Christopher D. Clausen wrote:
> Dan Pritts <[EMAIL PROTECTED]> wrote:
>> Is it a technical, or a policy, reason that computer administrators
>> can't change the afs client config?
>>
>> I can imagine having the facility of the afs client admins group
>> available, and ANDing that group with the administrators group to
>> determine if the user is privileged, but i don't understand the
>> current situation.
> 
> I specifically requested the current behaviour.  You may not have local 
> "Administrators" who are not also smart enough to configure the AFS 
> client, but I do.
> 
> If its a problem, setup group policy to add the local administrators 
> group to the "afs client admins" group and be done with it.
> 
> <<CDC 

Chris:

It wasn't just you.

The problem is that on Windows XP and below, users must run as
"Administrator" for a large number of applications and system
configuration options to work.  Some examples include:

 * Changing the time zone

 * Adding a printer device

 * Establishing a VPN session

 * Changing network location

and so on.

large organizations needed to provide the ability for users to do the
things they need to do to make Windows usable and yet didn't want them
messing around with the AFS Client Service configuration.

Hence, the AFS Client Admins group was born.

Jeffrey Altman
Secure Endpoints Inc.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to