Administrative rights to Windows Server

I know that we need administrative rights to a window box during
installation and configuration.
After cutover to production, is it possible for the DBA to survive if
administrative rights are revoked?
What daily/often-run tasks will be affected?
Thanks for any suggestion.
PS (Our system admin has taken away admin rights from the DBA, so far, we
are able to identify 10 problem areas, but all of them have workaround/fixes
of some sort).

There's difference between Local and Domain user in windows environment.
Local user with ORA_DBA should be able to do most Oracle administrative tasks.
However, Oracle DBA account is usually given local administrator privilege on the server.
Check more information in metalink doc Note:77665.1

Similar Messages

  • Administrator rights running Windows XP under bootcam[

    I have Win XP running under boot camp and it runs beautifully. I do have several programs that are giving me warning messages regarding Administrator rights. I am logged in as administrator under windows. Is there some difference that I need to be aware of when setting up administrator rights under Windows/Bootcamp?
    Thanks,
    Dale Roach

    Since Fusion is not an Apple product, you might want to ask in VMware Fusion
    http://communities.vmware.com/community/vmtn/desktop/fusion

  • Administrator rights problem Windows 2008 R2

    Hello,
    I have a problem on a Windows 2008 R2 server member of a workgroup. It seems to be a rights problem. I have the problem with all accounts (administrator, another account member of administrators group and any other new account created for testing member
    of admin group or not).
    When i click on the explorer button in the task bar, an error message is displayed and explorer is not launched : Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item.
    Same message if i double-clic on explorer.exe in c:\windows folder. I can browse my computer by using the "my computer" in start menu.
    When i launch internet explorer, it crash immediately, the window is closed.
    If i launch the disk management console, i have a message : You do not have access right to Logical Manager
    I have tryed to install the update KB2444677 and it fails with an access denied error.
    UAC have always been disable but now i cannot launch c:\Windows\system32\UserAccountControlSettings.exe. When i double clic on the icon nothing happens.
    I have disabled IE ESC but no change.
    The problem occur also under safe mode.
    Anybody have an idea about this problem ?
    Regards

    Hi PimPamPoum_59,
    Please also try Go to component Services à Right Click My Computer
    à Properties
    à Default Properties
    à Make sure Default Impersonation level is set to 'Impersonate'
    in windows server 2008 r2.
    For the more detailed information, please refer to this thread:
    Windows Server 2008 - Unable to access Disk Management and other components - MMC Snap-in problems:
    http://social.msdn.microsoft.com/Forums/windowsserver/en-US/d1576093-e000-45c5-a047-d06a5dd6f9f4/windows-server-2008-unable-to-access-disk-management-and-other-components-mmc-snapin-problems?forum=winserver2008appcompatabilityandcertification
    I hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Downgrade Rights Of Windows Server

    Can I downgrade from Windows server 2012 to Windows 2008 , I got an update from the customer representative that I can do it, but they told me to check for the downgrade rights. I just want to know that how can I check that whether I have downgrade rights
    or not and I also want to know how can I downgrade .

    Hi,
    Customers who have licensed software through a Microsoft Volume Licensing program are eligible to use prior versions of the software edition that they have licensed. This is known as a downgrade right.
    If you have legally obtained physical media (CD/DVD) of older licensed Microsoft products that your organization is currently licensed to use through downgrade rights, you can use these prior software versions at your discretion.
    With the release of new product versions, previously available products are removed from the VLSC as they become N-2 versions. Support for physical media purchases of these N-2 products through Microsoft also ends at that time.
    If your organization continues to require access to specific prior version products, we recommend that you first contact your Microsoft reseller to determine whether they still have media inventory. If you received past shipments of physical Volume Licensing
    media (comprehensive or subscription kits) or purchased physical CD/DVD media, you can continue to use these discs to install prior versions of products that are no longer available from the VLSC.
    for oem licenses, Downgrade rights are documented in the Microsoft Software License Terms that
    customers accept upon first running Windows and Windows Server software. Thanks
    to downgrade rights, end users who have acquired a later version of the software (such as Windows Server 2012 R2 Standard) can use an earlier version of the software (such as Windows Server 2008
    R2 Standard) until they are ready to migrate to a later version Technology.
    To downgrade Windows Server software customers must:
    Purchase a Server system licensed with Windows Server software.
    Accept the Microsoft Software License Terms.
    Perform the downgrade or down-edition process to the eligible
    downgrade/down-edition product using the media/key from a genuine, previously
    licensed OEM, retail or Volume Licensing Server product.
    thanks
    diramoh

