specific and character-specific data in the installation directory (%ProgramFiles%\Sony\Everquest).&amp;nbsp; In the early days it was all in custom binary files, later they moved to text files.&amp;nbsp; They've never heard of %APPDATA%, %HOME%, and the registry?&amp;nbsp; You need to have write access to the application install directory.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I'd like to tell Sony to get on the ball with EQ, and make it work for normal users.&amp;nbsp; It runs in a home environment, often without a firewall or an network guru.&amp;nbsp; It&lt;/FONT&gt;&lt;FONT face=Tahoma&gt; attracts non-techno-geeks so, the audience is particularly susceptible to scams &amp;amp; hoaxes.&amp;nbsp; (&lt;A href="http://www.rpgexpert.com/2103.html"&gt;Even the scammers get scammed!&lt;/A&gt;)&amp;nbsp; Microsoft &amp;amp; Sony need to do our parts to give these users a safe, secure environment.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;I bet you run as administrator.&amp;nbsp; I do it, too.&amp;nbsp; I tried hard to run as normal user, on both my development &amp;amp; email machines.&amp;nbsp; It was a big hassle, go figure!&amp;nbsp; Every time I ran into a problem with a tool or VS component, I'd tell the owner.&amp;nbsp; They'd look at me funny &amp;amp; tell me &amp;#8220;too bad&amp;#8221;.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;You &lt;EM&gt;really&lt;/EM&gt; want me to run as normal user, because that'll give you the best chance of a VS that works well as normal user.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;Your users really want you to run as normal user, for the same reason.&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Tahoma&gt;OK, out of breath, time to take a break from the rant.&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=161609" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/jaybaz_ms/archive/tags/Admin+vs.+Normal+User/default.aspx">Admin vs. Normal User</category></item></channel></rss>