29 March,18 at 02:09 PM
How can a user be granted rights to upgrade third party applications without assigning them an elevated desktop on Windows?
Answer:
In order to grant the necessary permissions for end users to upgrade third party applications like Visual Studio or Adobe Flash Player an elevated desktop role assignment is not necessary.
Below are the steps necessary to accomplish the role assignment. The example below uses Adobe Flash Player, however this works for any file that is needed.
1) Create a new Windows Application Right Definition in Access Manager
2) Navigate to 'Match Criteria' and Add... a new criteria
a. Specify a description of the file 'Adobe Flash Player'3) Go to 'Run As' and specify the local administrator or Domain group that will be used to run with privilege.
4) Create a new Role Definition and assign this newly created application right.
5) Create a new role assignment to include this new Role Definition
6) Assign the role assignment to an AD user or AD group.
Before testing, make sure to refresh the cache on the Centrify Agent or allow for enough time for these changes to take effect on the Windows machines.
Note: To import the file so it auto populates the File Detail section as seen above, click "Import File" and navigate to a copy of this file on the machine then click 'Open'.