Administrative user only for install software but prevent intercative session

Hello,
as an university, we are not allowing domain users di write anything on the C:\ drive on our Win7/64 PCs; therefore users are unable to install any software and that is what we - usually - want.
But there are some users (researchers, Teachers or labs) who sometimes need to install software in order to test it. So we created on their PCs a local user "install" as member of the local administrator Group. They should use it when
UAC prompts them to give administrative rights to install software or with the "Run as administrator" right click. This works fine but unfortunately we noticed that many users are using the "install" account to do their daily work, so they
are working the whole day long with the highest privileges and we do not want this for obvious security reasons.
We want to leave the administrative user "install" for the software installation purpose but we want prevent users using it interactively; we couldn't find a way to do this. Is it possible ?
In order to discourage users, we also made some tests giving the "install" local user, deny permission on the start menu, desktop and some other folders, so that they couldn't find programs and be very limited in using the installa account
interactively, but this does not give the expected results (for example the user is able to create a folder on the desktop after a couple of popus warnings, or the start menu is not completely empty).
Any ideas ?
Thank you in advance.
Best regards,
Eric

Hi,
In my opinion, you can try to use AppLocker to accomplish this task. You can create a new pricple the allow specific user or group install application. Also the type of about to be installed app could be customized.
You can allocate User group app install permission to make sure they could install APP unrestricted but doesn't have administrator rights.
Please refer to the link below for more details about APP Locker:
http://technet.microsoft.com/en-us/library/dd723678(v=ws.10).aspx
Roger Lu
TechNet Community Support

Similar Messages

  • User Status for Installed Base

    Hi All,
    Pls let me know where to maintain user status for installed base. I believe status profile could be assigned to transaction level only but still SAP help says it is possible to maintain in installed base.
    Also let me know is it possible to maintain user status for induvidual objects.
    Regards
    Ram.

    Hi Ram,
    In Spro, under the option "Define Installed Base Category and Installation Rules" you have an option to assign status profile to ibase category.
    In ibase the user status can only be maintained at header level according to standard. Further information available in SPRO documentation.
    Best Regards, Adil

  • Hi I bought a copy of both Photoshop and Premiere Elements in 2013. I've only just installed  Premiere, but each time I try to open it, it requires sign-in to Adobe Cloud. I enter the details (I've checked these again and again) but it never connects, and

    Hi I bought a copy of both Photoshop and Premiere Elements in 2013. I've only just installed  Premiere, but each time I try to open it, it requires sign-in to Adobe Cloud. I enter the details (I've checked these again and again) but it never connects, and I cannot use the software. Can you help? Thanks, Tony

    Hi,
    Can you please elaborate what happens when you try to Sign in?
    Also , Can you please share the following logs at [email protected]:
    Go to %temp% folder and share PDApp.log , oobelib.log and amt3.log
    Thanks,
    Shikha

  • Thank you for installing itunes but itunes didn't install

    I recently re installed Windows 7 and attempted to install itunes. I receive the message,"Thank you for installing itunes but itunes failed to install. Can you help?

    This happens to me on several Windows PCs.  Some running Win7.  Some running WinXP. 
    I found that by using Safari, I could successfully download iTunes.  Didn't work on any other browser I tried - only Safari.
    Been that way for the past three iTunes updates.  Annoying but I can work around it rather easily.
    Best of Luck

  • IMac with Lion. I have an icon on the dock for Fluenz software but it has a white circle around it with a white slash through it (like the international "no" sign).  What does the circle mean?

    I have an iMac using Lion. I have an icon on the dock for Fluenz software but it has a white circle around it with a white slash through it (like the international "no" sign).  What does the circle mean?  The Fluenz software seems to work ok.

    Checkout the software vendor's website for updates:
    http://fluenz.com/commons/beta-forum/posts/free-lion-upgrade-fluenz-updates-page
    Your only other option is to boot from an OS X 10.6 system.
    Hope the link helps.