  • User Accounts in Domain Admins group do not have full administrative rights to the server

    Our server was fine until recently one day we lost admin access for admin user accounts. If we log in to the server with the Domain Admin account, this account has full admin access to the server and can install and launch all programs and even all server
    admin tools. If we log into the server with a user account which is in the Domain Admins group, that account cannot install software or launch Services.MSC. Even IE will not load any page and crash with a "Not Responding" Error.
    The server has no viruses we even ran SFC /SCANNOW and it did repair from corrupted files but that didn't fix the issue.
    Any ideas?

    Hi Rick,
    May be UAC is blocking installtion. Have it disabled and see if it helps.  Ensure you have domain admin groups added into local administrators group.
    Alos Check these links please.
    https://social.technet.microsoft.com/Forums/en-US/b5300f28-6a2a-4760-8b80-97a2da0f87c1/2012-domain-admin-user-cannot-install-programs-on-a-domain-windows-7-pc?forum=winserverDS
    https://social.technet.microsoft.com/Forums/en-US/0ca040de-52ac-4259-bf78-c22436fd04d4/domain-users-with-domain-admins-right-cannot-install-programs-or-open-server-manager?forum=winserverDS
    Thanks,
    Umesh.S.K

  • Enabling Windows Server 2008 R2 Built-In Administrator Account

    The properties box for my Windows Server 2008 R2 built-in administrator program says the account is disabled.  Even the primary user account has virtually no priveliges.  How can I, with a mere primary user account available at logon, enable
    the built-in administrator account, or otherwise grant my primary user account administrator priveliges?  Windows Server 2008 R2 denies my primary user account access/permission for nearly all changes to accounts, programs and OS features. 
    Stephen W Plunkett

    The properties box for my Windows Server 2008 R2 built-in administrator program says the account is disabled.  Even the primary user account has virtually no priveliges.  How can I, with a mere primary user account available at logon,
    enable the built-in administrator account, or otherwise grant my primary user account administrator priveliges?  Windows Server 2008 R2 denies my primary user account access/permission for nearly all changes to accounts, programs and OS features. 
    Stephen W Plunkett
    In some of the organisations, default admin accounts on member servers are purposefully locked/disabled through group policy for security reasons.
    If you know the password for locked out/disabled admin account then there is a possibility of unlocking/re-enabling the account without using any third party tools.
    To do that,
    Restart the server
    Press F8 and select Safe Mode Without
    Networking
    Log on to the server with locked out/disabled admin account with its password.
    If you could successfully log on to the server then you will have option to unlock and enable the built-in admin account !
    Most of the downtime's are caused because of SysAdmin's curiosity ! - Santosh

  • Windows Server 2012 Essentials Connector version is more current than server

    In trying to connect a new laptop to domain/server, it kept failing with a message indicating that other software was in the process of installing or that a reboot was pending.  Since neither was the case, I downloaded the current version of the Connector
    software from the Microsoft website to try.  That didn't work either.  It turns out that a pre-installed software component called Intel Smart Connect Tech was keeping the laptop from connecting.  I uninstalled this software and installed the
    connector software and it appeared to connect to the server.  However, it is displayed in the Essentials Dashboard as Offline.  The client (Laptop) displays a message saying "The Windows Server 2012 Essentials Connector version that is installed
    on this computer is more recent that the sever.  Contact the administrator to ensure the server is up to date".  I tried uninstalling the Connector software from Control Panel, but I get a message "Could not delete key \software\microsoft\windows
    server.  Verify that you have sufficient access to that key, or contact your support personnel".  I've tried both with domain admin and local admin credentials.  So, I ignored the message and continued the connector install.  It finished
    and appeared to connect successfully.  The connector version displayed in Control Panel\Programs and Features is correct.  However, the registry entry is not updated and the version error pops up with each login and the Dashboard shows the client
    as offline. 

