Changing IP address without handing out local admin or elevated CMD
Posted by Crackmin@reddit | sysadmin | View on Reddit | 38 comments
I am so lost on this one, I've been staring at it for 5 hours banging my head
So! We've recently implemented Admin by Request and started removing everyone's local admin. One issue, 60+ of our users need to change IP addresses regularly to interface with strange obscure devices, and Admin by Request works amazing for everything else, but doesn't pick up system dialog elevation requests properly. We need an automated solution to approving this or we'll be getting hundreds of requests per day
Testing done:
Creating an executable that runs ncpa.cpl through Admin by Request - still requires a second UAC prompt to change adapter settings, so can't be automated
Using the Network Configuration Operators group - This also grants the ability to run CMD as admin, which we REALLY do not want people to do, we'd prefer if script-based attacks had to earn local admin the hard way
Definitely not disabling UAC
Had a look at using Simple IP Config, a free software - was told not to implement an additional software unless strictly necessary, so that's a last ditch option
Has anyone done anything like this before and has advice?
Thank you so much for your help
38 Comments
Sabbest@reddit
Crackmin@reddit (OP)
Ferisii@reddit
disposeable1200@reddit
Crackmin@reddit (OP)
elpollodiablox@reddit
ithium@reddit
Crackmin@reddit (OP)
redthrull@reddit
Visible_Witness_884@reddit
Chairface30@reddit
Visible_Witness_884@reddit
Chairface30@reddit
elcheapodeluxe@reddit
Crackmin@reddit (OP)
BubblySpaceMan@reddit
Crackmin@reddit (OP)
AccomplishedPlay7@reddit
Stonewalled9999@reddit
Visible_Witness_884@reddit
DonnellyJohn@reddit
fp4@reddit
Background-Look-63@reddit
FuriousRageSE@reddit
Imposing-Force@reddit
ithium@reddit
FuriousRageSE@reddit
PAiN_Magnet@reddit
SevaraB@reddit
w3warren@reddit
thegarr@reddit
Lower_Fan@reddit
Bulky_Ad_7777@reddit
barnzy12@reddit
Bulky_Ad_7777@reddit
Stryker1-1@reddit
blnk-182@reddit
aringa@reddit