To enable deployment of agents to computers running firewall software, consider the following:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\LocalAccountTokenFilterPolicy
This is required because User Account Control (UAC) in Windows Vista or Windows 2008 does not automatically grant administrative rights to local users. This occurs even though the local users are members of the Administrators group.
Note: Setting this value will result in remote UAC access token filtering being disabled.
Setting this value is only worthwhile if the user has a local administrator account on the computer running Windows Vista or Windows 2008. Domain administrators will not benefit from this change.
CAM: 4104
File and printer sharing, and so on: 137, 138
IDManager: 135
File and printer sharing, and so on: 139, 445
The Classic model allows fine control over access to resources and prevents network logons that use local accounts from being mapped to the Guest account, which typically has Read Only access to a given resource.
Copyright © 2013 CA. All rights reserved. |
|