Jump to content

Problmes running custon MMC console for staff user


Recommended Posts

Posted

I have created a custom MMC console that will let a staff user change pupils passwords. i have install the adminpak tools of server 2003 onto the XP workstation. If i log on it works fine but when they staff log on it come up with an error "current policies stop microsoft management console from opening in author mode"

 

I think it is a permission to access something on the c:drive, staff have no c/:drive access when on the network here.

 

 

Can anyone help or suggest any way to get this working.

Posted
Top of my head sounds like it's something to do with the rights for users accessing those commands, specifically the "reset password" one. Bit rusty. Go check it :)
  • 1 month later...
Posted (edited)

I am still trying to get this working, I have installed the admin tools on staff members laptop and put the custom msc concole on but they cannot use it. i have tried putting the custom console onto a shared area it still does not work. It comes up with an error 'Current Policies prevent the microsoft management Console from opening in author mode. Consult your administrator for details.'

 

 

Wiseman

 

I like your password changer, is there anyway it can limited so they can only search through certain OU's ie, the pupil one?

Edited by Kyle
Posted

Found out what it was witht he custom MMC.

 

I had it running in author mode, as soon as si changed it to limitied user it worked.

 

 

@Wiseman

 

I would still like to know if you can limit what your password software has access to?

Posted
Found out what it was witht he custom MMC.

 

I had it running in author mode, as soon as si changed it to limitied user it worked.

 

 

@Wiseman

 

I would still like to know if you can limit what your password software has access to?

 

Just make sure you only delegate the user permission to change the passwords of the users in the OUs that you want them to.

Posted
Just make sure you only delegate the user permission to change the passwords of the users in the OUs that you want them to.

 

I advise people to secure their domain from Active Directory rather than from applications. If you use custom security within an application, users can always write a script of download another app to bypass the application level restrictions.

 

I created a quick article about delegation:

Password Control for Active Directory - Security

 

Although I advise using Active Directory to control security, there is an alternative method you can use to hide accounts from Password Control:

Password Control for Active Directory - Hide Accounts

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...