Ntrights.exe Windows 2008 R2 Resource Kit Tool? Does it exist or is there something similar I can use?

I am running Windows Server 2008 R2 Standard as a DC
I am trying to add users/groups to the following local policies through a GPO, however I need to script it out using something similar to ntrights.exe. I do not want to do it through the GUI because this is going to be a re-occurring process.
Below are the policies I am trying to configure via some kind of command prompt. I do not think I can do this with PowerShell 2.0 even with the import-module grouppolicy cmdlets.
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Allow log on locally
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Debug programs
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Force shutdown from a remote system
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Shut down the system
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Change the system time
Computer Configuration\Policies\Windows Settings\Security Settings\Local Policies\User Rights Assignment\Allow logon through Remote Desktop Services
Would it be safe to copy the Windows Server 2003 ntrights.exe resource kit tool and try it on Windows Server 2008 R2? I am working on a virtual test lab environment so I can actually take a snapshot before hand but wanted your expert thoughts on it first.
Thank you in advance.

I found the solution.....You can actually use "quoted" host names in the templates instead of the SIDs. Make sure that for Domain User Accounts you specify the Domain prefix. For Local User accounts you can just specify the local user name.
The filename of the template that I made is LOCAL_SEC_TEMPLATE.inf
Here's what's inside that LOCAL_SEC_TEMPLATE.inf template:
[Unicode]
Unicode=yes
[Registry Values]
[Privilege Rights]
SeInteractiveLogonRight = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins"
SeDebugPrivilege = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins"
SeRemoteShutdownPrivilege = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins"
SeSystemtimePrivilege = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins","LOCAL SERVICE"
SeShutdownPrivilege = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins"
SeRemoteInteractiveLogonRight = "Administrators","XXDIGIHD\DigiOps","XXDIGIHD\Domain Admins","Remote Desktop Users"
[Version]
signature="$CHICAGO$"
Revision=1
[Profile Description]
Description=Local Security Template
Here's how I applied the template to the Local Security Policy: (You can use PowerShell or the regular command prompt)
SECEDIT /configure /db secedit.sdb /cfg "c:\LOCAL_SEC_TEMPLATE.inf"
Here's the link on using SECEDIT >> http://www.appdeploy.com/tips/detail.asp?id=23
Thanks for your help Gunter, this issue is solved.

Similar Messages

  • Windows 2008 R2, Internet Information Services: Changing security settings to change a folder's content by using PHP

    Hello,
    I would like to ask if somebody's there who could help me:
    I am a PHP developer from Stuttgart, Germany.
    In my PHP web application I want to edit text files by using PHP code.
    These files are created once (by me), so they exist before the PHP application is used by any web user.
    My PHP code reads out some text files and other text files' contents are changed.
    In my developer's environment (Windows XP, XAMPP) it works fine.
    So I'm sure my code is OK.
    But the productive system ist a windows server system (Windows 2008 R2 and Internet Information Services).
    And here it doesn't work! The text files' contents aren't changed.
    I know on windows based webserver systems I have to change the folders security settings
    (what I mean: the folders where the text files are placed). I must give the IIS system user (in the past it's name was IUSR..., now it is named otherwise) additional rights, so that it can change folders content.
    I did. But it doesn't work.
    Some years ago when we used Windows Server 2003 that was the solution that worked.
    Giving the IUSR right to change folders content. That was it.
    But what is new in Windows Server 2008 that it doesn't work?
    I think it must be very complicated. Could somebody help me?
    Thanks
    Tommy

    Hi,
    This is IIS related issue, so you may post in the IIS forum.
    And it seems like that you have already post there, please follow it up to get further assistance
    http://forums.iis.net/t/1208164.aspx?Windows+2008+R2+Internet+Information+Services+Changing+security+settings+to+change+a+folder+s+content+by+using+PHP
    Regards,
    Yan Li
    Regards, Yan Li

  • HT201335 I have an i mac early 2008 10. 8. 2 mountain lion. Is there any way i can do the mirroring to my apple tv.

