Click here to get back home

Re: Remote Computer Management

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: Remote Computer Management Andrew Hayes 12-07-2005
Get Chitika Premium
Posted by Andrew Hayes on December 7, 2005, 9:49 pm
Please log in for more thread options
Thanks Joe.

I took a look at the KB article and figured that since it uses DCOM, and
DCOM got really messed around with in 2003 SP1 and XP SP2, that that is the
likely cause.

I did some more searching and came up with a library topic called "Securing
a remote WMI connection":

http://msdn.microsoft.com/library/default.asp?url=/library/en-us/wmisdk/wmi/securing_a_remote_wmi_connection.asp

Unfortunately, most of what that said is already covered as the Domain
Admins group is a member of the local Administrators group on the XP
machine, and has all the various remote access, remote start, permissions.

What I did find though is that when I use the WMI Control snap-in from the
2003 server connected remotely to an XP desktop, it gives me the same error:

Failed to connect to DESKTOP
because "Win32: Access is denied."

The default namespace for scripting, according to the WMI control of the
desktop, is root\cimv2. The local Administrators group (of which the Domain
Admins is a member) has full rights to the root namespace and all
subnamespaces.

Looking at the WMIPROV.LOG file on the XP desktop I see that there are
various entries that say "Impersonation failed - Access denied" and "WDM
call returned error: 4200". Maybe that has something to do with it.

Also, when I click on the Internet Information Services (IIS) Manager, it
pops up an Access Denied box saying "The username/password you used to
connect to this machine does not have administrator privileges, or you
entered an incorrect password. Please provide an account with administrator
access.", with a couple of textboxes for entering a username and password.

This is very strange when I'm running Computer Management as the Domain
Admin, who most certainly does have administrator privileges on the remote
machine. This would mean that the wrong security information is being passed
to the XP desktop, or is not being passed at all.

What is also strange is that even if I type the XP machines local
adminsitrator username and password, it still pops up an Error dialog saying
"You have been denied access to this machine.". Right-clicking on IIS
Manager in Computer Management and clicking on Properties brings up an "RPC
Server unavailable" error.

> Hey, this sounds a lot like my question earlier that was never answered.
> I did find this Article from 10/2/2003 that gave me the clues to getting
> it working again. So my only problem now is the "Why" part but anyway
> this is the article ID: 248823
>
> please post if you have other info.
>
>
>> For some reason, I can no longer use the Properties option for all of the
>> XP desktops and 2003 servers in the office when I connect to them
>> remotely through Computer Management from my 2003 management server.
>>
>> I can still see and use the System Tools, Storage, and Services and
>> Applications sub-menus for the remote machines but no longer can get OS
>> info. It always comes up with a System Properties dialog saying Win32:
>> Access Denied, even though I did Run As... and used the Domain
>> Administrator account.
>>
>> Maybe it's a service pack change, but how do I give Domain Administrator
>> access rights to remote Computer Management system properties?
>>
>>
>
>



Posted by Andrew Hayes on December 8, 2005, 1:45 am
Please log in for more thread options
Further information.

When using Computer Management from Windows XP to remotely query WMI Control
on a Windows 2000 Professional machine, it works correctly.

Performing the same action from a Windows 2003 SP1 Server responds with the
Failed to connect to DESKTOP because "Win32: Access is denied." message.

Using the XP machine to try and get system properties from all the desktops,
some of the Windows 2000 machines worked, while some of the 2000/XP machines
give the "Win32: Access is denied." message, and some give Failed to connect
to DESKTOP because "Win32: The RPC server is unavailable."

Anyone have any ideas on why this is?



Posted by Roger Abell [MVP] on December 8, 2005, 10:31 pm
Please log in for more thread options
The WMI management is wanting to use RPC endpoints, and these
can be any ephemeral Tcp port. I do not routinely do much workstation
management, but with servers what you report sounds the same as
when RCP/DCE, or as it is called in the W2k3 group policy, Remote
Management is not provided as an exemption in the firewall for the
machines from which remote WMI is being attempted.

> Further information.
>
> When using Computer Management from Windows XP to remotely query WMI
> Control on a Windows 2000 Professional machine, it works correctly.
>
> Performing the same action from a Windows 2003 SP1 Server responds with
> the Failed to connect to DESKTOP because "Win32: Access is denied."
> message.
>
> Using the XP machine to try and get system properties from all the
> desktops, some of the Windows 2000 machines worked, while some of the
> 2000/XP machines give the "Win32: Access is denied." message, and some
> give Failed to connect to DESKTOP because "Win32: The RPC server is
> unavailable."
>
> Anyone have any ideas on why this is?
>
>



Similar ThreadsPosted
Help with Computer Management Services settings September 1, 2007, 6:22 pm
Account lock out when accessing computer management remotely September 27, 2006, 11:32 am
FSRM remote management permissions June 11, 2007, 11:28 am
LsaEnumerateAccountsWithUserRight failed for remote computer March 15, 2006, 2:29 pm
Can a Computer (so everyone who logs on on that computer) have access rights? January 12, 2006, 6:50 am
Password Management Issue July 11, 2005, 12:19 pm
Patch Management for Non-MS Products October 3, 2005, 1:13 pm
User management issues July 20, 2006, 10:50 am
Securing management access? February 16, 2008, 7:52 am
Simple user/password management? July 6, 2005, 11:50 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap