Jump to content

Recommended Posts

Posted

I am trying to install Microlibrarian on a 32 bit Windows 7 Pro computer and it seems that in order to register the thumbprints, the user must be a local administrator. I want to make the librarian's domain account a local admin on this computer only.

I thought I had done it but when I log in as her I don't get the usual desktop which is covered in icons including the one for the library system, I get the first 10 icons only, which are normally found on the domain network manager's desktop.( The domain network manager doesn't have all the program icons etc). She certainly seems to be an admin as she can see the C drive which normal users cannot.

I really need her to be able to see all the usual icons AND have local admin access.

Can someone talk me through this? I don't see what I have done wrong but I don't want to prejudice anyone so I am not going to tell you what I did

Posted
I agree as above, create a domain user, but then on the local workstation open up MMC and under local admins, either add 'domain users' or the user's username to the list then reboot.
Posted

Thanks Ben, and Michael - that is EXACTLY what I did - but the result is as you see.

At least I am NOT going mad - I had got to the point where I really thought I had done something unbelievably stupid.

Now I know I didnt - what's going on then??

The only thing I didnt say was that I tried with her own account with the results as above, so then I created a new user called library, put it in the same place as all the staff accounts so it would pick up the redirected desktop etc and the result was exactly the same as above....

Posted
It sounds like Group Policy isn't applying properly?

 

If the software just requires the user account to be a member of the LOCAL ADMINISTRATORS group then group policies etc. wouldn't affect this. If the user account is in the Local Admin's group then.. it's in the Local Admins Group.

 

:/ seems weird to me..

@witch When you have logged on as the account, go to Command Prompt, type: gpresult /r and press enter.

 

look at the section which shows you "The user is a part of the following security groups" and see what it states.

 

James.

Posted

The accounts in question log on fine as long as I havent added them as local admins on the machine and all group policies are there.

I'll have a look at that tomorrow, thanks James :)

Posted
And when you are logging in as this user... are you logging in to the domain or to the local machine?

The domain - I need her to be able to see all the domain stuff. It is just that in order to use the fingerprint program, she needs to be an admin

Posted

An admin for a fingerprint software?!?

 

I hate software like that!! What software is it? It may be that its permissions on certain directories which would be a better option as it wouldn't open your system up to any threats from a user installing/infecting the local machine.

Posted (edited)

Right. Have had a look and it says the user is part of the following security groups:

Domain User

Everyone

BUILTIN\Administrators

BUILTIN\Users

NT AUTHORITY INTERACTIVE

CONSOLE LOGON

NT AUTHORITY\AUTHENTICATED USERS

This organisation

local

All_staff

High Mandatory Level

So - are we saying that if the user is a local admin, despite being logged on as a domain user ON the domain, they will pick up the local admin stuff and not the domain?

I just want this user to pick up the redirected folder!!

Edited by witch
Posted (edited)

According to GP result, all the appropriate policies are applying, from default domain downwards. Whilst the shortcuts dont appear I can see that the policies are applying by thigns like the RUN COMMAND DISAPPEARING EVERY TIME I LOG OFF AND ON AGAIN!!!!!

So, I thought OK if it is acting like a local machine I will create a shortcut for the desktop...BUT that doesnt appear which means that the policies are applying that only allow redirected folder icons - EXCEPT THEY DON'T APPEAR!!!

Gah.... I just need the librarian to be able to access the microlibrarian website as an local administrator (but on the domain) via some kind of shortcut PLEASE can someone help??

Edited by witch
Posted

If you use the original login again for the librarian, i.e. no admin rights, and set up a new account for the running of the thumbprint software (with admin rights), you should then be able to set in the compatibility setting to always run as admin.

This way when the librarian runs the software it will ask for authentication and you can put in the admin user's credentials, or use RunasSPC to automate it if it doesn't need to be that secure (or you don't mind anyone using it on the librarians comp)

Posted
So - are we saying that if the user is a local admin, despite being logged on as a domain user ON the domain, they will pick up the local admin stuff and not the domain?

I just want this user to pick up the redirected folder!!

 

Yes, that's correct about the local user bit. If you only want that user to pick up a redirected folder/shortcut, you need to place them lower down the chain - for example:

 

Curric OU > Curric Users OU (this is where all pupil objects and the necessary GPO would be linked). Create another sub OU and link the GPO:

 

Curric OU > Curric Users OU > Library User OU (Place the library user here and link a GPO here). GPOs last in the chain will take priority.

Posted (edited)
I created 'library' as a 'Staff' user and it is with all the other staff users which do get all the redirected folders etc. Should it be somewhere else then? Edited by witch
Posted

The Micro Librarian thumbprint reader is a pain in the backside on XP too - also needs local admin rights if it's any consolation.

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...