  • HT204387 I have brought a iPhone 5s and installed software but my bluetooth is not working. Please help me

    I have brought a iPhone 5s and installed software but my bluetooth is not working. Please help me

    What are you trying to connect the iPhone to and what is happening when you try?

  • HT2404 i pay for my software but not download

    i pay for my software but not download yet...

    If you're talking about Mountain Lion it can take a few hours (or more) for the download to complete.

  • HT201364 Hi, I have all the specs for installing Mavericks but it wont do it. Would upgrading first to Mountain Lion help?

    Hi, I have all the specs for installing Mavericks but it wont do it. Would upgrading first to Mountain Lion help?

    Are you sure?
    Upgrading to Mavericks
    You can upgrade to Mavericks from Lion or directly from Snow Leopard. Mavericks can be downloaded from the Mac App Store for FREE.
    A. Upgrading to Mavericks
    To upgrade to Mavericks you must have Snow Leopard 10.6.8 or Lion installed. Download Mavericks from the App Store. Sign in using your Apple ID. Mavericks is free. The file is quite large, over 5 GBs, so allow some time to download. It would be preferable to use Ethernet because it is nearly four times faster than wireless.
          Macs that can be upgraded to OS X Mavericks
             1. iMac (Mid 2007 or newer) - Model Identifier 7,1 or later
             2. MacBook (Late 2008 Aluminum, or Early 2009 or newer) - Model Identifier 5,1 or later
             3. MacBook Pro (Mid/Late 2007 or newer) - Model Identifier 3,1 or later
             4. MacBook Air (Late 2008 or newer) - Model Identifier 2,1 or later
             5. Mac mini (Early 2009 or newer) - Model Identifier 3,1 or later
             6. Mac Pro (Early 2008 or newer) - Model Identifier 3,1 or later
             7. Xserve (Early 2009) - Model Identifier 3,1 or later
    To find the model identifier open System Profiler in the Utilities folder. It's displayed in the panel on the right.
         Are my applications compatible?
             See App Compatibility Table - RoaringApps.

  • Allow local user to install software but deny logon

    So my requirement is that regular users are not allowed to install software on a computer, but if they want to install they could if an admin would come and enter admin username and pw on popup after they try to install something. Also 2nd requirement is
    that admin user is not allowed to logon locally. So i figured i'll create local admin and deny him logon locally but then when try to install software it tells me that i don't have required logon right to do this action. Is there a way i could achieve this?
    Thank you!

    You first requirement can be satisfied by configuring UAC.
    you second requirement can be set in security options. I would NOT recommend denyiong logon to the group administrators. instead you should create a custom (AD) group to contain your administrators. make it member of the local administrator group(s) (posibly
    using 'restricted groups' GPO) and deny log on as you like through user right assignment (also possible by GPO)
    MCP/MCSA/MCTS/MCITP

  • I don't recall always having to enter admin. name and p/w when doing updates. Is this req't only for certain software. I am a bit paranoid now with the Mac Defender lurking about.

    When completing the software updates I can't remember always having to enter administrator name and password. Maybe it's just been automatic on my part but now I rethink the process when I am asked to enter this info since the Mac Defender malware became an issue with Mac. Just wanted to know if this procedure occurs with all software updates or is it selective based on the type of update? This time is concerned Airport. Thanks for any insight.

