Windows 7 - Prompting Admin credential for running applications

Asked By Saleem on 31-Jan-11 07:52 AM

Hello, I have a small question maybe someone can help me with.

 

I am running Windows 7 Enterprise 64 bit operating system; I am trying to run some application in user profile which doesn’t have admin rights, it is prompting the admin credential for running the applications. I need to run those applications in users profiles those doesn’t have admin right without prompting admin credentials.

 

Your help is greatly appreciated and I look forward to hearing a solution.

Thanks for your time.

 

Regards,

Saleem PS

Venkat K replied to Saleem on 31-Jan-11 10:09 AM
Usually the application will run based on the account which the "application pool" run.
You can give the admin right only for the account which the application pool run. So further you no need to give any admin access for the users who are browsing the application.

Hope this helps!

sandeep replied to Saleem on 01-Feb-11 10:22 AM
HI,

    please provide more clarity on your query, as mentioned earlier it seems to be like you have an application designed which shouldn't prompt for admin rights while executing ? !

note : by default depends on what you are trying to do with your app, it will generally prompts for credentials. only solutions for it is to add user onto admin group or run your app as admin.


thanks
sandeep
Mike Manny replied to Saleem on 01-Feb-11 11:22 AM

Your issue is with User Account Control on Windows 7. Fortunately you do have the Enterprise edition so you should be able to run it in Xp mode.  You could also turn off UAC but i do not suggest it.  you could also change the permissions of folders to make it work with UAC, but that just sounds terrible.  I personally would try Run Windows XP (or an earlier version of Windows) in a virtual machine  then if that doesn't work, test it with Disable UAC to make sure it can work at all like that.

That might be the only resolution to the issue, but be careful of the increased security risks.



For applications to receive the Certified For Windows Vista or Certified For Windows 7 logo, the application must be designed to work well for standard users unless the tool is specifically intended for use by administrators. However, many applications were developed prior to Windows Vista and will not work correctly with UAC enabled. These might include some older antispyware, antivirus, firewall, CD/DVD-authoring, disk-defragmentation, and video-editing tools designed for Windows XP or earlier versions of Windows.

Typically, most features of an application will work correctly with UAC enabled, but specific features might fail. You have several ways to work around this:

  • Run the application with administrator credentials As described in the section titled "How to Control UAC Using Application Properties" earlier in this tutorial, you can specify that an application always requires administrator credentials.
  • Modify permissions on the computer If an application requires access to a protected resource, you can change the permissions on that resource so that standard users have the necessary privileges. Instructions on how to isolate the protected resources are provided later in this section.
  • Run Windows XP (or an earlier version of Windows) in a virtual machine If the application fails with administrative privileges or you do not want to grant the application administrative privileges to your computer, you can run the application within a virtual machine. Virtual machines provide an operating system within a sandbox environment, allowing you to run applications within Windows XP without requiring a separate computer. You can maximize virtual machines so that they display full screen, providing a similar experience to running the operating system natively. Virtual machines perform slightly slower than applications that run natively within Windows, however. Windows 7 Professional, Enterprise, and Ultimate operating systems include Windows Virtual PC and the Windows XP Mode environment.
  • Disable UAC You can disable UAC to bypass most application compatibility problems related to the permission changes in Windows Vista. However, this increases the security risks of client computers when running any application, and therefore is not recommended. To disable UAC, read the section titled "How to Configure User Account Control" later in this tutorial.

To isolate the protected resources accessed by an application, follow these steps:

  1. On a computer running Windows 7 with UAC enabled, download and install the Microsoft Application Verifier from http://www.microsoft.com/downloads/details.aspx?FamilyID=C4A25AB9-649D-4A1B-B4A7-C9D8B095DF18&displaylang=en.
  2. On the same computer, install the ACT, which you can download at http://go.microsoft.com/fwlink/?LinkId=23302.
  3. Start the Standard User Analyzer (which is installed with the ACT). On the App Info tab, click Browse and then select the application's executable file.
  4. Click Launch and then respond to any UAC prompts that appear. The Standard User Analyzer will start the application. Use the application, especially any aspects that might require elevated privileges, and then close the application.
  5. Click the View menu and select Detailed Information.
  6. Wait a few moments for the Standard User Analyzer to examine the application log file. Browse the different tabs to examine any errors. Errors indicate that the application attempted to perform an action that would have failed if it were not run with administrative privileges.

On the File tab and the Registry tab, notice the Work With Virtualization column. If the entry in that column is Yes, that particular error will not cause a problem as long as UAC virtualization is enabled. If UAC virtualization is disabled, the error will still occur. If the entry in the column is No, it will always be a problem unless the application is run as an administrator.

Nikhil Mahajan replied to Mike Manny on 03-Feb-11 07:20 AM
hey..
administrator  account...
go to run ...then type cmd ... right click on it and run as administrator....
command prompt will come..
then write following command..

net user administrator /active:yes
and hit enter....

then just switch user.. login to administrator account.. then u wont face any credential  prob..