Forum Discussion

BrianPitt's avatar
BrianPitt
Brass Contributor
Feb 26, 2020

GPO for Elevated Rights

Is there a good way to setup via Group Policy the ability for accounts with local administrator rights only to open certain executables (not all) without a UAC prompt?  THings like mmc.exe / regedit.exe / etc.

This is more of a convenience thing as there are a group of executables we would like to avoid UAC Prompts on constatntly but only for administrator rights accounts.

 

Also,

What is the best way to give elevated privileges to a certain folder or file in Windows and alow only certain users to have the rights?  The best thing I have right now is under Computer Configuration / Policies / Windows Settings / Security Settings / File System, adding the folder or file there and then adding an AD User Group to security of the file or folder and giving that group full rights to it.  Looking to see if that is best or if another option?

 

Resources