    I have an i mac early 2008 10. 8. 2 mountain lion. Is there any way i can do the mirroring to my apple tv/ tv?

    Not natively. That requires the newer processor. You will have to use Airparrot
    http://airparrot.com/

  • My iphone 5 is not syncing with my laptop and windows 8. cant find an itunes app for my laptop. is there something i can get that will help with this

    My iphone 5 is not syncing with my laptop and windows 8. cant find an itunes app for my laptop. is there something i can get that will help with this?

    Lbo51380 wrote:
    cant find an itunes app for my laptop. is there something i can get that will help with this?
    Go here -> http://www.apple.com/itunes/download/

  • I purchased Adobe Creative Suite 3 Master Collection Design Across Media Upgrade for Windows at a business closing.  What do I need to find out before I can use it?

    I purchased Adobe Creative Suite 3 Master Collection Design Across Media Upgrade for Windows at a business closing.  What do I need to find out before I can use it?

    I couldn't tell you what you purchased, and it might even be difficult for an Adobe employee to do so.  The business could have a few options as far as what they might have purchased.
    Your best bet, considering what little you paid, will be to hand it over to someone you might sell it to and let them try it out.  If it works, then it works.

  • Installing DSEE 7 on Windows 2008 R2 SP1 64-bit does nothing

    Hi All,
    Has anyone been able to install DSEE 7 on Windows 2008 R2 SP1 64-bit? Is it supported?
    I followed the instructions and when run the command (as the Administrator) below nothing happen, it simply return an empty command prompt. Ms VC 2008 Redistributables (the one that come with the archive) is installed.
    dsccsetup.exe war-file-create
    dsccsetp.exe ads-create
    When run the same command using the same archive on Windows 7 64-bit it does prompt for further input or report error.
    Any suggestions or help would be much appreciated.
    Shane L

    Windows 2008 R2 is not listed as a supported OS in the release notes.
    http://docs.oracle.com/cd/E19424-01/820-4805/820-4805.pdf
    It lists:
    Microsoft Windows Server 2008 Standard Edition for x86 and x64 Service Pack 1
    Microsoft Windows Server 2008 Enterprise Edition for x86 and x64 Service Pack 1
    If you are able to go to the next version, it is listed as supported in the release notes for ODSEE 11g:
    http://www.oracle.com/technetwork/middleware/downloads/odsee-11gr1certmatrix-161592.xls
    I have not tried 11g on 2008 R2 myself, but if it is in the certification matrix, it should work.
    Hope that helps,
    Eric

  • How can I open multiple "non-merged" firefox windows? With IE, I would use the "-nomerge" option. Is there something similar for Firefox?

    I use a website in my daily work activities that I need to have multiple sessions of the website open at any given time. Natively, I cannot have multiple sessions open in a single browser (separated tabs or separate windows) without one session taking over the other. Internet Explorer has a command line option (-nomerge) that will allow me to accomplish what I need. The target line of the IE shortcut properties would look like this:
    "C:\Program Files\Internet Explorer\iexplore.exe" -nomerge
    Is there a similar solution for Firefox?
    I am running Windows 7, IE11 and Firefox 26
    Thank you in advance,
    Robert

    Hello rpvincent, try
    * firefox.exe -new-window <url>
    (the url is without < >)
    see also : http://kb.mozillazine.org/Command_line_arguments
    thank you

  • I have windows 7 and I have tried to download itunes three times, it wont work. Are there older versions I can use?

    I have windows 7, I have attempted to download Itunes three times. It will not work.

    Window's problem. The Apple Servers have work fine for the last 24 hour (apart from the Apple Support community forum update an hour ago).

