Windows 7 + app needs Admin Privileges


Recommended Posts

Hello gang,

My office uses an app that is requiring Admin Privileges. The users are Customer Service reps and there is no way that we are going to give these people this level of access. I spoke with the company that created the app and their responses have been:

  • Give the users admin rights (ummmmm, NO!)
  • Right click and run the app with Admin Rights... as if an Administrator is available to log in 24/7

I asked if they could give me a list of folders or files that are accessed by their app. A week later the tech contacted me and informed me that they cannot give me such a list (do they not know?)

The app runs fine under XP, but now with that being, finally, phased out we have to find a way to get this to work.

So at this point I am at a bit of a loss to know what to do next. For the record I got out of networking and support over 17 years ago (I much prefer Software Development, thank you) so I cannot be sure if it is a specific port that this app is using or.... ????!

Any thoughts?

Correct. It runs on Virtual PC, but allows you to run applications without booting straight into Windows XP. You will need to install Windows XP Mode along with it. It was made for situations like yours.

Yea, I already thought about running XP on VPC but management doesn't want to do that either. Thanks though.

You could run process monitor

http://technet.microsoft.com/en-us/sysinternals/bb896645

And see what its trying to do, and then give the permissions it needs to do that without full admin rights.

You could run process monitor

http://technet.micro...ernals/bb896645

And see what its trying to do, and then give the permissions it needs to do that without full admin rights.

Thanks. This is part of what my manager wants me to do. Once I find out, how do I add these values to Active Directory? (any sort of primer would be helpful)

Odds are i have a feeling the application put something in the system hive. first application that comes to mind is quickbooks. this is a big epic fail imo. you may be able to get by with changing a few registery permissions. what application is it?

You can try VMware Thinapp, Microsoft App-V, Spoon Studio or one of the other application virtualization software perhaps (list here: http://en.wikipedia.org/wiki/Portable_application_creators)? These programs package your software such that they will read and write to a virtual file system and virtual registry so they should be able to run without admin privileges.

I've only personally tried the trial of VMware Thinapp, and it seems to work with most apps that don't do stuff like drivers or some kind of machine-based activation. You just start ThinApp in a clean Windows install and then it takes note of what is currently on the system. Then you install and run the app that you want to package, and then run ThinApp again - again it will take note of what is now on the system, and generate a package with the difference as a virtualized file system and registry. Even if your company cannot afford ThinApp, at least by using the trial you'd know from the virtual file system and registry which folders/registry keys the program writes to and can change the permissions to cater to the app.

Thanks. This is part of what my manager wants me to do. Once I find out, how do I add these values to Active Directory? (any sort of primer would be helpful)

Try giving all authenticated users full access to the folder that the app uses. Give us some more specifics on the app, and we could help out more specifically.

Odds are i have a feeling the application put something in the system hive. first application that comes to mind is quickbooks. this is a big epic fail imo. you may be able to get by with changing a few registery permissions. what application is it?

The app is by Teleflora and is used to monitor flower orders (exciting? Why yes it is!)

I'm going to try the Process Monitor and see if I can find out what it affects. (Teleflora would not, or could not tell me what it uses)

