Relinquish rights on Windows

Viewed 220

I have a C++ application that runs as administrator (it is compiled with a manifest with requestedExecutionLevel set to requireAdministrator.

At some point, once all the tasks requiring administration rights are done, I would like to relinquish those rights and perform the remaining tasks as the user that launched the application.

Windows provides the ImpersonateLoggedOnUser function, but I can't find any way to obtain a token for the user that called the application.

Are there any other ways to do what I have described here?

2 Answers

Perhaps a better approach would be to request highestAvailable instead of requireAdministrator in your manifest. Then, if you find that you are running elevated, just do everything you need to do. If you find that you are not running elevated:

  1. Launch your program again, using ShellExecute with the runAs verb to run it elevated.
  2. Have your unelevated process wait for the elevated process to do whatever it needs to do. (How to know when the elevated process is done is left as an exercise for the implementer. You also need to worry about what happens if the user does not allow your elevated process to start.)
  3. Once the elevated process completes, do the rest of your unelevated work.

If you want to continue with your original plan, this Raymond Chen blog post explains how to start an unelevated process from an elevated process. (The fact that your manifest requests requireAdministrator may complicate this process.)

Related