    Hi C.R.Lowe,
    Based on your description, I’m a little confused with this issue. Before going further, would you please let
    me confirm something more? Thanks for your understanding.
    When connect the client to Windows Server 2012 Essentials, did you mean that use
    http://<servername>/Connect
    and then select Download software for Windows option? More descriptions, please refer to the following article.
    To connect a client computer to the
    server
    If I misunderstand, please don’t hesitate to let me know.
    On current situation, please navigate to the registry path as the error message shows. And check
    Version value and let me know. Meanwhile, please right click
    Windows Server folder in Registry Editor and select “Permissions…”, then check if the account was assigned the correct permission to delete key.
    In addition, please check if you have installed the
    Update Rollup 1 for Windows Server 2012 Essentials
    By the way, please check Event Viewer and some related logs if can find some more clues. If any update, please
    feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

  • Running an External Program from Batch on Windows Server 2008R2 Failing

    Hi,
    I am trying to run an external program from a batch job and it is failing with this error message:
    Ext. prog.: ERROR: Input redirection is not supported, exiting the process immediately.
    Ext. prog.: External program terminated with exit code 1
    The program I am trying to run is:  timeout
    This command works on the OS: timeout -t 30
    I have setup the step to look like this:
    Under External Program:
    -Name: timeout
    -Parameter: -t 30
    I have also tried:
    -Name: timeout -t -30
    -Parameter:
    I am running ECC 6.04 on top of Windows Server 2008R2 with SQL Server 2008R2. 
    When we were running in Server 2003 on ECC 6.0 I was able to use the Sleep program just fine in the same manner.  I have found out that sleep is not available in server 2008.  It was replaced with timeout.
    After an update to EHP4 and moving to Windows Server 2008R2, Is there any pre-work that needs to be done on the SAP or Windows side before we can run external programs?
    Thank you,
    Neil

    > SAPService<SID> and <SID>ADM both have Administrator rights for the server.
    > That means they should have full access.
    No - this is no more true like that since Windows 2008, it's a bit more complex:
    http://en.wikipedia.org/wiki/User_Account_Control
    > Where would you setup the permission/policy to "interact with the desktop"?
    Add the policy using group policy editor (gpedit.msc)
    Markus

  • [Forum FAQ] How to install and configure Windows Server Essentials Experience role on Windows Server 2012 R2 Standard via PowerShell locally and remotely

