Home > Step-by-step guide: Elevating privileges for an administrator
Step-by-Step Guide:
EMAIL THIS

Step-by-step guide: Elevating privileges for an administrator

26 Apr 2006 | SearchWindowsSecurity.com

Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

We all know the issues surrounding Windows and elevated privileges. In our last poll, many of you selected Vista's user account control as a favorite feature of the upcoming release. While we wait for Vista's release, it is good for administrators to be able to elevate privileges as needed.

The following guide is taken from a webcast by Aaron Margosis, a Microsoft consultant. You can view the webcast in its entirety here.


Administrators, of course, have a legitimate need to run as admin, but they don't need to do everything as admin all the time. Unfortunately, Windows only accommodates one security level at a time. Running as admin all the time opens up some unnecessary security risks.

Not that using limited user accounts are a "silver bullet" for all security concerns. Limited user accounts, or LUAs, will help mitigate the risk of malware that depends on admin privileges. LUAs will not prevent any of the following dangers:

  • Anything you can do to yourself
  • Weak admin passwords
  • Attacks on services
  • Phishing
  • Stupidity

That said, administrators need to know how to elevate privileges as needed. Fast User switching is the best way (see Serdar Yegulalp's article on Fast User Switching), but it is not available in a corporate domain environment.

That leaves us a few other options.


Elevating privileges for administrators

 Home: Introduction
 Step 1: RunAs dialog
 Step 2: RunAs command line
 Step 3: Differentiating security levels
 Step 4: MakeMeAdmin
 Step 5: Caveats
 Step 6: Resources

ABOUT THE AUTHOR:
Aaron Margosis is a Senior Consultant with Microsoft Consulting Services, focusing on US Federal government customers. He specializes in application development on Microsoft platforms and products with an emphasis on application and platform security. Aaron has blogged extensively about how to run Windows as a non-admin, and created the popular MakeMeAdmin and PrivBar utilities. Aaron holds Bachelors and Masters Degrees from the University of Virginia, and calls Arlington, VA, home.
Copyright 2005 TechTarget


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Windows XP security issues, updates and alerts
How Windows 7 stands up to security tests
The state of enterprise security and emerging threats in 2009
A first look at Windows 7 security enhancements
How to strike a balance between Windows security and business needs
How to recognize and repair Blue Screen of Death stop error messages
Ten ways to sell security to management
Improve Windows security with our top 10 tips
Strategies for troubleshooting Windows XP errors
Managing single sign-on security burdens in Windows
A Windows security checklist for IT managers

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
drive-by download  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Windows Admin Solutions - User Management, Application Management, Windows Deployments
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts