Allowing Domain Users to run winrm commandsRun remote powershell as administratorRemote PowerShell, WinRM Failures: WinRM cannot complete the operationWinRM HTTPS Connection to Windows 8 SystemsWindows Remote Management Over Untrusted DomainsGetting Access Denied from WinRM on Windows 2008 R2Get local path of Windows fileshare when running a PowerShell script remotely via WinRMRemote Powershell not working but test-wsman doeswindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos databaseClients / Groups / Users not shown in group policy management console (GPMC)

Multi tool use
Multi tool use

Is there an official reason for not adding a post-credits scene?

Find the cheapest shipping option based on item weight

Emotional immaturity of comic-book version of superhero Shazam

3D Volume in TIKZ

What to use instead of cling film to wrap pastry

Refinish or replace an old staircase

ZSPL language, anyone heard of it?

How did the Venus Express detect lightning?

Is bounce rate of a website a ranking factor?

What was Bran's plan to kill the Night King?

Why are UK Bank Holidays on Mondays?

Should I decline this job offer that requires relocating to an area with high cost of living?

Would you use "llamarse" for an animal's name?

What is the solution to this metapuzzle from a university puzzling column?

I'm in your subnets, golfing your code

Proving n+1 th differential as zero given lower differentials are 0

How can I roleplay a follower-type character when I as a player have a leader-type personality?

Where can I go to avoid planes overhead?

What does 'made on' mean here?

Causes of bimodal distributions when bootstrapping a meta-analysis model

Wrong answer from DSolve when solving a differential equation

Are pressure-treated posts that have been submerged for a few days ruined?

Adding command shortcuts to bin

Something that can be activated/enabled



Allowing Domain Users to run winrm commands


Run remote powershell as administratorRemote PowerShell, WinRM Failures: WinRM cannot complete the operationWinRM HTTPS Connection to Windows 8 SystemsWindows Remote Management Over Untrusted DomainsGetting Access Denied from WinRM on Windows 2008 R2Get local path of Windows fileshare when running a PowerShell script remotely via WinRMRemote Powershell not working but test-wsman doeswindows-ubuntu-bash + hypervisor winrm + ansible - Server not found in Kerberos databaseClients / Groups / Users not shown in group policy management console (GPMC)






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








4















Currently i have a AD/Kerberos Configured on one EC2 instance(Windows 2008 R2) and created couple of users. Each of the users has administrator privileges. When We login as a non-domain Administrator, i can successfully execute the winrm commands. But when i login as the domain User (who has administrator privileges), i cannot run the winrm commands:



C:Usersdomain-username>winrm get winrm/config/service/auth
WSManFault
Message = Access is denied.

Error number: -2147024891 0x80070005
Access is denied.


I check the Group Policy Editor for WinRM did not find anything relevant. I am not sure what i am missing.










share|improve this question






















  • Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

    – HopelessN00b
    Jul 13 '12 at 20:57







  • 1





    Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

    – Todd Wilcox
    Dec 5 '17 at 18:34

















4















Currently i have a AD/Kerberos Configured on one EC2 instance(Windows 2008 R2) and created couple of users. Each of the users has administrator privileges. When We login as a non-domain Administrator, i can successfully execute the winrm commands. But when i login as the domain User (who has administrator privileges), i cannot run the winrm commands:



C:Usersdomain-username>winrm get winrm/config/service/auth
WSManFault
Message = Access is denied.

Error number: -2147024891 0x80070005
Access is denied.


I check the Group Policy Editor for WinRM did not find anything relevant. I am not sure what i am missing.










share|improve this question






















  • Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

    – HopelessN00b
    Jul 13 '12 at 20:57







  • 1





    Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

    – Todd Wilcox
    Dec 5 '17 at 18:34













4












4








4








Currently i have a AD/Kerberos Configured on one EC2 instance(Windows 2008 R2) and created couple of users. Each of the users has administrator privileges. When We login as a non-domain Administrator, i can successfully execute the winrm commands. But when i login as the domain User (who has administrator privileges), i cannot run the winrm commands:



C:Usersdomain-username>winrm get winrm/config/service/auth
WSManFault
Message = Access is denied.