    As we all know,
    the Windows Server Essentials Experience role is available in Windows Server 2012 R2 Standard and Windows Server 2012 R2 Datacenter. We can add the Windows Server
    Essentials Experience role in Server Manager or via Windows PowerShell.
    In this article, we introduce the steps to install and configure Windows
    Server Essentials Experience role on Windows Server 2012 R2 Standard via PowerShell locally and remotely. For better analyze, we divide this article into two parts.
    Before installing the Windows Server Essentials Experience Role, please use
    Get-WindowsFeature
    PowerShell cmdlet to ensure the Windows Server Essentials Experience (ServerEssentialsRole) is available. (Figure 1)
    Figure 1.
    Part 1: Install Windows Server Essentials Experience role locally
    Add Windows Server Essentials Experience role
    Run Windows PowerShell as administrator, then type
    Add-WindowsFeature ServerEssentialsRole cmdlet to install Windows Server Essentials Experience role. (Figure 2)
    Figure 2.
    Note: It is necessary to configure Windows Server Essentials Experience (Post-deployment Configuration). Otherwise, you will encounter following issue when opening Dashboard.
    (Figure 3)
    Figure 3.
      2. Configure Windows Server Essentials Experience role
    (1)  In an existing domain environment
    Firstly, please join the Windows Server 2012 R2 Standard computer to the existing domain through the path:
    Control Panel\System\Change Settings\”Change…”\Member of. (Figure 4)
    Figure 4.
    After that, please install Windows Server Essentials Experience role as original description. After installation completed, please use the following command to configure Windows
    Server Essentials:
    Start-WssConfigurationService –Credential <Your Credential>
    Note: The type of
    Your Credential should be as: Domain-Name\Domain-User-Account.
    You must be a member of the Enterprise Admin group and Domain Admin group in Active Directory when using the command above to configure Windows Server Essentials. (Figure 5)
    Figure 5.
    Next, you can type the password for the domain account. (Figure 6)
    Figure 6.
    After setting the credential, please type “Y” to continue to configure Windows Server Essentials. (Figure 7)
    Figure 7.
    By the way, you can use
    Get-WssConfigurationStatus
    PowerShell cmdlet to
    get the status of the configuration of Windows Server Essentials. Specify the
    ShowProgress parameter to view a progress indicator. (Figure 8)
    Figure 8.
    (2) In a non-domain environment
    Open PowerShell (Run as Administrator) on the Windows Server 2012 R2 Standard and type following PowerShell cmdlets: (Figure 9)
    Start-WssConfigurationService -CompanyName "xxx" -DNSName "xxx" -NetBiosName "xxx" -ComputerName "xxx” –NewAdminCredential $cred
    Figure 9.
    After you type the commands above and click Enter, you can create a new administrator credential. (Figure 10)
    After creating the new administrator credential, please type “Y” to continue to configure Windows Server Essentials. (Figure 11)
    After a reboot, all the configurations will be completed and you can open the Windows Server Essentials Dashboard without any errors. (Figure 12)
    Figure 12.
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    Part 2: Install and configure Windows Server Essentials Experience role remotely
    In an existing domain environment
    In an existing domain environment, please use following command to provide credential and then add Server Essentials Role: (Figure 13)
    Add-WindowsFeature -Name ServerEssentialsRole
    -ComputerName xxx -Credential DomainName\DomainAccount
    Figure 13.
    After you enter the credential, it will start install Windows Server Essentials role on your computer. (Figure 14)
    Figure 14.
    After the installation completes, it will return the result as below:
    Figure 15.
    Next, please use the
    Enter-PSSession
    cmdlet and provide the correct credential to start an interactive session with a remote computer. You can use the commands below:
    Enter-PSSession –ComputerName
    xxx –Credential DomainName\DomainAccount (Figure 16)
    Figure 16.
    Then, please configure Server Essentials Role via
    Add-WssConfigurationService cmdlet and it also needs to provide correct credential. (Figure 17)
    Figure 17.
    After your credential is accepted, it will update and prepare your server. (Figure 18)
    Figure 18.
    After that, please type “Y” to continue to configure Windows Server Essentials. (Figure 19)
    Figure 19.
    2. In a non-domain environment
    In my test environment, I set up two computers running Windows Server 2012 R2 Standard and use Server1 as a target computer. The IP addresses for the two computers are as
    below:
    Sevrer1: 192.168.1.54
    Server2: 192.168.1.53
    Run
    Enable-PSRemoting –Force on Server1. (Figure 20)
    Figure 20.
    Since there is no existing domain, it is necessary to add the target computer (Server1) to a TrustedHosts list (maintained by WinRM) on Server 2. We can use following command
    to
    add the TrustedHosts entry:
    Set-Item WSMan:\localhost\Client\TrustedHosts IP-Address
    (Figure 21)
    Figure 21.
    Next, we can use
    Enter-PSSession
    cmdlet and provide the correct credential to start an interactive session with the remote computer. (Figure 22)
    Figure 22.
    After that, you can install Windows Server Essentials Experience Role remotely via Add-WindowsFeature ServerEssentialsRole cmdlet. (Figure 23)
    Figure 23.
    From figure 24, we can see that the installation is completed.
    Figure 24.
    Then you can use
    Start-WssConfigurationService cmdlet to configure Essentials Role and follow the steps in the first part (configure Windows Server Essentials Experience in a non-domain environment) as the steps would be the same.
    The figure below shows the status of Windows Server Essentials.
    Figure
    25.
    Finally, we have successfully configured Windows Server Essentials on Server1. (Figure 26)
    Figure 26.
    More information:
    [Forum
    FAQ] Introduce Windows Powershell Remoting
    Windows Server Essentials Setup Cmdlets
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

