Start OneDrive Under Full Admin Rights

Viewed 392

Summary

I necessarily run Excel with Admin privileges and I have UAC set to Never Notify. Excel VBA opens Word. Word has a macro button that restarts OneDrive. The error message is that "OneDrive can't be run using full admin rights." How can I restart OneDrive without the error massage? enter image description here

Note: There is a sister post at How to Restart OneDrive via VBA When Running Excel Elevated, but that post poses an entirely different question.

Workflow

Excel VBA opens Word:

Sub m_Test_Finish_WordDoc()
Const strpath = "C:\Users\ssttr\OneDrive\Documents\Investing\Automation\Static Inputs\Restart_OneDrive.docm"

Dim Wd As Object
Dim InstrDoc As Object
Dim f As Boolean

On Error Resume Next

Set InstrDoc = GetObject(strpath)
    
With InstrDoc.Parent
    .Visible = True
    .Activate
End With

End Sub

Word macro restarts OneDrive:

Private Sub CommandButton1_Click()
   Application.Run "Restart_OneDrive"
End Sub
Sub Restart_OneDrive()
'Restarts OneDrive
    Dim shell
    Set shell = CreateObject("wscript.shell")
    shell.Run """C:\Users\ssttr\OneDrive\Documents\Investing\Automation\Static Inputs\OneDrive Restart - Copy.bat""" 'bat.zzz
End Sub

Contents of OneDrive Restart - Copy.bat

REM Restarts OneDrive from the command line.
REM From https://stackoverflow.com/questions/29872973/syncing-onedrive-skydrive-with-batch-file-via-cmd.
REM If the /background switch is omitted then Explorer is opened to the OneDrive folder in your user profile but OneDrive does not start.
REM If restarting OneDrive from a batch file then add the START command or the batch file won't end.

            REM start %LOCALAPPDATA%\Microsoft\OneDrive\OneDrive.exe /background <--  the original '~error-producing' command

            RunWithRestrictedRights %LOCALAPPDATA%\Microsoft\OneDrive\OneDrive.exe -w -v

One Possible Path to a Solution

I downloaded the RunWithRestrictedRights.exe standalone executable from https://www.coretechnologies.com/products/RunWithRestrictedRights/ into the C:\Windows\System32 directory and the implementation (shown above) in VBA was replacing the

start %LOCALAPPDATA%\Microsoft\OneDrive\OneDrive.exe /background

line in my batch file (which BTW is from Syncing OneDrive (SkyDrive) with Batch File (via cmd)) with

RunWithRestrictedRights %LOCALAPPDATA%\Microsoft\OneDrive\OneDrive.exe.

Note that, as required at the very bottom of https://www.coretechnologies.com/products/RunWithRestrictedRights/, I added the Administrator to the security policy settings for "Replace a process level token" and for "Adjust memory quotas." See below Notes > SecPol.msc §.

The hang-up is when that the batch file, when called in the above process (Important: remember Excel is Run As Admin), runs (i.e. cmd window flashes) but it does not open OneDrive.

Is my problem, as I suspect, in my batch file, or somewhere else? If somewhere else, then you may wish to see my sister post (it is the same underlying issue but pursing a very different question) at How to Restart OneDrive via VBA When Running Excel Elevated.

Notes:

Things that didn't work for me:

There was some stuff about UAC being required relative to an elevated launch of OneDrive, but that's a non-starter for me because if a user needs to attend to a UAC prompt, then my code's purpose of full automation is negated. Also, for my purposes, I have UAC set to Never Notify.

From https://superuser.com/questions/171917/force-a-program-to-run-without-administrator-privileges-or-uac/450503#450503 -- The MS RunAsInvoker Application Compatibility Toolkit shim does not apply bc I have UAC turned off by default.

FWIW, I did try setting UAC to Always Notify but it did not remove the error. I also tried RunAs /trustlevel:0x20000 %LOCALAPPDATA%\Microsoft\OneDrive\OneDrive.exe, and it did not seem to work, which is because per https://www.coretechnologies.com/products/RunWithRestrictedRights/ I have UAC disabled.

