How to allow access to winrs for non-admin user?

I have Windows Server 2012 (and Server 2008, but it is next priority) to monitor it using txwinrm. txwinrm library internally is using WinRS protocol. I have to monitor it using least privileged user, but don't know how to configure access for him.
All I managed to do - is to configure remote Powershell session for my user, but it's look like that winrs and powershell sessions have different security descriptors:
Invoke-Command -ComputerName 192.168.173.206 -Credential (credential Administrator $pwd) -ScriptBlock { 2 + 2}
# gives 4
Invoke-Command -ComputerName 192.168.173.206 -Credential (credential lpu1 $pwd) -ScriptBlock { 2 + 2}
# gives 4
winrs -r:192.168.173.206 -u:Administrator -p:$pwd 'powershell -command "2+2"'
# gives 4
winrs -r:192.168.173.206 -u:lpu1 -p:$pwd 'powershell -command "2+2"'
# Gives Winrs error: Access is denied.
Configuration for my user is following:
(Get-Item WSMan:\localhost\Service\RootSDDL).value
# O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;S-1-5-21-3231263931-1371906242-1889625497-1141)S:P(AU;FA;GA;;;WD)(AU;SA;GWGX;;;WD)
(Get-PSSessionConfiguration -name Microsoft.Powershell).SecurityDescriptorSddl
# O:NSG:BAD:P(A;;GA;;;BA)(A;;GA;;;S-1-5-21-3231263931-1371906242-1889625497-1149)S:P(AU;FA;GA;;;WD)(AU;SA;GXGW;;;WD)
(In each security descriptor my user is given general access to protected object).
So what security descriptor should I set to make my winrs query work for non-admin user?

Hi Bunyk,
I can not recreate the erroe you posted, and please also post the screenshoot in your convenience.
I tested with a non-domain user but has the local admin permission of the remote computer, and this worked, before running the remote cmdlet in powershell, I also configured the TrustedHosts.
In addition, the access denied could be also caused to the Protocol Filtering on the remote server, for more detailed information, please refer to this thread:
winrs error:access is denied
I hope this helps.

Similar Messages

  • How to hide the page ribbon and quichlaunch for non admin users

    HI
    1 ) how to hide the ribbon in a page in sharepoint 2010 for non administrator users  
    2) how to hide quicklaunch also for non admin users
    in quick lanuch i want to hide links for all site content also.
    i used Document Center Template to create my web application.
    adil

    HI
    i did not get how i use this control 
    <Sharepoint:SPSecurityTrimmedControl
    runat="server"
    PermissionsString="FullMask">
    2
      <div>
    3
        <SharePoint:SPLinkButton
    id="idNavLinkViewAll"
    runat="server"
    NavigateUrl="~site/_layouts/viewlsts.aspx"
    Text="<%$Resources:wss,quiklnch_allcontent%>" AccessKey="<%$Resources:wss,quiklnch_allcontent_AK%>"/>
    4
      </div>
    5
    </SharePoint:SPSecurityTrimmedControl>
    adil

  • User Interface Access Customisation for non admin users

    Hi,
    It is understood that for non-admin users, some features of the Planning Interface is not enabled and this can be controlled by proper access permissions. But, is it possible to extend the customization to provide some additional features in the menu bar for an user?
    For example, if View User wants to manage task lists. Is it possible by some sort of customization? Please advise.
    Thanks.