  • Need to provide local administrator access without domain administrator rights

    Hi All,
    I need to provide local admin access to one account in windows environment without providing domain administrator rights.
    Windows 2008 DC. Desktops : windows 7
    So that we can use this account to install agents like SCCM\SCOM in all servers & desktops.
    Need suggestions.

    Hi,
    I agree with Senne, in addition, we can also use net command to perform local group management.
    More information for you:
    Add a member to a local group
    http://technet.microsoft.com/en-us/library/cc772524.aspx
    How to Make a Domain User the Local Administrator for all PCs
    http://social.technet.microsoft.com/wiki/contents/articles/7833.how-to-make-a-domain-user-the-local-administrator-for-all-pcs.aspx
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Autologin on Windows Server 2008 R2 - local Administrator problem

    I needed an user to autologin on a Windows Server 2008 R2 server.
    Configured it following this guide: http://www.danj.co.uk/2011/06/enable-autologon-for-windows-2008-r2.html
    In addition I added the login information by using the Autologon tool from sysinternals: http://technet.microsoft.com/en-us/sysinternals/bb963905.aspx
    Now the user I configured autologins successfully. The only downside is that now you can login with the local Administrator account by just hitting enter, as it now doesn't check the password and instead has a blank one. I think this comes from the User
    accounts screen where I unticked the checkbox and also the Administrator account is listed. When trying to remove the local Administrator it tells me that it will delete the account. I don't want that.
    How do I keep autologin of the user I configured but also have the local Administrator account check his password?

    Hello,
    please see
    http://www.expta.com/2008/04/how-to-enable-autologon-for-windows.html
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • Administrator cannot change printer properties on "Advanced" tab from "Devices and Printers" on Windows Server 2012 R2

    Hello, dear Colleagues.
    User with administrators rights cannot change printer properties on "Advanced" tab from "Devices and Printers" on Windows Server 2012 R2. 
    If to launch "Devices and Printers" on server, all printer properties on "Advanced" tab are inactive (see screen below). 
    But I can change it manually with "Print Management". Features become active.
    The main purpose - to uncheck "Enable advanced printing features"  with powershell
    scripts.
    $erroractionpreference = "continue"
    $colPrinters = Get-Wmiobject -Class win32_printer -computername print_server -Filter "Name like 'printer1' or Name like 'printer2' or Name like 'printer3' or Name like 'printer4' or Name like 'printer5' or Name like 'printer6'" # get printers on server and filter with names
    ForEach ($objPrinter in $colPrinters) { # get printer details from WMI
    If ($objPrinter.RawOnly -ne "True") { # check that Advanced printing fetaures is turned on
    Write-host $objPrinter.Name
    Write-Host $objPrinter.RawOnly
    $objPrinter.RawOnly = "True" # Untick and update the object in WMI
    $objPrinter.Put()
    It works on Windows 7 workstation, but does not on print server Windows Server 2012 R2 with error
    Exception calling "Put" with "0" argument(s): "Generic failure "
    At \\print_server\c$\DisableAdvancedPrintingFeatures.ps1:8 char:17
    + $objPrinter.Put()
    + ~~~~~~~~~~~~~~~~~
    + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
    + FullyQualifiedErrorId : DotNetMethodException
    Can you help me with that? Look like somethings with rights.
    Thank you.

