Windows – Can’t create share on remote server without admin rights on local server

remotesharewindowswindows-server-2008-r2

We have a windows terminal server used by support staff. They do not have local admin rights on the terminal server. However they do have local admin rights on various Server 2003 file servers that they connect to from the terminal server and administer. One of their common tasks is creating shares on the remote servers.

Recently we migrated from 2003 to 2008 R2 on the terminal server. Since then they have been unable to create shares remotely on the 2003 file servers using computer management. They can launch computer management and connect to the remote server, then load the list of shares, but they cannot create a share. Error says "requires elevation".

It seems as though because you would need to elevate to create a share on the local machine, the mmc is requiring you to elevate but not providing a way to do so for the remote machine.

Does anyone know a way to use MMC to manage a remote machine with full elevated admin rights on the REMOTE machine but without admin rights on the local machine which you are running the MMC console?

Best Answer

I agree with KCotreau but I can't comment yet with being a noob so had to write it here instead. The shared folders MMC is the old one that was in 2003 an should allow you to lanuch it after you have created it first. when creating it you will be prompted for admin rights but go through the settings and turn off the need for admin rights and allow users to select the servers. this should work. If it doesnt let us know and I know of an alternative but it requires a bit more work.