Error number: -2147024891 0x80070005
Access is denied.


I check the Group Policy Editor for WinRM did not find anything relevant. I am not sure what i am missing.










share|improve this question














Currently i have a AD/Kerberos Configured on one EC2 instance(Windows 2008 R2) and created couple of users. Each of the users has administrator privileges. When We login as a non-domain Administrator, i can successfully execute the winrm commands. But when i login as the domain User (who has administrator privileges), i cannot run the winrm commands:



C:Usersdomain-username>winrm get winrm/config/service/auth
WSManFault
Message = Access is denied.

Error number: -2147024891 0x80070005
Access is denied.


I check the Group Policy Editor for WinRM did not find anything relevant. I am not sure what i am missing.







active-directory remote remote-access winrm






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Jul 9 '12 at 6:43









CheezoCheezo

158128




158128












  • Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

    – HopelessN00b
    Jul 13 '12 at 20:57







  • 1





    Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

    – Todd Wilcox
    Dec 5 '17 at 18:34

















  • Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

    – HopelessN00b
    Jul 13 '12 at 20:57







  • 1





    Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

    – Todd Wilcox
    Dec 5 '17 at 18:34
















Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

– HopelessN00b
Jul 13 '12 at 20:57






Is SysInternal's "ShellRunAs" tool an acceptable (if hacky) workaround? Supply it the program and an account with the access you need (like a domain admin service account) and you'll be able to execute it under a user's context, whether they have admin rights or not.

– HopelessN00b
Jul 13 '12 at 20:57





1




1





Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

– Todd Wilcox
Dec 5 '17 at 18:34





Can you clarify "has administrator privileges"? Did you add the user(s) in question to the local Administrators group?

– Todd Wilcox
Dec 5 '17 at 18:34










2 Answers
2






active

oldest

votes


















0














First thing that pops in my head: is cmd elevated? It would be by default on local Administrator account, not so with domain accounts that belong to local Administrators group. Your current prompt (c:users...) kind of suggests this might be the reason for access rights issues (elevated cmd starts in c:windowssystem32 by default).



I've tested both elevated and non-elevated and get same results as you do with "normal" and expected results with "elevated" one.






share|improve this answer























  • Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

    – Cheezo
    Jul 11 '12 at 14:55



















-1














You have to add the user to the group "Remote Management Users" on the WinRM server.






share|improve this answer

























    Your Answer








    StackExchange.ready(function()
    var channelOptions =
    tags: "".split(" "),
    id: "2"
    ;
    initTagRenderer("".split(" "), "".split(" "), channelOptions);

    StackExchange.using("externalEditor", function()
    // Have to fire editor after snippets, if snippets enabled
    if (StackExchange.settings.snippets.snippetsEnabled)
    StackExchange.using("snippets", function()
    createEditor();
    );

    else
    createEditor();

    );

    function createEditor()
    StackExchange.prepareEditor(
    heartbeatType: 'answer',
    autoActivateHeartbeat: false,
    convertImagesToLinks: true,
    noModals: true,
    showLowRepImageUploadWarning: true,
    reputationToPostImages: 10,
    bindNavPrevention: true,
    postfix: "",
    imageUploader:
    brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
    contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
    allowUrls: true
    ,
    onDemand: true,
    discardSelector: ".discard-answer"
    ,immediatelyShowMarkdownHelp:true
    );



    );













    draft saved

    draft discarded


















    StackExchange.ready(
    function ()
    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f405952%2fallowing-domain-users-to-run-winrm-commands%23new-answer', 'question_page');

    );

    Post as a guest















    Required, but never shown

























    2 Answers
    2






    active

    oldest

    votes








    2 Answers
    2






    active

    oldest

    votes









    active

    oldest

    votes






    active

    oldest

    votes









    0














    First thing that pops in my head: is cmd elevated? It would be by default on local Administrator account, not so with domain accounts that belong to local Administrators group. Your current prompt (c:users...) kind of suggests this might be the reason for access rights issues (elevated cmd starts in c:windowssystem32 by default).