    Hello, Alan
    Morris.
    Thanks for your reply.
    I've tried to runs PS Script both locally and remotely, previously running Powershell ISE as Administrator.
    I've noticed interesting thing - if to
    check "Enable advanced printing features"
    manually thru Print Management snap-in, script works fine. But, time to time after some manipulations on print server, this advanced feature returns to enabled state automatically by system, I think. In this case PS Script does not work. Next, if to disable
    feature manually again (thru Print Management snap-in),
    and enable manually again, PS Script will work. Very strange situation.
    Thanks.

  • Windows Server 2000 Advanced - Administrator Password Reset/Recovery

    I took over tech job for church that has Windows 2000 advanced server environment that has mirrored hard drives...Previous tech or person that installed server does not want to play nice with the administrator password and changes have to be made...I
    do have an account without administrator privileges but that does not help...so I attempted to reset or blank the administrator with a password reset disk and was not successful...when the partition mounts (while using reset disk) it shows that the
    password has been blanked (*BLANK*) but it still does not work...I've also tried putting the hard drives in a regular desktop, used the password reset disk and administrator password showed to be blanked, so I blanked it again for
    safe measure, replaced the drives in server and was still not successful...please advise

    First of all thanks for your response Amy...Yes it is the domain controller and only server for 7 users and 6 computers...and yes you were right about the DSRM password getting blanked...was able to log into DSRM with blank administrator password but
    that did me no good as I was still not able to make changes to the domain because (you may already know) Active Directory is not available in DSRM (it says to logon with domain administration rights)...my goal is to obtain domain
    administrator access in order to make changes:  add/remove users and computer account (which is the password the previous tech will not provide)...since this is such a small domain do I need restore Active Directory to reset or get domain administrator
    access? Authoritative Restore?  Which method, as a system state backup has never been done?...please advise

  • Administrators unable to write to a text file created by another Administrator on Windows Server 2008.

    Why are Administrators unable to write to a text file created by another Administrator on Windows Server 2008?
     --- The Administrators already have full control so how do I fix this? ---
    Example:  On a Windows Server 2008 (SP1): user A (who belongs to the Administrators group) logs in and creates a directory C:\foo and creates a file readme.txt in the foo directory.  User B (also a member of the Administrators group) logs in and opens C:\foo\readme.txt in notepad. User B types something and tries to save the file. User B cannot save the file…an option to save as some other file name is presented. The security permissions of C:\foo\readme.txt show that Administrators have full control.  
    Work around 1: Explicitly add user B to have full control over the foo directory. The problem is that all the all other Administrators still need to be added (current and future).
    Work around 2: Change the Users security permission to be full control on the foo directory. (this seems dangerous!)
    It is interesting to not that this same procedure is not a problem in Windows Vista. (Any insight about the difference?)
    Sincerely,
    Ian 

    so there is no way to change this without literally shutting down the UAC?
    I have files that  I need to modify all the time, and it is very annoying to have to save as to my desktop modify and then copy and paste the file again.
    I would also rather not give myself permissions to the entire C:\ Drive even specified Folders or documents, etc......
    You can change these settings without bringing down the UAC
    <!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:0; mso-generic-font-family:roman; mso-font-pitch:variable; mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-fareast-font-family:Calibri; mso-bidi-font-family:"Times New Roman";} .MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-size:10.0pt; mso-ansi-font-size:10.0pt; mso-bidi-font-size:10.0pt; mso-ascii-font-family:Calibri; mso-fareast-font-family:Calibri; mso-hansi-font-family:Calibri;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} -->
    1.    Click Start, type gpedit.msc and press Enter.
    2.    Expand Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options.
    <!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:0; mso-generic-font-family:roman; mso-font-pitch:variable; mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4; mso-font-charset:0; mso-generic-font-family:swiss; mso-font-pitch:variable; mso-font-signature:-1610611985 1073750139 0 0 159 0;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; line-height:115%; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-fareast-font-family:Calibri; mso-bidi-font-family:"Times New Roman";} .MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-size:10.0pt; mso-ansi-font-size:10.0pt; mso-bidi-font-size:10.0pt; mso-ascii-font-family:Calibri; mso-fareast-font-family:Calibri; mso-hansi-font-family:Calibri;} @page Section1 {size:8.5in 11.0in; margin:1.0in 1.0in 1.0in 1.0in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;} div.Section1 {page:Section1;} -->
    3.    Double-click “User Account Control: Behavior of the elevation prompt for administrators in Admin Approval Mode” on the right pane.
    a.    Choose “Elevate without prompting” and click OK.
    b.    Double-Click “User Account Control: Admin Approval Mode for the Built-in Administrator account”, Click Enable, Apply and then OK
    c.     Double-Click “User Account Control: Run all users, including administrators, as standard users”,Click Enable, Apply and then OK
    Then reboot the Server. You should now have the ability to modify any document, etc....