    Are you running as an Admin User or non-Admin? ie. have you set your Mac up with multiple user accounts - one as an Admin and one as a Standard user?
    For security, you are better off having an Admin user account that has Admin privileges and a Standard user account that you use from day to day with standard privileges. When you install system updates you will be required to enter an Admin name and password, and any software that needs access to the system will require an Admin name and password, but anything that you install just for your user account that doesn't require total system access will be able to be dragged and dropped into your Application folder as per usual.
    MacDefender runs in a web browser - that should be a huge red flag! If you see a warning when you are running Safari or another web browser close the browser window or Force Quit it. (under the Apple Menu => Force Quit...) In Safari Preferences untick Open "safe" files after downloading. (It will prevent an installer from automatically launching if something nasty is downloaded to your machine.) MacDefender and its variants attempt to trick people into installing stuff that will compromise their system. If something pops up unannounced on your machine that you didn't download, close it and delete it.
    This article goes into depth about the MacDefender Malware:
    http://rixstep.com/2/20110610,00.shtml
    The salient points are summed up in the "Recapitulate" section at the bottom of the article: It's a bit Hipster Geeky.
    "To Recapitulate
    As recounted elsewhere, the Mac Defender attack is a well thought out attack that may have taken months to get together. The first step was to compromise websites of eejits, hack their FTP accounts, and upload dynamited files to their servers.
    Then followed the Google whacks which led to people clicking on links they'd provided at the sites they'd hijacked.
    And then finally they uploaded Mac Defender so people would get hit by it. And the purpose of Mac Defender is to scare you into thinking you're infected so you pull out your credit card.
    Then the hackers run away with your credit card info and buy mink coats and chinchilla coats or whatever they want.
    But staying clear of Mac Defender is really easy and doesn't require any AV software.
    Don't ever open anything you didn't want to download.
    Turn off JavaScript when accessing any Google Images site.
    Make sure you don't have Safari set to automatically open downloads."
    I'd add, keep your software up to date. Especially Adobe's Flash Plug-in as this is no longer supplied in system updates by Apple and could become an attack vector in the future. Always download software from reputable sources - ie. when downloading the Flash plug-in, get it from Adobe directly - don't follow a link from a website that tells you your version of Flash is out of date.
    Enable your Firewall in System Preferences => Security => Firewall. Click on the Advanced button and Enable Stealth Mode too.
    Also under:
    System Preferences => Security => General.
    Disable Automatic Login. Require a password to unlock each System Preferences pane. Use secure virtual memory. Automatically update safe downloads list.
    Educate yourself.

  • For installing software packages, long delay in recognizing startup disk

    I have found that any time I install software using an installer package (e.g. flip4mac) on my iMac, there is a long delay before my startup disk is recognized as a valid installation location. All of the other drives are evaluated immediately, but I'd say it's about 20 seconds before I get the option of my startup disk (green arrow pointing down at a picture of a hard drive).
    Does anyone know what is causing this and how I might alleviate the problem? It's annoying, and I wonder if it's a sign of some deeper problem.
    I do have a bootcamp partition that I rarely use, and I have an external USB drive that I use for time machine backups.

    The more external storage devices you have connected to your computer the longer it's going to take to for your computer to evaluate which volumes it can install on. Short of dismounting the external HD's first this is the price you will be paying for all the external devices. BTW I'm in the same boat, I have 3 EHD's daisy chained together using FW 800.

  • Need a SCCM SQL Query Report for Installed Software with Packages and Applications.

    I need a report that will show the number of installs of all of the workstations applications and packages over a given period of time. 
    This will let us know how effective our deployments are and how well the on-demand software is being adopted.
    Any help?

    Your Install Source might be an option as most SCCM deployments will install from C:\Windows\ccmcache\xx [where xx is a random folder name]. Most software vendors will put an install source in the registry, but not all do, so it won't be completely accurate.
    When software is installed manually, the install source path won't be C:\Windows\ccmcache\xx.
    Here is a SQL query I have for Install Source:
    SELECT v_GS_COMPUTER_SYSTEM.Name0 as 'Computer Name', v_GS_INSTALLED_SOFTWARE.ProductName0 as 'Software Title', v_GS_INSTALLED_SOFTWARE.InstallSource0 as 'Install Source', v_GS_INSTALLED_SOFTWARE.ProductVersion0 as 'Version', v_GS_INSTALLED_SOFTWARE.InstalledLocation0
    as 'Installed Location', v_GS_INSTALLED_SOFTWARE.InstallDate0 as 'Install Date'
    FROM v_GS_COMPUTER_SYSTEM INNER JOIN v_GS_INSTALLED_SOFTWARE ON v_GS_COMPUTER_SYSTEM.ResourceID = v_GS_INSTALLED_SOFTWARE.ResourceID
    WHERE v_GS_INSTALLED_SOFTWARE.ProductName0 like '%Office 365 Pro%'
    ORDER BY v_GS_COMPUTER_SYSTEM.Name0

