Restart-Computer remotely with Local Admin

Hello;
I manage my company's server and AD infrastructure, containing hundreds of Windows 2012 R2 servers.  I also patch all of my servers monthly.  The biggest challenge in patching servers, is the fact that they need to be restarted every month, in
order for the patches to finish installing.
We have a certain group of servers, that need to have their restarts specifically scheduled.  The services offered by these servers are managed by a specific group of IT Pros.  However, this group of IT Pros do not have Local Administrative permissions
on these servers (nor do they need it to do there jobs).
I would like to enable this group to remotely restart these servers every month using the 'Restart-Computer' powershell command, without granting them Local Admin (that way, I won't need to get up at 3am every month to do this myself).  I've tried adding
them to the following "User Rights Assignment": "Force shutdown from a remote system" and "Shut down the system".
But, they still get an "Access Denied" error message.  What am I missing?  Is this even possible?  I've searched for hours now, but with no luck.

Thank you for the reply, but I had already tried those suggestions.  Here's what I've tried so far:
First, as I mentioned before, I've added the admins to the following "User Rights Assignment": "Force shutdown from a remote system" and "Shut down the system".  Then I temporarily added the admins to the "Allow log
on locally" user rights assignment so that I may log on to the server as the admins and prove that the admins can indeed restart the local server.  From the server console, the admin was able to launch a powershell session and run the "Restart-Computer"
command, and the server restarted perfectly. 
So that part worked just fine.  But I would like to get the admins to remotely restart the servers, without granting them the "Allow log on locally".  Another thing I tried, was to create a new remote PSSession, and then run the Restart-Computer
command from there.  At first, the New-PSSession gave me an access denied error message.  That's when I ran the Get-PSSessionConfiguration command, and I noticed that the "Builtin\Remote Management Users" group was allowed access. 
So I added the Admins to that group on one of the servers.  Now the New-PSSession command worked.  But the Restart-Computer still gives me an Access Denied error message.
Here are the commands that I am using.
First, running the Restart-Computer from the admin's workstation:
Restart-Computer -ComputerName SERVER01
Second, running the Restart-Computer command from with a remote PSSession.
New-PSSession -ComputerName SERVER01
Enter-PSSession 2
Restart-Computer
Either way, I get an access denied message.

Similar Messages

  • Remote Computer Management Using Local Admin Credentials?

    As per your requirement, I would suggest you to have a look on Lepide remote admin tool that allows to remotely administer single or multiple computers in the entire network simultaneously spread across multiple domains. Tool is free.

    If you are running as a standard user on your workstation and need to user the Computer Management mmc to remotely manage a second Windows workstation on your domain, how do you do this without using a domain account that is local admin on the remote system?If you open computer management locally first, you are prompted by UAC for local admin credentials on your local machine before you can even open Computer Management. If you provide those credentials and then try to connect to the remote computer using the mmc interface, you will get access denied errors if the administrator account isn't the same on both systems. It just fails without prompting for alternate credentials.Is there any workaround to get it to prompt and allow you to enter the local admin user credentials for the remote PC?I know you can get around this by using a...
    This topic first appeared in the Spiceworks Community

  • Network User with Local Admin Privileges?

    I have a small network (around 25 clients total) that was setup prior to my arrival. Each client has its own unique local admin (each machine was setup by the individual user) and it's become somewhat daunting to support them.
    All of the machines are connected (but not specifically bound) to an Open Directory and each is accessible via Remote Desktop, however I cannot push software updates, etc. without local admin privileges.
    I'd rather not create an account on each machine, nor do I want to completely lock down each computer (I'd like them to still have the flexibility to be admins so they can install apps, etc.)
    Is it possible to authenticate against OD and obtain local admin privileges?