  • ActiveSync requiring administrative rights to synchronize data with Windows Communication apps

    We are currently testing W8.1 Update 1 in our corporate environment and have run into an issue when attempting to synchronize the corporate exchange accounts with the Windows Communication apps (Mail, Calendar, People). The first problem we encountered was
    the requirement for each user to log into a Microsoft account just to access the Communication apps, this was handled through GPO by enabling the "Allow Microsoft accounts to be optional" policy. We could then launch the application, were prompted
    for exchange server information, but then upon attempting to synchronize received an error message stating that "To sync this account, you first need to make your Windows user account an administrator." Obviously we have no desire to make all of
    our users administrators, but for the purpose of testing we added the user account to the administrators group. The same error message appears! A quick search revealed that changing the UAC to a lower setting would resolve the problem, and sure enough we then
    received a prompt to Enforce Policies and synchronization completed.
    This can't possibly be the intention, that every Windows 8 user using ActiveSync is required to be an administrator and has to lower the UAC. We did determine that once synchronization has been configured, the administrative rights can be removed and UAC
    can be increased once again, but this is a ridiculous option.
    I would really appreciate an explaination of the reasoning if this is infact the intended setup, and if it is not, then what we are doing wrong. Thank you.

    Hi,
    In following article, you will see that the admin permission is required to do so:
    Activesync Working But Only For Some Users On Exchange 2007 / 2010
    http://alanhardisty.wordpress.com/2010/03/05/activesync-not-working-on-exchange-2010-when-inherit-permissions-not-set/
    Also, Microsoft's recommendation and best practice is that if you are a domain administrator that you have 2 accounts. One for your everyday user which is restricted in the same way that every other user is and a second for your administration role.
    Kate Li
    TechNet Community Support

Maybe you are looking for

  • Reading contents of called standard program

    Hi Experts, Calling Program: Zreport Called Program: Standard report (Note: with no Start-of-selection event. So, no Spool!). I need to read the content of one of the intrnal table of the called program inside my Zreport. Kindly guide how can I achie

  • Will Iphone 5s be compatible with Honda Accord HFL texting feature?

    The previous iphones does not support the Text/email function of Handa Accord 2013. Will the new update with iOs7 fix this issue?

  • Error Page After Run Project WebService onNetBeans4.1

    Hi All, I'm new to this group.. I'm working on Netbeans IDE5.0 Beta, and try following the steps to create a simple web service. But after creating the client application and packaging it , i got the following errors, case1: java.rmi.ServerException:

  • Relevant for Billing

    Hi. Any program o OSS note for modify the field Relevant for Billing (FKREL) of the table LIPS. Thanks.

  • Projects objet in SAP 2007A SDK ?

    Hi,   I'm trying to manage projects (OPRJ table) with the SAP 2007A SDK.  My server is running on PL38 and I can't find an object which will allow me to add, modify or delete a project.   I know that the SAP 2005A SDK doesn't have a project object.