Origins of the solution I am pursuing:

From https://www.coretechnologies.com/blog/alwaysup/onedrive-hates-admin-rights/ -- "UAC enables an administrator to run OneDrive normally" section -- this is a really informative and provided the final solution

SecPol.msc

From https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/replace-a-process-level-token -- "This policy setting determines which parent processes can replace the access token (editor's note - describes the security context of a process or thread) that is associated with a child process." That's the lynch pin setting.

I set that per https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/user-rights-assignment and https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/how-to-configure-security-policy-settings.

I also had to set Adjust memory quotas for a process per https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/adjust-memory-quotas-for-a-process and https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/how-to-configure-security-policy-settings.

Per https://docs.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/how-to-configure-security-policy-settings, "any change to the user rights assignment for an account becomes effective the next time the owner of the account logs on." so I restarted (after I tested and confirmed it did not work without a restart).

enter image description here

Update 2022-01-07-18.7

I've moved from a *.bat because I was passing multiple commands, to attempting to directly implement the command by way of:

Sub Restart_OneDrive()
     Dim RWRR As Variant
     RWRR = shell("RunWithRestrictedRights.exe ""C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe"" -w -p -v", vbNormalFocus)
End Sub

but I get Run-time error '53': File not found.

{downlaods runtm53.png}

The error still occurs if I change to

RWRR = shell("C:/Windows/System32/RunWithRestrictedRights.exe ""C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe"" -w -p -v", vbNormalFocus)

or to

Call shell("RunWithRestrictedRights ""C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe""", vbNormalFocus)

I have the required security policy set per https://www.coretechnologies.com/products/RunWithRestrictedRights/ :

{downlaods rwrr_secpol.png}

which states:

Does RunWithRestrictedRights.exe work on Windows XP and Windows Server 2003, where there is no UAC?

Yes, it works well on Windows XP and Windows Server 2003. The Windows Integrity Level can't be set (that feature is only available in Windows Vista and later) but the application is run without admin rights as intended.

One note though: If you receive an error stating that "a required privilege is not held by the client", please ensure that your account has these two rights: Adjust memory quotas for a process; Replace a process level token.

If I run directly from a non-elevated command line

RunWithRestrictedRights.exe "C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" -w -p -v

or

C:/Windows/System32/RunWithRestrictedRights.exe "C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe"```` or ````RunWithRestrictedRights "C:\Users\ssttr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" -w -p -v

it works, resulting in:

{rwrrok.png}

I have tried all these syntax commands inside the shell, with what I think are the appropriate syntax changes, e.g. as shown the above VBA above, but still get the run time error 53.

FWIW here's the help for RunWithRestrictedRights.exe:

{rwrr help.png}

which says:

RunWithRestrictedRights

Synopsis: Runs a given application in a "restricted" mode - at Medium (or Low) Integrity and without rights granted by being a member of the Administrators group.

Usage: RunWithRestrictedRights.exe [-w] [-l] [-p] [-v] [-d ]

Options: The full path to the application to be started. Please be sure to enclose the path in quotes if it contains at least one space. -w Instead of returning immediately after launching the application, wait until the application ends. Optional. -l Instead of running the application with Medium Integrity, start it with Low Integrity. Optional. -p Also strip away rights granted from being a member of the "Power Users" group. Optional. -d Also deny rights to the given SID. -v Produce verbose output. Optional.

Exit code: The non-zero process identifier (PID) if the application was successfully started. -1 if there was an error starting the application.

Version: 3.0.1.16 (Feb 18 2020)

Example: > RunWithRestrictedRights.exe "C:\MyApp\MyApp.exe" - Starts MyApp.exe with retricted rights.

This free utility is Copyright 2020, Core Technologies Consulting, LLC. Find out about this and our other products at our web site: https://www.CoreTechnologies.com/

0 Answers
Related