Shadow Copy on 2012 R2 Only for Admins or dedicated Users

Hi,
is this possible? That only dedicated Users, or Admins are eligible to use Shadow Copy Restore?
we have many home office users (not in Domain...) connected with VPN and they see the the right click and previos Versions.
Now im Afraid that someone could set back the whole data directory a feew days back or more...
would can be done?
Shadow copy only for admins would be nice 

there seems no such permission to control previous version...
this may be helpful...
http://social.technet.microsoft.com/Forums/windowsserver/en-US/b78896ee-8364-4a02-a082-7f22e6417dc7/server-2008-and-shadow-copy-permissions?forum=winservergen
Best,
Howtodo

Similar Messages

  • Weblogic Access Logs not getting generated / updated only for Admin server

    Hi All,
    I have a query ,
    We recently noticed that the weblogic access logs for our admin server are not getting generated.
    However we checked that the access logs are getting generated for the managed servers that we have.
    There is not much difference between the logging settings between the admin and the managed servers.
    We thought that there might be some problem with the buffering and that the data might not be written to the files immediately.
    So after researching we found the parameter "-Dweblogic.logging.bufferSizeKB=0" and added that to the java options however it did not make any difference.
    Also we tried modifying the config script as ,
    <server>
    <web-server>
    <web-server-log>
    <buffer-size-kb>0</buffer-size-kb>
    </web-server-log>
    </web-server>
    </server>
    However no luck .....
    We are using weblogic 9.2 MP3 and think there might be some bug with this version , however its hard to believe that the logs are generated and updated for managed servers and not for the admin servers.
    The only thing we notice in the access logs of the admin server is 404 errors.
    Any suggestions ?
    Regards,
    Stacey.

    This has come up recently here:
    access log not writing to disk in a timely fashion
    I didn't find that buffer-size-kb capability in the docs in 9.2. I recommend checking with support.

  • IMovieQuits on Launch... only for Admin account

    Hi
    Just installed iMovie 6.02... but as Admin it Quits Uexpectedly on launch (as it's loading the last project...)
    I've deleted prefs, repaired permissions, etc etc.
    New Admin users are fine ... as are managed users....
    The crash report mentions iTues in the crashed thread report.
    Thread 4 Crashed:
    0 com.apple.CoreFoundation 0x907be584 CFRetain + 60
    1 com.apple.MediaBrowser 0x67e026ec -[MediaGrabberiTunes _loadMusicThreaded] + 636
    2 com.apple.Foundation 0x92944194 forkThreadForFunction + 108
    3 libSystem.B.dylib 0x9002bc28 pthreadbody + 96
    I deleted all iTunes prefs (including the ones in the ByHost folder) but it didn't make any difference.
    All other iLife 06 apps run fine.
    Not a show stopper... but I want to know why!!!
    Thanks for any thoughts
    Lee

    Try this:
    Quit iMovie. Delete its prefs file at the admin accounts home folder at ~/Library/Preferences/com.apple.imovie... (or something like that -- I'm at a Windows box right now). Then launch iMovie and rebuild its prefs as you like.

  • Programs freeze frequently only for one of four users on iMac

    When I log on to the imac with my user (with administrator rights), the user interface frequently freezes. The keyboard or mouse does not work any more. It then helps to restart Finder using cmdaltesc.
    When logging on with the three other users, this problem does not occur.
    Do you have any idea how to fix that problem?
    Thanks.