  • The color replacement tool  does not exist in photoshop cs6

    Hi guys!
    I have a huge problem with my new photos hope cs6, it doesn`t have a Color replacement tool button, I mean this
    Icon
    In addition I searched category under brush tools but it doesn`t exist
    Just I have color replacement in
    Image > Adjustment> Replace color
    Is it the same with that tool

    Hi,
    the color-replacement tool is still there in CS6, "under" the brush-tool in the toolbar of photoshop-CS6.
    Reveal it by alt-click on the brush...
    did I understand your question right?
    If you want a tool-preset of the color-replacement like the other tool-presets in your screenshot,
    you choose the tool first and then you can make a new preset for your special color-replacement-tool,
    including size of your point etc...

  • Looking for Driver for HP 3500 Color Laserjet for Windows 7. Is there a Generic I can use?

    I've been checking HP for 18 months and can never locate a driver for this Printer. Does anyone have any suggestions?

    Hi,
    Unfortunately your product is not supported by Windows 7, and will not be supported in the future, as you may find by the document below:
    http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&taskId=115&prodSeriesId=...
    Say thanks by clicking the Kudos thumb up in the post.
    If my post resolve your problem please mark it as an Accepted Solution

  • Hi i have a LG 3D SMART TV that i was runing nero home media 4 from my old windows laptop, this software wont now run from my macbook pro, does anyone know if a program is available i can use preferably for free

    HI i recently purchased a macbook pro to replace my old laptop running windows.
    the problem i have is i have a LG SMART 3D TV which i was running nero media home 4 on from my old laptop, i have tried to install this program on my macbook but is it not compatible.
    does anyone know which program is available to run from my apple product to smart tv in a similar way..... preferable free
    regards
    steven

    First, back up all data immediately, as your boot drive might be failing.
    There are a few other possible causes of generalized slow performance that you can rule out easily.
    Reset the System Management Controller.
    If you have many image or video files on the Desktop with preview icons, move them to another folder.
    If applicable, uncheck all boxes in the iCloud preference pane.
    Disconnect all non-essential wired peripherals and remove aftermarket expansion cards, if any.
    Check your keychains in Keychain Access for excessively duplicated items.
    If you have more than one user account, you must be logged in as an administrator to carry out this step.
    Launch the Console application in the same way you launched Activity Monitor. Make sure the title of the Console window is All Messages. If it isn't, select All Messages from the SYSTEM LOG QUERIES menu on the left. If you don't see that menu, select
    View ▹ Show Log List
    from the menu bar.
    Select the 50 or so most recent entries in the log. Copy them to the Clipboard (command-C). Paste into a reply to this message (command-V). You're looking for entries at the end of the log, not at the beginning.
    When posting a log extract, be selective. Don't post more than is requested.
    Please do not indiscriminately dump thousands of lines from the log into this discussion.
    Important: Some personal information, such as your name, may appear in the log. Anonymize before posting. That should be easy to do if your extract is not too long.

  • I have a 2008 macbook and everything is to date except Adobe Flash player which I can no longer download. When i try, it will not allow me to push "install." Is there another product I can use or is there a way to install this? I am using Firefox 4.0 btw.

    For some reason my adobe flash player will not load or reinstall. I keep getting a screen from adobe that says quit or intall but there is no button for the install to push. Only the quit is useable. I want to be able to view video but can't. Does this have to do with Firefox 4? I have deleted multiple unable to be downloaded installs or misinstalls of adobe flash player. Help!

    Start here.

  • Unable to Start EHP Installer Server on Windows 2008 -

    Hi,
    I have an SAP ECC 6.0 running on Windows 2008 x64 (64 bit)with MS SQL 2005. I have downloaded latest EHP Installer and the recommended JCE Policy and followed SAP Note 1245473. After extracting the SAR file I tried to start EHP Installer in <sid>adm using the command STARTUP.BAT "jce_policy_zip=<Policy-Zip file>"  with Administrator Privilege but its not getting started.
    Regards
    Manesh M S

