BJG Posted March 10, 2022 Posted March 10, 2022 Currently IT staff here have a regular account, and a separate admin account. When they need to do something that requires admin credentials, they can use 'elevated' permissions with this account; "run as" with admin etc. I'm wondering what the simplest method is to apply this to network folder access, so that regular accounts have typical limited folder access to group shares, but it's possible to 'elevate' the session to obtain full access. At the moment the only way I can see is to remote into the fileserver as admin, or disconnect the current drive mappings then re-establish them with different credentials. Am I missing a simpler way...?
BlueScreen Posted March 10, 2022 Posted March 10, 2022 Have you tried Explorer++? You can try running as the elevated user then accessing the remote share.
DaveTheTech Posted March 10, 2022 Posted March 10, 2022 If I navigate to \\fileserver\d$ I get prompted for creds. Could they not rdp to the server to get whats needed? Or just have access via their standard account? Surely you'd be looking at a PAM based solution? Otherwise, you'd have the option to remember credentials, pretty much loosing and security gains.
bald_pig Posted March 10, 2022 Posted March 10, 2022 You can connect to a share twice, once with the hostname, and once with the server ip, so perhaps map shares to one with default creds, and then map to the other with elevated?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now