    Usually this means something you've installed in your Home folder or cache files or preference files are corrupted. Get a utility such as TinkerTool System and use it to clean all of your user caches and to check your preference files. Consider deleting the /Home/Library/Preferences/com.apple.finder.plist and com.apple.dock.plist files then log out and back in. Check your Login Items for any that may be incompatible and temporarily try removing any third-party preference panes you may have installed. See also:
    Kappy's Personal Suggestions for OS X Maintenance
    For disk repairs use Disk Utility. For situations DU cannot handle the best third-party utilities are: Disk Warrior; DW only fixes problems with the disk directory, but most disk problems are caused by directory corruption; Disk Warrior 4.x is now Intel Mac compatible. TechTool Pro provides additional repair options including file repair and recovery, system diagnostics, and disk defragmentation. TechTool Pro 4.5.1 or higher are Intel Mac compatible; Drive Genius is similar to TechTool Pro in terms of the various repair services provided. Versions 1.5.1 or later are Intel Mac compatible.
    OS X performs certain maintenance functions that are scheduled to occur on a daily, weekly, or monthly period. The maintenance scripts run in the early AM only if the computer is turned on 24/7 (no sleep.) If this isn't the case, then an excellent solution is to download and install a shareware utility such as Macaroni, JAW PseudoAnacron, or Anacron that will automate the maintenance activity regardless of whether the computer is turned off or asleep. Dependence upon third-party utilities to run the periodic maintenance scripts had been significantly reduced in Tiger and Leopard. These utilities have limited or no functionality with Snow Leopard and should not be installed.
    OS X automatically defrags files less than 20 MBs in size, so unless you have a disk full of very large files there's little need for defragmenting the hard drive. As for virus protection there are few if any such animals affecting OS X. You can protect the computer easily using the freeware Open Source virus protection software ClamXAV. Personally I would avoid most commercial anti-virus software because of their potential for causing problems.
    I would also recommend downloading the shareware utility TinkerTool System that you can use for periodic maintenance such as removing old logfiles and archives, clearing caches, etc. Other utilities are also available such as Onyx, Leopard Cache Cleaner, CockTail, and Xupport, for example.
    For emergency repairs install the freeware utility Applejack (not compatible with Snow Leopard.) If you cannot start up in OS X, you may be able to start in single-user mode from which you can run Applejack to do a whole set of repair and maintenance routines from the commandline. Note that AppleJack 1.5 is required for Leopard. AppleJack is not compatible with Snow Leopard.
    When you install any new system software or updates be sure to repair the hard drive and permissions beforehand. I also recommend booting into safe mode before doing system software updates.
    Get an external Firewire drive at least equal in size to the internal hard drive and make (and maintain) a bootable clone/backup. You can make a bootable clone using the Restore option of Disk Utility. You can also make and maintain clones with good backup software. My personal recommendations are (order is not significant):
    1. Retrospect Desktop (Commercial - not yet universal binary)
    2. Synchronize! Pro X (Commercial)
    3. Synk (Backup, Standard, or Pro)
    4. Deja Vu (Shareware)
    5. Carbon Copy Cloner (Donationware)
    6. SuperDuper! (Commercial)
    7. Intego Personal Backup (Commercial)
    8. Data Backup (Commercial)
    9. SilverKeeper 2.0 (Freeware)
    10. MimMac (Commercial)
    11. Tri-Backup (Commercial)
    Visit The XLab FAQs and read the FAQs on maintenance, optimization, virus protection, and backup and restore.
    Additional suggestions will be found in Mac Maintenance Quick Assist.
    Referenced software can be found at www.versiontracker.com and www.macupdate.com.

  • Possible to create separate passwords for admin and main user account?

    Hello,
    My ex wife is going to lend me her Macbook so I can open a separate account to transfer 30K critical business emails from my current Macbook Pro to Mail.app whilst it gets replaced by Apple.
    I still need to work with these emails over the week I'll be left without the computer.
    I was thinking, when requesting to import the mailboxes from my External HD, will it ask for a administrators password?
    She's a bit paranoid about giving me it if that's the case, even though I couldn't give a toss... so is there a way to password protect her main user account with one password, and create another admin password for importing an external mail folder - as OSX sometimes asks for an admin password to install apps etc.
    If I can just use a guest account and import the 'Mail' and 'Mail Downloads' folders from my library to a separate Mail.app on her computer without a password, then great.
    If it's the case the admin password is needed, please let me know ASAP so we can make arrangements for her to hang around to type it in whilst I initially make the transfer - which would be a right royal pain because I'd have to tidy the house up and put some putpourri out and ****.
    TIA

    She can create a new account for you to use. She can set it up as a new Standard account which restricts you from admin privileges. You can use the same username and password as you use on your machine. You will have access to the standard OS X applications such as Mail so you can download your email into a separate account. This can be configured to be exactly the same Mail account you use on your machine.
    Once your use of her machine is finished and you've transferred your data to your machine, she can log into her admin account and delete the Standard account you were using.

