Jump to content

Using 'elevated' admin rights for folder access


Recommended Posts

Posted

Currently IT staff here have a regular account, and a separate admin account. When they need to do something that requires admin credentials, they can use 'elevated' permissions with this account; "run as" with admin etc.

 

I'm wondering what the simplest method is to apply this to network folder access, so that regular accounts have typical limited folder access to group shares, but it's possible to 'elevate' the session to obtain full access. At the moment the only way I can see is to remote into the fileserver as admin, or disconnect the current drive mappings then re-establish them with different credentials. Am I missing a simpler way...?

Posted

If I navigate to \\fileserver\d$ I get prompted for creds.

Could they not rdp to the server to get whats needed? Or just have access via their standard account?

 

Surely you'd be looking at a PAM based solution? Otherwise, you'd have the option to remember credentials, pretty much loosing and security gains.

Posted
You can connect to a share twice, once with the hostname, and once with the server ip, so perhaps map shares to one with default creds, and then map to the other with elevated?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...