    Hi,
    You can create right click menus, and you can also create links on the tools page. Would any of these help you?
    Here is the doc on those subjects:
    Creating and Updating MenusAdministrators can create right-click menus and associate them with data forms, enabling users to click rows or columns in data forms and select menu items to:
    Launch another application, URL, or business rule, with or without runtime prompts
    Move to another data form
    Move to Manage Approvals with a predefined scenario and version
    The context of the right-click is relayed to the next action: the POV and the Page, the member the user clicked on, the members to the left (for rows), or above (for columns).
    When designing data forms, use Other Options to select menus available for Data Form menu item types. As you update applications, update the appropriate menus. For example, if you delete a business rule referenced by a menu, remove it from the menu.
    To create, edit, or delete menus:
    Select Administration, then Manage, then Menus.
    Perform one action:
    To create a menu, click Create, enter the menu's name, and click OK.
    To change a menu, select it and click Edit.
    To delete menus, select them, click Delete, and click OK.>
    Specifying Custom ToolsAdministrators can specify custom tools, or links, for users on the Tools page. Users having access to links can click links from the Tools menu to open pages in secondary browser windows.
    To specify custom tools:
    Select Administration, then Application, then Settings.
    For Show, select Advanced Settings.
    Click Go.
    Select Custom Tools.
    For each link:
    For Name, enter the displayed link name.
    For URL, enter a fully qualified URL, including the http:// prefix
    For User Type, select which users can access the link.
    Click Save.

  • Acrobat 7 requires admin password at every launch for non admin users?

    acrobat 7 requires admin password at every launch for non admin users?
    any one with a solution or similar problem?
    thanks for any help.

    I've been avidly following all of the threads regarding this issue...yet none of the solutions have worked for me. I've got 11 Mac users that do not use the Creative Suite..only Acrobat, Quark, etc. I've tried installing and re-installing through both Admin and User accounts, I've tried the AdobeBib XML change, I've tried enabling Root and installing, changing permission on the Acrobat folder, etc. all to no avail. I still get asked for Admin Authentication every time Acrobat and Distiller are opened (except on the Admin account side). This is happening on one particular Mac (G4, 1GB Ram, OS 10.4.3) for both Acrobat Standard 6 and 7 as well. The biggest issue that also happens in tandem with the Acrobat installs is the inability to print from Quark. I get the following error when printing: "The process "pictwpstops" terminated unexpectedly on signal 6." Because of the necessity to print Quark documents, I have uninstalled all Acrobat on the machines until we can get a fix. This resolves the printing problem with Quark. The only option left is to set up all users as Admin accounts - which I really do not want to do. Any other suggestions out there? I've got more information available if needed.

  • Not able Access Page in Page in Page Library for Non Admin users in Shrepoint 2013

    Hi all,
    All Non Admin users are not able access the page in pages library.If you have idea realting to this please give reply.
    Regards
    VeerendraNadh

    Hi Veerendra,
    Thanks for posting your issue,
    I think you have not published your pages for Major version. thus, other users are unable to see your pages from page library.
    for more details, kindly check out below mentioned URL
    http://blogs.technet.com/b/tothesharepoint/archive/2013/04/10/stage-7-upload-page-layouts-and-create-new-pages-in-a-publishing-site.aspx
    I hope this is helpful to you, mark it as Helpful.
    If this works, Please mark it as Answered.
    Regards,
    Dharmendra Singh (MCPD-EA | MCTS)
    Blog : http://sharepoint-community.net/profile/DharmendraSingh

  • Majority of reports missing for non admin users

    I have followed the instructions here (SCCM 2012–Reporting in console for non-admins (Reporting User Role) v2) to allow non admin users the ability to view
    reports in the console. So far, so good. However, when viewing the reports with the non admin user, only about 100 of the 400+ reports appear.
    Am I missing something here?

    The custom reporting one in the link I provided, and also modified versions of the following:
    OS Deployment manager (removed rights to All driver related items (drivers and driver packages), Boot image packages (except read access), Operating system installation packages).
    Application Administrator (removed Application>Approve; Distribition Point>Set Security Scope; Distribution Point Group>Set Security Scope; Global Condition>Set Security Scope)
    The reports missing we care about primarily are Software ones (companies and products and files).

  • Reader 9.5.1 Crashes after a few seconds for non-Admin users

    I have Adobe Reader 9.5.1 installed on some Citrix XenApp 5.0 servers that are Windows 2003.  Any time a non-admin user launches Reader it is open for a matter of seconds and then crashes.  It shows a Dr Watson crash in the error logs each time. If I logon as an Administrator, it works just fine.  I've tried reinstalling/repairing the installation to no avail. 
    Has anybody run into this in the past or does anyone have any ideas on how to fix it?

