T
Thorsten Butz
I want to achieve, that administrative accounts are completely free,
they shall not be restricted by UAC.
I can do that for the Root-Administrator-Account, the one with the -500
SID. But I want to free "john doe", if he is Domain Administrator.
"Elevate without prompting" is not adequate, because programs that do
not force an elevation of rights ("asInvoker") would run with the
stripped down token.
So, why can't I do that? Or: how? Any ideas?
Thanks Thorsten
they shall not be restricted by UAC.
I can do that for the Root-Administrator-Account, the one with the -500
SID. But I want to free "john doe", if he is Domain Administrator.
"Elevate without prompting" is not adequate, because programs that do
not force an elevation of rights ("asInvoker") would run with the
stripped down token.
So, why can't I do that? Or: how? Any ideas?
Thanks Thorsten