Tag Archives: application

Launch apps as Admin without prompt

This is a tip intended to ease the pain of continuously having to click the ‘Yes’ prompt when you want to launch an app in ‘Admin mode’.

The trick is to use the built-in Windows Task scheduler.

1. First you create a new task (not a basic task) and specify a name e.g. ‘CommandLine’ plus check the ‘Run with highest privileges’ check box.

2. On the actions tab you add a ‘Start a program’ action and select the executable e.g.’C:\Windows\System32\cmd.exe‘

3. Optionally under the Settings tab you can choose ‘Run a new instance in parallel’so you can run multiple instances of the app if required.

4. Click OK to create the task

Next you create a Windows shortcut (say on the desktop by right clicking and choosing new -> Shortcut)

1. Specify the following as the ‘Target’: e.g.  ‘C:\Windows\System32\schtasks.exe /run /tn CommandLine‘
Pay attention that the last parameter must match the task name.

2. You may want to manually select an icon for the shortcut as it won’t select the app icon by itself.

Now if you click (double-click) the shortcut a brief command line window before opening your app (in admin mode) – without prompting you! One big disadvantage is that you cannot pass command line parameters this way so launching say notepad with a specified txt file this way won’t work.

Of course, it would have been easier if MS built in a way you can choose (at your own risk) which apps you would like to launch in admin mode without prompting. There is a potential security risk in allowing functionality like that but if they wanted to it could be done with a big warning dialog at the start – that tells you you’re doing this at your own risk. It could use something like signing the required exe with a local (only) certificate to mark it trusted only on the local machine or generating a hash that gets stored in an encrypted system location or something, to tell the OS that particular exe can be trusted (when launched). The way to set up this hash and stuff would need to be a secure process in itself (requiring a ‘human’ user input) and letting you jump through a couple of hoops – once off. The idea is to allow only that particular exe on the particular machine as trusted. Copying it to another machine or changing it would require setting up the ‘trust’ again. Just an idea… (throwing a hint… to Microsoft)

QuickMon 2

A quick follow-up on my QuickMon application. I’ve now managed to get a basic working application that performs some simple monitoring of 4 different types of agents (ping, file count, services and BizTalk suspended instance count). Also it includes the first notifier agent that simply logs to a plain text file.

The full architecture is a bit complicated to explain in a simple post so I’ll have to start working on a much more detail blog posting to explain it all.

Other than the documentation the next steps are to test its stability, improve error handling and adding the other basic agents I planned to make it useful.