  • Is there any way to create admin role only for one resource.

    Hi all,
    I am trying to create an admin role with 'update user' capability. But I want to restrict the user(with the admin role) to be able to update a user's attribute only for one resource, The user(with the admin role) should not be able to update the attributes of the other resources which a user have.
    Is there any way to create admin role only for one resource?
    I customized the tabbed user form to show only one resource attribute (deleting the missing fields and adding my tab for the resource) and then assigned this new User Form to the user(with the admin role) in security tab.
    It works fine. But the problem is that if any user(with the admin role) is also admin of some other resource then he/she will not be able to view the other resource attributes.
    Please suggest,
    thanks

    The loop function always repeats the same region so of course the fade is also copied. So option+drag the original region to make a (non clone) copy, fade the first region and loop the second one (which you just copied).

  • Is there any shadow copy in linux

    If you use ZFS on Linux (not that I'm saying you should) you get a third way to do this as well.

    Shadow Copy in Windows is actually a feature that Linux had long before and Microsoft was embarrassed for going so long without having it.  It's famously one of the big "finally Windows is catching up" features where every OS had it years before them.
    Shadow Copy is just another name for snapshots.  Linux uses LVM as its main snapshot tool although snapshotting is starting to appear as an extra tool in BtrFS too.
    

  • DHCP scope only for WiFi

    Hi. Is it possible to configure some DHCP scope on Windows Server 2012 R2
    only for WiFi devices?
    Maybe some policy?
    Thank you!

    Hi,
    Base on my experience, in the enterprise environment, we usually create a private vlan for the wireless terminal.
    Therefore you can create a dedicated scope for the wireless terminal device.
    More information:
    What's New in DHCP in Windows Server 2012 R2
    http://technet.microsoft.com/en-us/library/dn305900.aspx
    Configuring a DHCP Superscope
    http://technet.microsoft.com/en-us/library/dd759168.aspx
    Hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • All USB drives mount as read only for user

    I have searched a bunch and thee results I find seem to be irrelevant to my situation. Most relate to a single USB media that is a problem and won't read or write.
    On a new Arch install on a new computer (my third base system install). Running Gnome.
    All USB mass storage devices mount as read only for the logged in user. Root has write permissions and I can mkdir no problem. It is not an issue with the USB drive itself as this occurs with multiple USB media (I've tested several SD cards on a reader and at least two drives, all the media works correctly on my existing installations)
    I'm posting the contents of my /etc/group file in case there's an obvious error there I don't see, and my dmesg output upon plugging in the drive. User name is changed in the group file posted to "archie"
    This is a single-user system.
    /ect/group
    root:x:0:root
    bin:x:1:root,bin,daemon
    daemon:x:2:root,bin,daemon
    sys:x:3:root,bin
    adm:x:4:root,daemon
    tty:x:5:
    disk:x:6:root
    lp:x:7:daemon
    mem:x:8:
    kmem:x:9:
    wheel:x:10:root,archie
    ftp:x:11:
    mail:x:12:
    uucp:x:14:archie
    log:x:19:root
    utmp:x:20:
    locate:x:21:
    rfkill:x:24:
    smmsp:x:25:
    http:x:33:
    games:x:50:
    lock:x:54:
    uuidd:x:68:
    dbus:x:81:
    network:x:90:
    video:x:91:
    audio:x:92:
    optical:x:93:
    floppy:x:94:
    storage:x:95:
    scanner:x:96:
    power:x:98:
    nobody:x:99:
    users:x:100:archie
    systemd-journal:x:190:
    archie:x:1000:
    avahi:x:84:
    polkitd:x:102:
    rtkit:x:133:
    gdm:x:120:
    brlapi:x:999:
    kvm:x:78:
    ntp:x:87:archie
    dmesg output
    [ 968.044188] usb 4-3: new high-speed USB device number 4 using ehci-pci
    [ 968.170628] usb-storage 4-3:1.0: USB Mass Storage device detected
    [ 968.171435] scsi7 : usb-storage 4-3:1.0
    [ 969.174450] scsi 7:0:0:0: Direct-Access Generic USB SD Reader 1.00 PQ: 0 ANSI: 0
    [ 969.175068] scsi 7:0:0:1: Direct-Access Generic USB MS Reader 1.03 PQ: 0 ANSI: 0
    [ 969.939417] sd 7:0:0:0: [sdb] 15572992 512-byte logical blocks: (7.97 GB/7.42 GiB)
    [ 969.941028] sd 7:0:0:0: [sdb] Write Protect is off
    [ 969.941037] sd 7:0:0:0: [sdb] Mode Sense: 03 00 00 00
    [ 969.944664] sd 7:0:0:1: [sdc] Attached SCSI removable disk
    [ 969.945509] sd 7:0:0:0: [sdb] No Caching mode page found
    [ 969.945517] sd 7:0:0:0: [sdb] Assuming drive cache: write through
    [ 969.952682] sd 7:0:0:0: [sdb] No Caching mode page found
    [ 969.952693] sd 7:0:0:0: [sdb] Assuming drive cache: write through
    [ 969.956396] sdb: sdb1
    [ 969.965003] sd 7:0:0:0: [sdb] No Caching mode page found
    [ 969.965011] sd 7:0:0:0: [sdb] Assuming drive cache: write through
    [ 969.965015] sd 7:0:0:0: [sdb] Attached SCSI removable disk
    I'm sure I'm just missing something in user management, but I can't find what.
    Last edited by hooya (2014-04-27 03:10:49)

