--
Bruce Sanderson MVP
http://members.shaw.ca/bsanders/
It's perfectly useless to know the right answer to the wrong question.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"Bruce Sanderson" <bsan...@newsgroups.nospam> wrote in message
news:uWfQOCRr...@TK2MSFTNGP04.phx.gbl...
Any user in hold of Debug permission (SeDebug Privilege) can easily become
an owner (Administrator) on that PC... User with debug permission can run
tools such as lsadump, pwdump etc...
--
Mike
Microsoft MVP - Windows Security
"S. Pidgorny <MVP>" <slav...@yahoo.com> wrote in message
news:%23KT4n%23frGH...@TK2MSFTNGP04.phx.gbl...
I tried granting a user both the "increase scheduling priority" and "debug
programs" "right" under Security Settings, Local Policies, User Rights
Assignment (in Computer Configuration) via GPO to a specific domain user,
but that user still could not add a check mark to the "Show processes from
all users" check box in Task Manager.
I verified using gpresult /v that the settings in the GPO had been applied
to the computer.
Any other ideas come to mind?
It may well be that there is no specific right or permission that grants
this - this ability may be built-in to the Administrators group inherent
rights (unfortunately!) but it would be nice to know definitively.
--
Bruce Sanderson MVP Printing
http://members.shaw.ca/bsanders
It is perfectly useless to know the right answer to the wrong question.
"S. Pidgorny <MVP>" <slav...@yahoo.com> wrote in message
news:%23KT4n%23frGH...@TK2MSFTNGP04.phx.gbl...
Roger
"Bruce Sanderson" <bsan...@news.postalias> wrote in message
news:O6FCVy6r...@TK2MSFTNGP04.phx.gbl...
For an unknown reason, the client application randomly goes into a very
tight CPU loop - no page faults, no I/O, no database interaction, no network
activity. There are between 400 and 500 users spread over 24 servers (the
application is a real memory hog and also can be quite CPU intensive when
operating normally). The client application is a win32 executable - a
classic desktop type application - no web browser/server involved. It is
not unusual for a single user to have multiple instances of the client
running - each process manages one window. At any given point in time,
there are sometimes as many as 100 instances of the client application
running on each server. When one of the client application instances
(.exe - process) gets into this loop situation, it completely hogs one of
the two CPUs on that server, which impacts the performance for all users on
that server. Some days this doesn't happen at all; on other days we see
five or six intances. Unfortunately, most of our users are in the habit of
merely ignoring the "hung" window and starting another instance of the
client application - which works correctly and allows them to proceed with
their work. Sometimes, the user will "Close" the window, believing that
this has "solved the problem", but this unfortunately does not cause the
associated process to terminate.
We're working with the application vendor to find out what triggers this
problem and get it fixed, but the problem is quite random and is proving
hard for the vendor to diagnose. This is a major "system" for our agency
and switching to another vendor would be a multi-year, very expensive
process - its not going to happen!
So, in the mean time, we're faced with these runaway processes on the
Terminal Servers. We monitor the %CPU on all the servers and can see when
this problem is happening on a particular server becuase the %CPU is then
consistently high for a long time. We've decided that a couple of the staff
in our Help Desk are knowledgeable and trusted enough to be able to
identify, track down and terminate the "bad" processes. So I'm looking for
a way to allow these few users to view and terminate processes from any user
without being an administrator. We appreciate that such a
right/privilege/permission could be used to terminate any process, including
vital system processes, but judge that risk slight and acceptable given the
particular people that would be granted that right and the alternative of
suffering degraded performance. If there really isn't a way without them
being administrators, then we'll just live with that.
I'll take a look at PSTools suite as you suggest. I'm somewhat familiar
with System Internals and have used some of their tools for other purposes.
Thanks for your time.
--
Bruce Sanderson MVP Printing
http://members.shaw.ca/bsanders
It is perfectly useless to know the right answer to the wrong question.
"Roger Abell [MVP]" <mvpN...@asu.edu> wrote in message
news:etnmkC$rGHA...@TK2MSFTNGP02.phx.gbl...
"Bruce Sanderson" <bsan...@news.postalias> wrote in message
news:%23t2ecZU...@TK2MSFTNGP04.phx.gbl...
--
Luiz Alberto Koroll
------------------------------------------------------------------------
Luiz Alberto Koroll's Profile: http://forums.techarena.in/member.php?userid=50501
View this thread: http://forums.techarena.in/showthread.php?t=555483
would be grateful for any suggestions.
--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
* http://sl.mvps.org * http://msmvps.com/blogs/sp *
"theelk" <the...@discussions.microsoft.com> wrote in message
news:0D154630-ED9B-4018...@microsoft.com...
Thanks,
Chaz
--
capnjack
------------------------------------------------------------------------
capnjack's Profile: http://forums.techarena.in/members/136273.htm
View this thread: http://forums.techarena.in/server-security/555483.htm