Basically, i have a need where I need to have a user actually run a 3rd party program on server sbs 2003 directly but we do not want to give that person any access to server controls, server apps etc… just the 1 application they need to run. Is there any way to do that and what permissions/policies do I have to address.
My concern is that because the program they are running may write to temp folders or need to modify its own registry settings as part of its operation, that the levels of permissions/policy cannot be controlled enough to remove access to the other areas.
I hope that makes sense but I have not been able to find any similar scenarios here or through a general google search.
Hope somebody can help .. (btw, the owner is insisting on tryign to get this to work, i think it is absolutely the wrong thing to allow so I don’t need to be reminded its a stupid thing to do.).