    Hi,
    "If your UAC on Windows 2008 is enabled (if you didn't switch it off) you have to start sapehpi using a security elevated cmd.exe:
    Start -> execute -> cmd.exe --> press CTRLSHIFTENTER and confirm the dialog box.
    This is due to the new security model in Windows 2008.
    You can switch to ""Windows 2003 mode"" by executing ""msconfig"", scrolling down and launching ""disable UAC"" and reboot."
    Thanks
    Sunny

  • Schedule Task - Windows 2008 R2 - User Session

    I am migratiing the schedule task from windows 2003 to windows 2008 and find some of behaviour change on handling user session by Task Scheduler.
    I have a simple batch to call "net use" command to map a network drive for copying file to remote server. And I have scheduled 3 similar tasks and run as same user (e.g. testuser)
    In windows 2003 enviornment, the mapped network drive resource will not be accessed by another schedule task. In windows 2008 R2, howerver, the network drive mapped in one of schedule task can be reached by another task. Does anyone have
    idea on this behaviour change?
    Here are the testing script
    Test Script 1
    NET USE >> D:\TEST1.LOG
    NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO >> D:\TEST1.LOG
    ping 127.0.0.1 -n 100
    NET USE Z: /DELETE
    Test Script 2
    NET USE >> D:\TEST2.LOG
    NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO >> D:\TEST1.LOG
    ping 127.0.0.1 -n 100
    NET USE Z: /DELETE
    Test Script 3
    NET USE >> D:\TEST3.LOG
    NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO >> D:\TEST3.LOG
    ping 127.0.0.1 -n 100
    NET USE Z: /DELETE
    Output in Windows 2003
    Test1.LOG
    New connections will not be remembered.
    There are no entries in the list.
    The command completed successfully.
    z: was deleted successfully.
    Test2.LOG
    New connections will not be remembered.
    There are no entries in the list.
    The command completed successfully.
    z: was deleted successfully.
    Test3.LOG
    New connections will not be remembered.
    There are no entries in the list.
    The command completed successfully.
    z: was deleted successfully.
    Output in Windows 2008
    Test1.LOG
    New connections will not be remembered.
    There are no entries in the list.
    The command completed successfully.
    z: was deleted successfully.
    Test2.LOG
    New connections will not be remembered.
    Status       Local     Remote                    Network
    OK           Z:       
    \\127.0.0.1\Share          Microsoft Windows Network
    The command completed successfully.
    System error 85 has occurred.
    The local device name is already in use.
    The network connection could not be found.
    More help is available by typing NET HELPMSG 2250.
    Test3.LOG
    New connections will not be remembered.
    Status       Local     Remote                    Network
    OK           Z:       
    \\127.0.0.1\Share          Microsoft Windows Network
    The command completed successfully.
    System error 85 has occurred.
    The local device name is already in use.
    The network connection could not be found.
    More help is available by typing NET HELPMSG 2250.