    Yes.
    You can wipe all account information and then recreate a common initial admin account. This will make administration far easier as all machines will have the same admin username/password combination. Next, bind all of the systems to the domain and create domain accounts for all users on the server (likely already exist). Log in as the domain accounts and migrate permissions to domain ids. Finally, promote the user to the local admin group through System Preferences > Accounts on the workstation. You must enable the account as a mobile account in Workgroup Manager first. If you do not, the account will not cache to the workstation and you will be unable to add it to the admin group.
    Also, in a workgroup of 25, I would recommend rethinking the decision to grant local admin access to end users. This is asking for trouble as you will have no control over when updates are applied or even if they are. In theory (and probably in practice), you will have 25 completely different machines configurations. This is far harder to manage and troubleshoot than 25 systems with different admin accounts.
    If you must provide some level of autonomy, while not trivial, you might want to consider modifying /etc/authorization and granting limited admin rights to the users.
    Hope this helps - congrats on the opportunity

  • Can't print with user but can with local admin

    Hello All,
    I'm a Windows admin learning how to support Macs in a 2003 AD environment. Here's my problem. I have a Windows 2003 AD Domain and an office of Mac clients running OSX 10.3.9. I'm using AdmitMac version 1 to connect the Mac's to AD. There's been previous problems with Mac machines dropping from the AD domain. A quick fix of this problem involves re-adding the affected machine back to the AD via the Admitmac utility. A long term fix of this problem will be an upgrade to Admitmac version 3, but that's down the road.
    Anyway, when 1 client lost its AD authentication, adding the machine back to the AD caused the local user profile to not be able to print to the shared network printer anymore. Printing works when logged in as the local admin on the Mac, but not as the user. I've tried giving the user admin rights, reconnecting the printer, and re-adding the machine to the domain. All of this has not helped the situation.
    Does anyone have any ideas for a possible fix?
    Thanks and sorry for the long winded post.
      Mac OS X (10.3.9)  

    USB printers are a pain.. it might not work at all from windows.. that is just the reality.
    USB printers are local printers that plug into your computer.. save your $50.. and the cost of the next couple of sets of ink cartridges or toners and go and buy a network printer. ie one that is designed to work in a network.
    If you want to pursue this..
    1. How did you name the Express.. and its wireless?
    Names should all be short, no spaces and pure alphanumeric.
    2. What printer is it? If you plug it in via USB to the computer does it work?
    3. Once you have it working plugged into the computer change it to print to IP of the airport express and see if that works.
    You can do this without bonjour..
    See this video for example of setting up printing to Extreme (same thing) by printing directly to the TCP/IP port.
    http://www.youtube.com/watch?v=qTN1g846dRE
    It is windows 7 but 8 should be much harder .. naturally MS took away the easy access to everything .. but it is still there for the most part.

  • Installing SQL server with local Admin rights

    Dear DB experts
    I have a concern about installing SQL server 2000 on win 2003 with out local admin rights
    I have delegated local admin rights to a Domain user.  that user can install and configure SQL with out any issues or its is a must to install SQL using local administrator account   pls advise.
    Regards
    Rabbani
    RaSa

    Hi Syed_R,
    SQL Server 2000 was out of support in SQL Server Forums since April,2013. You can install SQL Server 2005 or later version and more experts will assist you.
    As other post, the user that runs the SQL Server installer must have Admin rights on the server when installing. For local installations, you must run Setup as an administrator. If you install SQL Server from a remote share, you must use a domain account
    that has read and execute permissions on the remote share.
    In addition, in preparation for setting up Microsoft SQL Server on this system, you add the Setup account to the local administrators group, also the Setup account need to have certain user rights for avoiding SQL Server installation fails. Such as Local
    Policy Object Display Name, Backup files and directories and so on.
    For more information, you can review the following article.
    http://support.microsoft.com/kb/2000257
    Thanks,
    Sofiya Li
    Sofiya Li
    TechNet Community Support

  • Delay when starting accdb without local Admin rights.