This topic is now closed to further replies.
  • Posts

    • My father still uses a programme written in dbase3. Still manages to work with a little help from dosbox. 
    • Microsoft hides these secret Windows 11 performance boost settings available on every PC by Sayan Sen Windows enthusiasts often look for ways to extract as much performance out of their systems as possible, and it's often the case that they try and do so while trying to minimize the heat and power consumption. This is especially relevant in the case of mobile Windows PCs since laptops and notebooks tend to get hot and management of that heat and power is harder in such a form factor. As such users often turn to techniques like under-volting which can be used to squeeze out the maximum capabilities of a chip while also maintaining lowered power levels. There are official apps from AMD and Intel with the likes of Ryzen Master and XTU (Extreme Tuning Utility). While these are quite handy, most enthusiasts probably prefer to dig into the BIOS and play around with settings there like Curve Optimizer on Ryzen, which lets users set various frequency-voltage scaling values. These are essentially called P-States. If you are not familiar with them, Processor Power Management is done through Advanced Configuration and Power Interface (ACPI) P-states and C-states. While P-states or performance pwoer states handle CPU voltage-frequency scaling, C-states deal with CPU sleep states so that some of the CPU functions, which are not necessary at that moment, can be disabled. The P-states and C-states work together to make the processor run more efficiently. It helps the OS and apps determine which cores can be parked and which should be boosted. Of course not every user is an enthusiast or knows the technicalities and integrities of how things like overclocking or undervolting work. Thankfully for them Windows itself offers something pretty cool, though it is hidden by default on all systems. By default, Windows only has two P-States, "Minimum Processor State" and "Maximum Processor State." However, this can be changed with a Registry trick to expand the options under a secret "Processor performance boost mode" dropdown. This essentially enables the HWP or hardware P-States available on a device, and these are not controlled just by the OS itself as the underlying hardware gets involved too. In total there are five Processor Performance Boost Mode profiles that control how Windows requests and allows CPU turbo/boost behavior under the different power policies. They are: Disabled: In this mode, processor boosting is effectively turned off. The CPU will avoid entering turbo or boost frequencies and instead operate closer to its base frequency ceiling. This can significantly reduce power consumption and heat output, but at the cost of reduced burst performance and responsiveness in short workloads. Enabled: This is the standard behavior where boost functionality is allowed under normal conditions. The processor can opportunistically increase frequency when workload demands it, balancing performance gains with power and thermal constraints as managed by the system. Aggressive: Aggressive mode favors performance more heavily, allowing the CPU to enter higher boost states more readily and sustain them longer. This should in theory improve responsiveness under bursty or heavy workloads but increases power draw and thermal output compared to the default enabled behavior. Efficient Enabled: This mode still allows boosting, but with a stronger bias toward energy efficiency. The system attempts to use boost more selectively, avoiding unnecessary frequency spikes when the performance gain is marginal. Efficient Aggressive: This is a hybrid approach where boost is still performance-responsive, but the system continuously weighs efficiency more heavily than in Aggressive mode. It aims to deliver noticeable performance improvements while reducing wasted power in less demanding scenarios. Here's how to enable the Processor performance boost mode: Open Registry Editor: Press Win+R, type regedit, and click OK. Go to: HKLM\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\be337238-0d82-4146-a960-4f3749d470c7 (where HKLM stands for HKEY_LOCAL_MACHINE_) Modify the value of Attributes from 1 to 2 (you can find modify option by right-clicking) After that, exit Registry, you should now be able to see the new "Processor performance boost mode" dropdown menu: As you can see there are now five new P-States or CPPC states or power profile available that help define the boost mode processor setting on your PC. Wrapping it up here's a quick run-down of the settings as defined by Microsoft itself. Setting Description Disabled The corresponding P-state-based behaviour is disabled. Collaborative Processor Performance Control (CPPC) behaviour is disabled. Enabled The corresponding P-state-based behaviour is enabled. CPPC behaviour is Efficient Enabled. Aggressive The corresponding P-state-based behaviour is enabled. CPPC behaviour is Aggressive. Efficient Enabled The corresponding P-state-based behaviour is Efficient. CPPC behaviour is Efficient Enabled. Efficient Aggressive The corresponding P-state-based behaviour is Efficient. CPPC behaviour is Aggressive. Aggressive At Guaranteed Windows calculates the desired extra performance above the guaranteed performance level, and asks the processor to deliver that specific performance level. Efficient Aggressive At Guaranteed Windows always asks the processor to deliver the highest possible performance above the guaranteed performance level. In the next part we shall be comparing these settings to explore how much of a benefit or regression they can provide in terms of performance and power efficiency. If you decide to change the values on your system and are experiencing problems like crashes or an overheating PC, make sure to revert the steps back to the original state.
    • I think he means you haven't reviewed previous UFC games. Of course it doesn't matter... Every time you just report on something that involves the President even if just simply what happened you guys usually get accused of being anti-Trump. We live in fun times.
    • So how did you solve the problem? Disabling Secure Boot isn’t a solution.
  • Recent Achievements

    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
    • One Month Later
      agatameier earned a badge
      One Month Later
    • Week One Done
      agatameier earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      518
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      ATLien_0
      93
    5. 5
      Steven P.
      77
  • Tell a friend

    Love Neowin? Tell a friend!