    My company is into same issue but thing is that I cannot uninstall the MS patch as it will be vulnerability for our servers and we have opened a case with MS and they have reveiwed the proc dump and now MS is asking to get this reviewed with Adobe. I'm not sure how to reach out to Adobe Support to get the fix from them. Any solution on this regard, it will be great help. Thanks, Sayed.

  • QuickTime fails to initialize for non-admin users (Error 63441)

    I have installed iTunes 6.0.4 (including QuickTime 7.0.4) on my XP PC. iTunes and QuickTime work fine for the Admin users, but not for non-Admin accounts.
    iTunes crashes with the generic Microsoft 'send error report' message; QuickTime gives "QuickTime failed to initialize. Error # 63441".
    Any help / suggestions appreciated.

    Eventually fixed it!
    As mentioned in numerous other posts this came down to an issue with registry keys.
    Updated the permissions for HKEYLOCALMACHINE\SOFTWARE\Apple Computer, Inc.\QuickTime to give 'Full Control' to 'Everyone'.
    Initially had a lot of difficulty accessing the Apple Computer, Inc. branch - kept getting 'access denied'. This turned out to be because there was no owner set for the key. Once I had made myself owner I was able to make the other changes.

  • Using mms.cfg file to enable Autoupdate for non-Admin users

    I need help in getting this to work.  So far it does not.
    Adobe Flash for windows 17.0.0.23
    Windows 7 Enterprise  - 5000 systems
    Users are not administrators on systems.
    The Non admin user gets prompted with a screen ( we do not want any prompts)
    Then the install fails because they are not an administrator.
    My mms.cfg file:
    AutoUpdateDisable=0
    AutoUpdateInterval=1
    SilentAutoUpdateEnable=1
    How do I use this or any other method to have Adobe Flash update automaticly for all users including non-admins
    and give no prompts?
    What are the next steps.  Is there an enterprise support site or method to use for mass distributions for Flash?
    Please Get back to me today before 12:00 EDT 13 Apr 2015.
    Gary Pearson
    401-233-6898

    Hi garyp81126656,
    The current mms.cfg file configuration will perform either a notification update or a background update. There are a few options to update non-admin users:
    Host the background update resources locally.  When using the Adobe servers for background updates there is no way to disable notification updates.  By hosting the background update resources locally users will never be prompted to update.
    Disable updates and deploy Flash Player updates via SCUP, SMS, or Group Policy.
    You can find the various deployment options are listed in Chapter 3 of the Flash Player Administrator's Guide.  The Admin Guide also contains information to license Flash Player for distribution within your organization, which is a requirement for any of the deployment methods described in the Admin Guide.  Additional information is available at An outline of Flash Runtime installation options
    Maria

  • Generic Object Services - View Attachments disabled for non admin user

    Hi,
    I am using SAP 4.7 and the attachments created using table TOA01 - archive link are visible to an administrator user through Generic Object Services toolbox while same View Attachments option appears disabled for other non admin users.
    Kindly help !

    Hi Neha,
    I'm sorry I don't have answer to your question but I wonder if you could help me.
    I'm looking at OSS note 530792 to configure GOS 'create attachment' option to copy the attachments to the archive server. currently, these are written to the SAP office tables SOC3, SOFFCONT1, etc and I want to use the archivelink and SAPHTTP and copy to the archive storage.
    Have you successfully managed to configure your system since you mentioned TOA01?
    In the same GOS menu I've activated the 'Business document' option and can copy these to the archive server by correctly configuring OAC2 and OAC3.
    I'll really appreciate of you could please share your knowledge.
    Thanks.
    Soyab

  • Itunes hangs for non admin users

    I've got itunes 10.6.3 running on 10.6.8 Macs which are joined to AD and OD for network authentication.
    When starting itunes as anything other than an administrator (local or domain) itunes simply hangs - on the very first run you can Agree to the EULA but after that it hangs at the startup. Sometimes you get the authentication dialogue for our proxy server but not always.
    I've checked and the proxy isn't even receiving any requests, and it works fine for an admin user. I've taken the proxy out of the users preferences and it still hangs.
    So is itunes dead in the water for non admins, or do I have to resort to the Windows 95 days of making everyone an admin of the Mac?