    Hi,
    I have a problem with one application, the front end of the application is MS Access DB that's connects to our SQL Server over odbc driver If the user is in a local administrator group everything is working fast. When the same user is put in the user group
    without Administrative rights I recive a delay for about 60 sec then the error pops up
    After I hit ok a new SQL login pops up and I just press second time ok and the application starts without entering any user and pass. This is not happening if the user is in the built in Administrators Group.
    Thanks for the help
    fract

    Hi fract,
    as a Microsoft partner I have asked support for help.
    Here is their answer:
    Hi Partner,
    Thanks for your reply.
    Based on my research, the issue is identified as a compatibility issue that Access 2010 has with SQL Server 2008 R2. Access uses PERMISSIONS function to check the privileges. The PERMISSIONS function is deprecated in SQL Server 2008 R2. I haven’t found
    any workaround for this issue currently.
    You can check the more detail information at below link:
    PERMISSIONS (Transact-SQL)
    http://msdn.microsoft.com/en-us/library/ms186915(v=sql.105).aspx
    I think you need to access SQL Server 2008R2 with local admin right.
    If you have any further questions, please let me know.
    Best Regards,

  • GroupWise 6.5.7 distribution without local admin rights

    I would like to distribute the GroupWise 6.5.6up1 (6.5.7) client
    installation (from 6.5.1).
    Im using the setup.cfg and setup.ini to have an unattended installation.
    It is working great with local admin rights.
    Now I would like to distribute this version with ZENworks. Im using the
    workstation object (association) so the distribution will take place when
    the workstation starts up.
    But (as far as I can see) the registration of DLLs will not take place.
    What kind of alternatives are there to distribute GroupWise without local
    administrator rights?
    Thanks.
    Armand.

    Thanks for the reply.
    The .aot files give problems, dll files are missing (the known
    vslwp7.dll) and I found a lot of bad experiences on the forums with the
    viewer etc.
    Armand.
    > I've been using the AOTs included with the GW Client (Zen directory). =
    > They import into Zenworks easily and have worked well for me the last 2 =
    > upgrades.
    >
    > >>> <[email protected]> 10/11/2006 1:34:27 AM >>>
    >
    > I would like to distribute the GroupWise 6.5.6up1 (6.5.7) client
    > installation (from 6.5.1).
    > I=92m using the setup.cfg and setup.ini to have an unattended installation.=
    >
    > It is working great with local admin rights.
    >
    > Now I would like to distribute this version with ZENworks. I=92m using the
    > workstation object (association) so the distribution will take place when
    > the workstation starts up.
    > But (as far as I can see) the registration of DLL=92s will not take place.
    >
    > What kind of alternatives are there to distribute GroupWise without local
    > administrator rights?
    >
    > Thanks.
    > Armand.
    >
    >

  • Why my software needs Local Admin? Windows 7 App Compatibility

    Hi
    I have a software that works great on Windows 7
    My problem is that I can run it only with local admin. if I'm logged in with a standard user - I get errors and the software doesn't open. no errors in the event viewer
    Usually what I do in those cases is searching the registry or the folder that the user needs a modify permission and add it
    Sometimes I use procmon if I can't find it manually.
    in this case - procmon didn't help me :/. no "Access Denied" rows at all...
    I tried to add the user to the "Power Users"\"Distributed COM Users" group and I still get the same error.
    I tried to use the compatibility tab though the software works perfect on windows 7, my only problem is the prerequisite of local admin I'm trying to remove.
    Is there any tool I can use to find out what the software does that requires local admin rights?
    Tamir Levy

    Hi,
    Firstly please refer to this article to troubleshoot an application that cannot run as a standard user:
    An Application Cannot Run as a Standard User
    http://technet.microsoft.com/en-us/library/dd919180(v=ws.10).aspx
    Some programs are designed to perform legitimate administrative actions and therefore require administrative permissions. There is no idea to run it without administrator.
    Karen Hu
    TechNet Community Support

  • Running Desktop software without local admin rights

    Is it possible to run Blackberry Desktop Software without the user having local admin rights? I have a number of users who have work BBs who need to use BDS, but I am in the process of correcting my predecessor's decision to give everyone local admin rights.