    I am also having the same problem. Root can read and write to automounted drives, but my user cannot. I've tried with a variety of drives, I am assuming they are being automounted by root instead of the logged-in user somehow. (I am running x directly, and am not using a display manager, if that has anything to do with it).
    When I look at how it is mounted it is as follows:
    /dev/sdc1 on /run/media/myuser/drivename type vfat (rw,nosuid,nodev,relatime,uid=1000,gid=1000,fmask=0022,dmask=0077,codepage=437,iocharset=iso8859-1,shortname=mixed,showexec,utf8,flush,errors=remount-ro,uhelper=udisks2)

  • Block vendor only for po

    Hi All,
        We want to block vendors only for purchasing that means user should be able to create RFQ but he should not be able to create PO for that vendor. How to do this?
    Thanks in advance.
    Pavan

    Hi Pavan,
    Go to MK05, Enter Vendor / Purchase Orgn and there is a Tab called Block for Quality Reasons.
    Select Only the Block function 01 Lock the Purchase order.
    Eventhough If you are not able to do RFQ. Go to OQB3 and select the reason and choose your reason suppose 01 uncheck all the options expect for Purchase order and save.
    Surely this would resolve your thread.
    Revert back in case not solved.
    Reg,
    Ashok
    Rewards Welcome

  • Restricting Access only for APPS account using SQLNET

    Dear Friends,
    Recently we have an incident that a functional consultant has cracked the Apps password. I don't know how.
    Now what we are planning is to restrict the database access to only the dba team using sqlnet.ora file and its tcp.validnode_checking parameter.
    However, the problem is that we want to continue the APPSRO(which is an Apps Read Only Account) access to them.
    Is there any way possible to restrict access only for a particular database user account using sqlnet.ora
    please help.
    Thanks.

    Recently we have an incident that a functional consultant has cracked the Apps password. I don't know how.
    Now what we are planning is to restrict the database access to only the dba team using sqlnet.ora file and its tcp.validnode_checking parameter.
    However, the problem is that we want to continue the APPSRO(which is an Apps Read Only Account) access to them.
    Is there any way possible to restrict access only for a particular database user account using sqlnet.ora
    Now what we are planning is to restrict the database access to only the dba team using sqlnet.ora file and its tcp.validnode_checking parameter.
    However, the problem is that we want to continue the APPSRO(which is an Apps Read Only Account) access to them.
    Is there any way possible to restrict access only for a particular database user account using sqlnet.oraNo (and even if it exists, I believe this does not fix the main issue with the apps password which could be cracked again).
    The proper way would be changing the apps password and meet the security requirements in these docs.
    Secure Configuration Guide for Oracle E-Business Suite 11i [ID 189367.1]
    Secure Configuration Guide for Oracle E-Business Suite Release 12 [ID 403537.1]
    FNDCPASS Utility New Feature: Enhance Security With Non-Reversible Hash Password [ID 457166.1
    Thanks,
    Hussein                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

  • Share Sessions for two or more Users ?

