Microsoft KB Archive/883273

= A user can schedule a task to run in the security context of a user account that has more user rights =

Article ID: 883273

Article Last Modified on 2/7/2007

-

APPLIES TO


 * Microsoft Windows Server 2003, Standard Edition (32-bit x86)
 * Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)

-





INTRODUCTION
When you use the Scheduled Task Wizard to create a scheduled task on a Microsoft Windows Server 2003-based computer, you must be a member of the Administrators group, the Backup Operators group, or the Server Operators group on the local computer. Additionally, you must type the user name and the password of a user account to schedule the task. When the scheduled task starts, it runs as if it were started by this user. Therefore, the scheduled task runs in the security context of this user account. If you type the user name and the password of a user account that belongs to a group that has more user rights than the group where you are a member, the task will not run as you expect, because the user name and the password are not configured for the task. However, a user may be able to use the schtasks command to schedule a task to run in the security context of a user account that has more user rights, including administrative rights.



MORE INFORMATION
A member of the Administrators group can use the Cacls.exe utility to modify the discretionary access control List (DACL) of the Tasks folder and grant a member of any group permission to create or to modify scheduled tasks. If a member of the Administrators group uses the Cacls.exe utility to modify the DACL of the Tasks folder, a user may be able to use the schtasks command to create a scheduled task to run in the security context of a user account that has more user rights, including administrative rights. However, if the user creates a second scheduled task to run under the same user account that has more rights, the user receives a message that is similar to the following, where  is the name of the task:

WARNING: The scheduled task  has been created, but may not run because the account information could not be set.

The scheduled task is created, but the user name and password account information are not configured for the task.

For more information about how to use the Cacls.exe utility to modify a DACL, visit the following Microsoft Web site:

http://technet2.microsoft.com/WindowsServer/f/?en/library/3be8b68f-f83c-409b-8b97-f026f75e17ca1033.mspx

Keywords: kbinfo kbprb kbtshoot KB883273

-

[mailto:TECHNET@MICROSOFT.COM Send feedback to Microsoft]

© Microsoft Corporation. All rights reserved.