Powershell script adding local user through registry to COM security settings in component services

StackOverflow https://stackoverflow.com/questions/19994082

  •  30-07-2022
  •  | 
  •  

Question

I am adding in a monitoring system that needs a local user on each server (1000+) and it needs to have permissions to DefaultAccessPermission, DefaultLaunchPermission, AccessPermission and LaunchPermission.

I did find the following script online: http://social.technet.microsoft.com/Forums/en-US/5db2707c-87c9-4bb2-a0eb-912363e2814a/using-powershell-to-set-dcom-permissions-for-fim-selfservice-password-reset?forum=ilm2

I have tested this on a 2008 R2 server and it only updates the LaunchPermissions with a given user. I have tried looking through MSDN documentation (http://msdn.microsoft.com/en-us/library/aa910612.aspx and http://msdn.microsoft.com/en-us/library/aa912325.aspx). Maybe I am in over my head but it would be nice if I could script it out. I already have adding a user autocratically with powershell. I just need these COM security permissions updated now.

The other thing that I should mention is that these servers are not on a domain and I cannot go through and install software on the remote machines. So it would be nice if I could have this in a couple of script files and most that could be removed once the script is complete.

Any help or pointing me in the right direction would he appreciated.

Was it helpful?

Solution

I ended up having to use an executable along with my powershell script to get this done. That can be found here http://www.microsoft.com/en-us/download/details.aspx?id=8279 for the dcom permissions. Which there is a similiar answer found here https://serverfault.com/questions/555745/change-a-dcom-applications-identity-with-a-script.

This does not work though on 2012 r2 servers using the new .Net Framework.

Licensed under: CC-BY-SA with attribution
Not affiliated with StackOverflow
scroll top