Setting Machine-Wide Access Permissions

Dcomcnfg.exe allows you to set access permissions to control the list of users who are granted or denied access to the methods of those servers that do not provide their own access permissions. You can add users or groups to the list, specifying whether access permission is being granted or denied. You can also remove users from the list.

When setting access permissions, you must ensure that SYSTEM is included in the list of users that are granted access. If you have granted access permissions to Everyone, SYSTEM is included implicitly.

The process of setting access permissions for a machine is similar to setting launch permissions. The following steps should be taken.

    To set access permissions for a machine:
  1. On the Default Security property page in Dcomcnfg.exe, choose the Edit Default button in the Default Access Permissions area.
  2. To remove users or groups, select the user or group you want to remove and choose the Remove button. The selected user or group will no longer appear in the list box. When you have finished removing user and groups, choose OK.
  3. If you want to add a user or a group, choose the Add button.
  4. If you know the fully qualified user name you want to add, type it in the Add Names text box.

    If you do not know the user name, you can browse the user database to find it. When you have located the user name, select the user or group from the Names list box and choose the Add button.

  5. From the Type of Access list box, select the access type (either Allow Access or Deny Access). To add other users that will have the selected type of access, repeat step 4. When you have finished adding users for the selected access type, choose the OK button.
  6. To add users that will have a different type of access, repeat steps 4 and 5. Otherwise, choose OK to apply the changes.