    Hello gheatley,
    Welcome to the Support Community!
    The BlackBerry® Desktop Software will need to be installed in a Windows® user account with local admin rights, but it can be used from within other user accounts with more limited permissions.
    Thanks.
    -FS
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.
    Click Solution? for posts that have solved your issue(s)!

  • Troubles with remote installation on older macbook- problem arises when I restart computer while holding down option key

    I've got remote disk sharing set up so I can upgrade my operating system from my desktop using snow leopard CD. My Macbook is able to read disk remotely and all goes well following directions for installation until I am supposed to hold down option key while restarting computer. When I do this, only my hard drive is an option for start up, not the hard drive and the disk as it shows in the instructions and pop up menu for start up. Why? What am I doing wrong with the start up? Also, it says I should be able to choose the Airport network, but my computer automatically connects and anyways, that is also not an option from the pop up menu (to choose a network and enter password), that pop up menu section doesn't show up at all, it goes right to choosing disc icon where only mac hard drive, not mac os x install, is an option. Does this make sense? I'm giving up for now.
    Thanks.

    The only known way to make it work on an external drive is by first installing Windows onto an internal drive, then cloning the install to an external Thunderbolt drive. Thunderbolt is seen as an extension of the internal bus, so Windows doesn't see it as an external device.

  • Local Admin add with GPP netbios name not working

    I am trying to add domain users to be a local admin on certain machines. This however is not working with some machines critereria of the GPP.
    For example: there is a GPP who adds the administrator to the local admin and deletes the ones already there. Then there follows a few other users with criteria: member of the security group laptopusers or other security groups. Also have added a user and
    the criteria is netbios name of the computer. The member was immediatly added after a restart of that client.
    There is also a group in AD and added members to that group that are local admin on every machine so there is no criteria. This is working fine. WHen i add all users to this group all users are local admin everywhere. Was tested.
    However i have several users that do not be added to the local admin when the criteria is: netbiosname is ... Although when i give the command on the client: ipconfig /all the netbios name is exactly the same.
    Looked in the winlog and it looks like a problem with the machines names or usernames. But how to solve it?
    Which other cirteria i can use to add a member to local admin on a specific machine.
    The GPP is beneath the computer preference and in AD beneath a computer OU.
    freddie

    > the command nbtstat -n givves also the name as i gave in in the criteria
    > of the GPP.
    >
    > With Winlog i mean: set the gpo logging so that in a file the errors
    > appearing for the group policy applied. However there is not much to see
    > in case of this...
    Ok :) I know that these GPP debug logs are kind of "insufficient" in
    terms of debugging ILT filtering issues, because there's absolutely
    nothing about the filter evaluation in them...
    In a quick test I ran right now, it worked without a problem. So it
    seems you most probably will be out of luck in this forum, because it is
    not a general issue.
    BTW: Did you type in the name or did you select it through the object
    picker button ("...")? Maybe this filter is case sensitive?
    Martin
    Mal ein
    GUTES Buch über GPOs lesen?
    NO THEY ARE NOT EVIL, if you know what you are doing:
    Good or bad GPOs?
    And if IT bothers me - coke bottle design refreshment :))
    I jhave give in the name and then check name so he gets the name from AD. I have done that again to see if it works now. The strange thing is that it works well on some systems and not for some other systems...
    freddie

  • TS3276 I have installed OS X Mavericks on macbook pro, macbook air & iMac but I am having terrible trouble with apple Mail. I need to take all accounts online frequently OR worse I have to quit mail and restart computer. Is anyone else having problems?

    I have installed OS X Mavericks on macbook pro, macbook air & iMac but I am having terrible trouble with apple Mail. I need to take all accounts online frequently OR worse I have to quit mail and restart computer. Is anyone else having problems?