    Hi,
    im new on this site.
    Now we like to use SGD and stumbling over a problem, im not sure that sgd can handle this.
    We like to share Sessions like a open Terminal between users. That means if User one open a terminal at home and he like that user2 go ahead with his work, he like to "give" user2 his own terminal (with history or anything else). We found the "Shadow-Funktion", but this is only for the Administrator...but thats what we mean/search.
    Is it possible to share praticular terminals/browsers/GUIs between users if they are opend?
    I hope i you understand wat i try to explain :-)
    regards

    I haven't tried this - it's actually a change to how the classroom shadowing scripts are usually set up, but it may work - if it does feel free to award me a lot of duke stars ;-)
    1. Set the login script to be �unixclass.exp� on the X application you want to share and then make multiple copies - on for each user (e.g. daves terminal, freds terminal, etc.).
    Assign these objects only to the specific users
    2. For each terminal object create a new X application object named something like 'dave's shared terminal' and set the Application Command of the object to �/opt/tarantella/bin/bin/ttashadow�.
    Set the Arguments for command of the object to �-silent -pointer $SHADOWDISPLAY�
    Set the height & width to be identical to the master object and the color depth to at least 16bit
    Set the Login Script of the object to �pupil.exp�.
    Set the Environment Variable 'MYCLASS' to the ENS object name of the terminal object - e.g. �MYCLASS=.../_ens/o=Applications/cn=daves terminal�
    Assign these objects to all the other users.
    Then how it should work is 'dave's terminal' can be viewed and used by anyone running 'daves shared terminal' as long as dave keeps it running
    To force dave to allow access to his terminal remove the '-silent' option from the ttashadow command.
    fingers crossed....

  • Can a Column in a Project Plan be set to Read Only for everyone except Admins

    At my company the Project Server Admins create the initial project plans.  We want to add a new column that will designate each task in the plan as Capital or Operational.  We do not want anyone to have the ability to change these.
    When the Project Managers need additional tasks on their plans they will need to copy an existing one in order to have this piece of information pre-populated on their new tasks, since we do not want them deciding what the task should be themselves and populating
    the field as they create tasks.

    In addition to Dale's excellent answer, I'd mention that it is possible to make a column "read-only" for certain security groups in MS Project Pro with VBA code. 
    That being said, I'd suggest to follow Dale's advice using a "soft" solution.
    Hope this helps,
    Guillaume Rouyre, MBA, MCP, MCTS |

  • Photoshop Elements 9 effects only work for Admin

    Hi.
    I am a teacher with a Maclab running Photoshop Elements 9. We just discovered that the effects pannel (where drop shadow, etc.) appear is blank for any non- administrator account. I have uninstalled and reinstalled. Tried installing under a student account. I thought I found the right files in the Applications Support folder and copied them to the Application Support folder of the user and still no luck. Does anyone have a solution for this?

    All versions of PSE are designed to run from admin accounts. It is possible to change the permissions on the files (no need for Root!) to make it run in standard accounts, but you must be aware if you choose to do so, that if you set the file permissions so that anyone can write to it, ANYTHING can write to it, and you are making a weak spot in your computer's defenses, however minor.

  • How do I create a specific packages for users where in only the admin has the access of which software the user can download?

    Is there any possibilities that the admin of the team can limit the packages of the user? Only the admin can add and remove software to be downloaded for specific users.

    You can include single app plans in team packages, but otherwise no. This will exclusively depend on the users' local permissions on the computer - if the can install one app, they can install all of them, be it only as a trial.
    Mylenium

Maybe you are looking for