Wednesday, July 24, 2013

Force a script to relaunch w/ Admin perms

This used to happen all the time in our organization. A script would be provided to our service desk staff, their instructions are very clear "execute the script by right clicking on it and 'run as administrator'". And yet 6 outta 10 times, they couldn't handle that. They'd run the script by doubleclicking on it . .and then wonder why things didn't work.

There's an easy fix for this with a lovely bit of DOS code:

------------------Begin Code--------------------

Set _tempvbs=%LocalAppData%\getadmin.vbs
OPENFILES > nul

:: If error flag set, we do not have Admin.
If ERRORLEVEL 1 (GOTO :ELEVATE) ELSE (GOTO :RUNSCRIPT)
 
:ELEVATE

:: Create a temporary VBScript
   cls
   Echo Set objShell = CreateObject^("Shell.Application"^) > %_tempvbs%
   Echo objShell.ShellExecute "%~f0", "", "", "runas", 1 >> %_tempvbs%

:: Relaunch this script 'As Admin'
   cscript "%_tempvbs%" //nologo
   Exit /B


----------------Exit Code---------------------------


These dos commands when integrated into a script can be used to quickly determine if the script was launched w/ administrative credentials. If it wasn't, it will create a temporary VSB script which will be used to create a UAC prompt for credentials. Once credentials are entered in the prompt, the original script will be re-executed under the entered creds.

This means that service techs just need to doubleclick on a script file, and then enter credentials when prompted.

Very very handy. I am plagiarizing this code, as it was found on a message board, and I have lost track of where I found it. I will post the original link once I track it down. Props should be given to the originator of this concept . . very slickly done imho.

No comments:

Post a Comment