    Fgi42 wrote:
    The backup destination is an OpenSolaris ZFS directory shared with netatalk.
    That doesn't sound like a supported destination for Time Machine backups. See Apple's Disks that can be used with Time Machine.
    You'll probably need to find someone familiar with the OpenSolaris OS.

  • Automatic updates for non-admin users (again)

    Hi all,
    My users are logged in with non-admin accounts on Windows 7.
    They know the password of an admin account.
    I would like Adobe flash player to automatically remind them of updates and allow them to install those updates, if necessary by entering the password for an admin account.
    Is this possible? How do I do this?
    Thanks
    Tom

    Hi, It is the Account that must have the Privileges. Take a look at this Troubleshooting Guide. Page down to Advanced Troubleshooting.
    I think that will explain what you need.
    Using the automatic Flash Player notification in the Global Settings is an easy way. However it checks also for Permissions when Uninstalling/Installing.
    Hope that helps.
    eidnolb
                        EDIT: I guess it would help if you had the link: http://kb2.adobe.com/cps/191/tn_19166.html    
    Message was edited by: eidnolb   adding link

  • Applet does not run for non-admin users

    When logged in as a normal user, our applet fails to run. When logged in as a local admin, the applet runs successfully. The client machine is running Windows XP and IE 8.
    The java console contains this error message when it fails:
    JNLPAppletLauncher.loadLibrary("jogl")
    Exception in thread "AWT-EventQueue-3" java.lang.UnsatisfiedLinkError: jogl
    at org.jdesktop.applet.util.JNLPAppletLaunc her.loadLibrary(JNLPAppletLauncher.java: 1922)
    at sun.reflect.NativeMethodAccessorImpl.inv oke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.inv oke(Unknown Source)
    at sun.reflect.DelegatingMethodAccessorImpl .invoke(Unknown Source)
    at java.lang.reflect.Method.invoke(Unknown Source)
    at com.sun.opengl.impl.NativeLibLoader.load LibraryInternal(NativeLibLoader.java:174 )
    at com.sun.opengl.impl.NativeLibLoader.acce ss$000(NativeLibLoader.java:49)
    at com.sun.opengl.impl.NativeLibLoader$Defa ultAction.loadLibrary(NativeLibLoader.ja va:80)
    at com.sun.opengl.impl.NativeLibLoader.load Library(NativeLibLoader.java:103)
    at com.sun.opengl.impl.NativeLibLoader.acce ss$200(NativeLibLoader.java:49)
    at com.sun.opengl.impl.NativeLibLoader$1.ru n(NativeLibLoader.java:111)
    at java.security.AccessController.doPrivile ged(Native Method)
    at com.sun.opengl.impl.NativeLibLoader.load Core(NativeLibLoader.java:109)
    at com.sun.opengl.impl.windows.WindowsGLDra wableFactory.<clinit>(WindowsGLDrawableF actory.java:60)
    at java.lang.Class.forName0(Native Method)
    at java.lang.Class.forName(Unknown Source)
    at javax.media.opengl.GLDrawableFactory.get Factory(GLDrawableFactory.java:106)
    at javax.media.opengl.GLCanvas.chooseGraphi csConfiguration(GLCanvas.java:520)
    at javax.media.opengl.GLCanvas.<init>(GLCan vas.java:131)
    at javax.media.opengl.GLCanvas.<init>(GLCan vas.java:90)
    at gov.nasa.worldwind.awt.WorldWindowGLCanv as.<init>(WorldWindowGLCanvas.java:50)
    Java on Windows XP attempts to store the native libraries it downloads at C:\Documents and Settings\<USER>\Local Settings\Temp\
    Non local admin users do not have access to this folder. Is there any way to change the applet launcher so that it stores the native lib cache elsewhere?
    Thanks,
    Jeremy

    user11193214 wrote:
    JNLPAppletLauncher.loadLibrary("jogl")
    ..Non local admin users do not have access to this folder. Is there any way to change the applet launcher so that it stores the native lib cache elsewhere?I don't know. One thing I do know is that the JNLPAppletLauncher since plug-in2 architecture JREs allow hooking into JNLP services. Try using web start to launch the applet.