    I just checked to see if the update to OS X Yosemite 10.10.1 solved any of the issues outlined in my previous post, and to my dismay, nothing has changed -- all of the previous problems persist.
    My iMac (8) -- it's renamed itself eight times since the recent troubleshoot with the Apple tech rep -- shows up as a shared device in Finder on my MacBook Pro, but when I click on it, I cannot establish a connection using "Connect As".  So I've attempted to connect using the menu "Go/Connect to Server...", using both (alternately) the iMac's name and IP address, to no avail.  I get a message which reads: "There was a problem connecting to the server 'Peter's iMac (8)'. This server may not exist or it is unavailable at this time.  Check the server name or IP address, check your network connection, and then try again."
    Here's what I know:
    The server -- Peter's iMac (8) does exist;
    The server -- Peter's iMac (8) is available at this time;
    The server name -- Peter's iMac (8) -- is correct, as specified in the system sharing preferences;
    The server IP address is correct, as specified in the system sharing preferences;
    The network connection is active when I attempt to connect.
    I'm convinced the problems stem directly from the OS X Yosemite update.  None of this was ever remotely an issue in the previous OS X's -- any of them.  This is maddening!  What can be done?  Apple?? Anyone???

  • Cannot access to any site with ssl connection and fail to open safari and keychain, unless restart computer and login in with Guest account.

    when Update to 10.7.2 ,I cannot access to any site with ssl connection and fail to open safari and keychain, unless restart computer and login in with Guest account.
    OS:10.7.2
    Macbook Pro 2010-mid 13inch

    I also have the same problem, however if I use Firefox or Opera sites with ssl connection work fine. Still, I can't use Google Chrome (ssl), Safari (ssl), the Mac app store (generally), or the iTunes store (generally). Both the iTunes store, Safari and the app store won't respond, and Chrome displays this error: (net::ERR_TIMED_OUT). The problem persists regardless of what network I'm using. Also, when trying to access the keychain or iCloud, the process will not start (will hang). I didn't have these problems at all before updating to 10.7.2.
    Sometimes rebooting helps, and sometimes not. If the problem disappears by rebooting, then it only lasts a few minutes before it reappears. It is very frustrating, especially since there doesn't seem to be any obvious or consistent way of which to fix it.
    I'm also using a Macbook Pro 13-inch mid 2010.

  • My computer crashed with lightroom open, since restart I get a msg LR encounted an error when reading from its preview cache and needs to quit

    Hi All
    My computer crashed with lightroom open, since restart I get a msg 'LR encounted an error when reading from its preview cache and needs to quit'
    I'd appreciate any suggestions
    Many thanks

    Many thanks for your help, at lease the LR is working now. How do I rebuild previews and smart previews or will this happen automatically?
    Many thanks

  • I had a Microsoft tech access my computer remotely to resolve issues with my hotmail acct. There were files that needed to be deleted and he also changed some settings.   Later, when I tried to open InDesign I received the following error:  AMT Subsystem

    I had a Microsoft tech access my computer remotely to resolve issues with my hotmail acct. There were files that needed to be deleted and he also changed some settings.
    Later, when I tried to open InDesign I received the following error:
    AMT Subsystem Failure
    The licensing subsystem has failed catastrophically. You must reinstall or call customer support.
    I rebooted the computer and tried again:
    Licensing for this product has stopped working.
    You cannot use this product at this time. You must repair the problem by uninstalling and then reinstalling this product or contacting your IT administrator or Adobe customer support for help.
    I can access Acrobat and MS Office programs, it's just the CS3 programs that I can't access. Can I uninstall and then reinstall CS3 without an access (un-lock) code?

    Use the trackpad to scroll, thats what it was designed for. The scroll bars automatically disappear when not being used and will appear if you scroll up or down using the trackpad.
    This is a user-to-user forum and most people will post on here if they have problems. You very rarely get people posting to say there update went smooth. The fact is the vast majority of Mountain Lion users will not be experiencing any major problems with the OS, or maybe with apps which are not compatible, but thats hardly Apple's fault if developers don't update their apps.

Maybe you are looking for