    I've tested both elevated and non-elevated and get same results as you do with "normal" and expected results with "elevated" one.






    share|improve this answer























    • Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

      – Cheezo
      Jul 11 '12 at 14:55
















    0














    First thing that pops in my head: is cmd elevated? It would be by default on local Administrator account, not so with domain accounts that belong to local Administrators group. Your current prompt (c:users...) kind of suggests this might be the reason for access rights issues (elevated cmd starts in c:windowssystem32 by default).



    I've tested both elevated and non-elevated and get same results as you do with "normal" and expected results with "elevated" one.






    share|improve this answer























    • Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

      – Cheezo
      Jul 11 '12 at 14:55














    0












    0








    0







    First thing that pops in my head: is cmd elevated? It would be by default on local Administrator account, not so with domain accounts that belong to local Administrators group. Your current prompt (c:users...) kind of suggests this might be the reason for access rights issues (elevated cmd starts in c:windowssystem32 by default).



    I've tested both elevated and non-elevated and get same results as you do with "normal" and expected results with "elevated" one.






    share|improve this answer













    First thing that pops in my head: is cmd elevated? It would be by default on local Administrator account, not so with domain accounts that belong to local Administrators group. Your current prompt (c:users...) kind of suggests this might be the reason for access rights issues (elevated cmd starts in c:windowssystem32 by default).



    I've tested both elevated and non-elevated and get same results as you do with "normal" and expected results with "elevated" one.







    share|improve this answer












    share|improve this answer



    share|improve this answer










    answered Jul 11 '12 at 13:33









    BartekBBartekB

    63869




    63869












    • Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

      – Cheezo
      Jul 11 '12 at 14:55


















    • Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

      – Cheezo
      Jul 11 '12 at 14:55

















    Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

    – Cheezo
    Jul 11 '12 at 14:55






    Thanks for responding. I tried using the WinRM SOAP APIs as well and faced the same issue. Thats the primary usecase actually. So elevating cmd won't help my cause :)

    – Cheezo
    Jul 11 '12 at 14:55














    -1














    You have to add the user to the group "Remote Management Users" on the WinRM server.






    share|improve this answer





























      -1














      You have to add the user to the group "Remote Management Users" on the WinRM server.






      share|improve this answer



























        -1












        -1








        -1







        You have to add the user to the group "Remote Management Users" on the WinRM server.






        share|improve this answer















        You have to add the user to the group "Remote Management Users" on the WinRM server.







        share|improve this answer














        share|improve this answer



        share|improve this answer








        edited Nov 20 '14 at 17:06









        Dave M

        4,37982428




        4,37982428










        answered Nov 20 '14 at 13:37









        aceq aceqaceq aceq

        20723




        20723



























            draft saved

            draft discarded
















































            Thanks for contributing an answer to Server Fault!


            • Please be sure to answer the question. Provide details and share your research!

            But avoid


            • Asking for help, clarification, or responding to other answers.

            • Making statements based on opinion; back them up with references or personal experience.

            To learn more, see our tips on writing great answers.




            draft saved


            draft discarded














            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f405952%2fallowing-domain-users-to-run-winrm-commands%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown





















































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown

































            Required, but never shown














            Required, but never shown












            Required, but never shown







            Required, but never shown







            R dOydLsKkUZvj2NILdEJApUu9jN64CjFzQ,yQ,JBJosbu3IlHgSr,M,AkdtIpnKc4pA,OVS
            uD,VzSzHJilTgwBT7A2 J1l pwtWjP2JUwNdv

            Popular posts from this blog

            RemoteApp sporadic failureWindows 2008 RemoteAPP client disconnects within a matter of minutesWhat is the minimum version of RDP supported by Server 2012 RDS?How to configure a Remoteapp server to increase stabilityMicrosoft RemoteApp Active SessionRDWeb TS connection broken for some users post RemoteApp certificate changeRemote Desktop Licensing, RemoteAPPRDS 2012 R2 some users are not able to logon after changed date and time on Connection BrokersWhat happens during Remote Desktop logon, and is there any logging?After installing RDS on WinServer 2016 I still can only connect with two users?RD Connection via RDGW to Session host is not connecting

            Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

            Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020