    Sorry for confusing, I have udpated the script for this testing
    =====================================================
    Script for Schedule Task 1 - to map a network drive and issue a ping command to "sleep"
    Echo %date% %time% list drive on schedule task 1
    NET USE 
    Echo %date% %time% map drive on schedule task 1
    NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO
    ping 127.0.0.1 -n 100 > NUL
    Echo %date% %time% remove drive on schedule task 1
    NET USE Z: /DELETE
    Script for Schedule Task 2 - to list out any network drive are mapped.
    Echo %date% %time% list drive on schedule task 2
    NET USE 
    ========================================================================
    The schedule task 2 are triggered while the schedule task 1 are running, In the windows 2003, the schedule task 2 could not list out any mapped drive. In the windows 2008, however, the schedule task 2
    can list the network drive mapped by schedule task 1. The question is if there are any changes between windows 2003 and 2008, hope it can clarify.
    Ouput on windows 2003
    Schedule task1
    D:\>Echo Wed 02/06/2013 18:31:52.93 list drive on schedule task 1
    Wed 02/06/2013 18:31:52.93 list drive on schedule task 1
    D:\>NET USE
    New connections will not be remembered.
    There are no entries in the list.
    D:\>Echo Wed 02/06/2013 18:31:52.98 map drive on schedule task 1
    Wed 02/06/2013 18:31:52.98 map drive on schedule task 1
    D:\>NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO
    The command completed successfully.
    D:\>ping 127.0.0.1 -n 100 1>NUL
    D:\>Echo Wed 02/06/2013 18:33:32.07 remove drive on schedule task 1
    Wed 02/06/2013 18:33:32.07 remove drive on schedule task 1
    D:\>NET USE Z: /DELETE
    Z: was deleted successfully.
    Schedule Task 2
    d:\>Echo Wed 02/06/2013 18:32:22.54 list drive on schedule task 2
    Wed 02/06/2013 18:32:22.54 list drive on schedule task 2
    d:\>NET USE
    New connections will not be remembered.
    There are no entries in the list.
    Output on windows 2008
     Schedule task1
    C:\Windows\system32>Echo Wed 02/06/2013 18:17:52.13 list drive on schedule task 1
    Wed 02/06/2013 18:17:52.13 list drive on schedule task 1
    C:\Windows\system32>NET USE  
    New connections will not be remembered.
    There are no entries in the list.
    C:\Windows\system32>Echo Wed 02/06/2013 18:17:52.16 map drive on schedule task 1
    Wed 02/06/2013 18:17:52.16 map drive on schedule task 1
    C:\Windows\system32>NET USE Z: \\127.0.0.1\Share /PERSISTENT:NO 
    The command completed successfully.
    C:\Windows\system32>ping 127.0.0.1 -n 100 
    1>NUL
    C:\Windows\system32>Echo Wed 02/06/2013 18:19:32.59 remove drive on schedule task 1
    Wed 02/06/2013 18:19:32.59 remove drive on schedule task 1
    C:\Windows\system32>NET USE Z: /DELETE
    Z: was deleted successfully.
    Schedule task2
    C:\Windows\system32>Echo Wed 02/06/2013 18:18:07.69 list drive on schedule task 2
    Wed 02/06/2013 18:18:07.69 list drive on schedule task 2
    C:\Windows\system32>NET USE  
    New connections will not be remembered.
    Status       Local     Remote                    Network
    OK           Z:        \\127.0.0.1\Share        
    Microsoft Windows Network
    The command completed successfully.

  • Is Oracle client 10g or 11g for Windows 2008 R2 (6.1) available yet?

    I have not been able to locate this. If this has not been released, does anyone know when? I have tried the Windows 2008 64 bit 11gR1 (11.1.0.7.0) client on a Windows 2008 R2 with no success. Thanks.

    user12871152 wrote:
    Is there any update on the release date of the Windows 2008 R2 Oracle client? Rumor has it we might see it March 2010. Can someone confirm or deny?I can confirm that there is such a rumor.
    I can also confirm that a Support note 742060.1 "Release Schedule of Current Database Releases" provides further information.

Maybe you are looking for

  • Cost distribution within the group companies

    Hi Experts , Need your thoughts on what would be the best approach for the scenario explained below : We have a parent company and three other companies within the group. In total 4 company codes. There are some expenses which are booked under parent

  • Thumbnail problem

    since my last update, I see on my thumbnails several times the same old picture. When I click on it,  the old picture dissapears andI can see the original ones. When I open full screen view, the pictures do not show at all. Anyone experienced this? H

  • Confused by synchronization

    The following (experimental) code produces unexpected (to me) output: import java.util.Timer; import java.util.Observer; import java.util.Observable; class ImaginaryDbConnection { * Of course code was barrowed to do this!  Sort of based on Sun's Cubb

  • Can't connect to database server

    I've been using oracle db 8.0 since one year ago. Since about 3 months ago, i can't connect to my server database, even i do nothing which can change oracle settings. Why this thing happen ? and what should I do to solve this problem ? Note : When i

  • How to get mac to recognize thumb drive?

    how to get mac to recognize thumb drive?