  • How to create a valid database User/Group for installing Linux 5,3

    HI:
    I am trying to install E-Business Suite on LINUX and gave me the following error report
    Unable to validate Database User/Group :oralce /dba
    Provide a valid Database User/Group for the installation.
    when I was installiing on Windows, it did not gave me this error.
    How do I have to crate a user/Group to install eBusiness on my Linux/
    Please help
    Ali

    Hi user;
    hi Ali;
    Yes I run as a root userKeep using root
    When I use the following at the terminal
    It gave me a error message
    " Provide a valid Database User/Group for the installation. "
    Here is what I type at the terminalIts seems normal becouse u try to create same user!
    root@vis groupadd dba
    root@vis useradd -g dba -d /home/oracle vis
    root@vis useradd -g dba -d /home/oracle oracle Try this plz:
    groupadd dba << i think this group already created!
    useradd -g dba -d /home/applmgr applmgr << for apps node
    useradd -g dba -d /home/oramgr oramgr << for db node
    As you notice we define 2 different user under /home path!
    Regards
    helios

  • New nano - installed software but after that, the assistant never popped up

    brand new nano; installed software and it says the "assistant" is supposed to pop up and tell you to connect nano. assistant never popped up, but software installation said it was successful. so i connected ipod. now it's been sitting there connected and charging FOREVER and says "do not disconnect." shouldn't it be doing something by now?

    Does it show up in iTunes?

  • How to authorise users only for specific GL accounts

    Hi friends,
    My client does not want his endusers to see all the GL accounts' balances, they want to restrict them from looking at certain GL a/cs .From my security person I came to know that we cant restrict them only for certain GL accounts, it could eithre be all or none.
    I dont agree with that.
    Please guide if you know anyhitng about it.
    Thanks
    Shefford

    You can use the Authorization Group field in the G/L account master record (field SKB1-BEGRU, free text field) for this purpose. You can then use authorization object F_BKPF_BES to manage the different authorizations.
    Click <a href="http://sap.ittoolbox.com/groups/technical-functional/sap-acct/authorisation-based-on-gl-accounts-727160">here</a> for more information.
    Points are appreciated.
    Kind regards,
    Lodewijk

Maybe you are looking for

  • LED monitor and a 2007 mac pro compatibility

    My mac monitor is busted, I need to get a new one, though this time it won't be an apple one.  I have a 2007 mac pro, what I need to know is a LED monitor compatible with my mac pro.  For instance, this one, http://www.amazon.co.uk/gp/product/B005MHM

  • My mozilla mainpage keeps getting taken over by bing and I cant stop it-help!

    I have a mozilla mainpage with google. every time I try to "google", bing pops up instead and takes over and it wont go away. I cant use any other search engines-this just started and i swear it's a microsoft virus the way it acts.

  • Functional specs for customer hierachy

    Dear Gurus, I need to develop functional specs for customer hierarchy.the requirement is to create a new hierarchy type and move all the existing records from the present customer hierarchy setup since the present system has lot of scrap data.for thi

  • Cannot Install OS 9 After Installing Tiger ???

    I've recently upgraded from a Beige G3 MT to a G4 Digital Audio. When I received the G4, it had OS 9.2 on it. Having larger (newer drives) in my G3, I swapped the 30GB in the G4 for 200 & 80GB drives that I had in the G3. Both drives are on a ATA/133

  • Where can I find the field "Code" in PPOMA_CRM? what table?

    Hi Experts, I need to extract the Organizational Structure from PPOMA_CRM to BW. I know HRP1000 and HRP1001 are the main tables related to this transaction code, but I think they are not enough to suit my requirements. My OS tree is: Country->Region-