  • Solution: Software Update Notifications for Non-Admin-Users

    This is a follow up to [that thread|http://discussions.apple.com/thread.jspa?threadID=1642646].
    Problem:
    Since I'm using Mac OS X the software update notification only appears if you are logged in as an user with administrative rights. In a real multiuser environment this makes sense, because the ordinary user should not be confused with things he's not responsible for. But what about the situation with the typical single user machine, where the owner uses a non-admin account for normal work. In this case this user IS the administrator, although he's using a non-admin account. In this very common case the user should get the software update notifications as he/she can react to it. But even if "Check for updates" is selected in System Preferences, there will be no notifications. You can argue if this is a bug or not.
    Solution:
    I wrote a little applescript (in fact it's embedded into a launchd plist file, so you only have to care about one file), that checks once per day if there are any software updates available. If so, they are displayed in a nice looking Growl notification, if Growl is installed (highly recommended!), or in a standard system dialog. This works for any user. I'm using it for over a year now without any problems and decided to make it available to everybody. You can download it [here|http://blog.kaputtendorf.de/2009/02/22/updatecheck>.
    Best regards,
    Sven

    good job! I also suggest you submit this to mac os x hints.
    http://www.macosxhints.com/

  • Why Bridge CS5.5 is opened and not CS6 is opened for non admin user?

    Hi,
    I have CS5.5 updated to CS6 on my computer but CS5.5 version of Bridge is opened instead of CS6. This happens when I try to open CS6 version of Bridge by  using the CS6 icon, selecting CS6 version from the program list of Windows 7 and selecting the CS6 version from file manager. I did a quick check to try other programs and e.g. Photoshop, Illustrator start with CS6 version.
    My user account doesn't have the admin rights for the computer. When using on the same PC with admin account Bridge CS6 version is started as expected. Therefore this has something to do with admin rights. Therefore please instruct how to do the set up for user not having administrator rights.

    Hi,
    Just to update on the solution on this in case somebody else encounters this issue and searches the discussions for the solution.
    The reason for this was that in the Bridge CS5 advanced preferences it was set to start Bridge CS5 at logon automatically. Removing that solved the issue.
    My thanks to the Adobe support on pointing this one.
    Br, Juha

Maybe you are looking for

  • How can I get access to my Macintosh HD

    Hi! I tried to boot my Macbook, but it went straight to OS X Utilities. Now, i could not repair the disk called "disk0s2", and my Macintosh HD is not showing up on the left panel. I tried to reinstall the OS but the only HD that appeard were the Reco

  • Error when activating the master data

    Hi I am getting the following error when activating the master data. when using IDOC as transfer method in transfer rules <b>Error while creating table 'EDISEGMENT' entry '/BIC/CIRB0CLASS_NUM_TEXT'</b> If anyone came across this kind of problem plz s

  • Error unknown message when saving ai file

    Several days ago I got an external hard drive to backup. Had an error message saying all wasn't saved right. I use CS2 suite, all works fine except my illustrator files will not save as ai. They will save as jpeg, pdf, eps, but not ai. Error unknown

  • IMac G5 20" Hard Drive Replacement?

    Hi all, My brother has a 20" iMac G5 with a Maxtor HDD. It's a couple of years old and he doesn't have an AppleCare on it. The hard drive has been acting a little funny lately and I've had some bad experience with Maxtor in the past so I'm interested

  • Problem - different classes in a custom list

    Hi, Im making a school project and must use this List-class, written by some of our teachers. The problem is, the nodes in the list are type of Objects, and i must store multiple types of classes in the list. Storing works fine, but when i want to do