Registry Settings

The following settings can be configured in the registry to control the behavior of Make Me Admin. Settings should be stored in the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Sinclair Community College\Make Me Admin

To enforce settings, you should use the Group Policy templates, which are located in the installation directory. However, policy settings can be manually set in the following key:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Sinclair Community College\Make Me Admin

Setting NameDefault ValueFormatExplanation
Allowed EntitiesemptyREG_MULTI_SZList of SIDs for users or groups that are allowed to obtain administrator rights on the local machine.
Denied EntitiesemptyREG_MULTI_SZList of SIDs for users or groups that are not allowed to obtain administrator rights on the local machine. Denials take precedence over allowed entities.
Automatic Add AllowedemptyREG_MULTI_SZList of SIDs for users or groups that are automatically added to the Administrators group upon logon.
Automatic Add DeniedemptyREG_MULTI_SZList of SIDs for users or groups that are never allowed to be added automatically to the Administrators group upon logon. Denials take precedence over allowed entities.
Remote Allowed EntitiesemptyREG_MULTI_SZList of SIDs for users or groups that are allowed to obtain administrator rights from a remote computer.
Remote Denied EntitiesemptyREG_MULTI_SZList of SIDs for users or groups that are not allowed to obtain administrator rights from a remote computer. Denials take precedence over allowed entities.
syslog serversemptyREG_MULTI_SZSee the Syslog Configuration page for a detailed explanation.
Timeout OverridesemptyREG_SZ (separate value for each item in the list)Specifies different timeout values for users or groups. For example, you can allow your help desk 60 minutes while allowing everyone else 15 minutes. The highest timeout value that applies to a given user wins.
Admin Rights Timeout10REG_DWORDThe number of minutes that the user will be added to the Administrators group.
Remove Admin Rights On LogoutFalse (0)REG_DWORDSpecifies whether to remove administrator rights if a user logs off of their Windows session.
Override Removal By Outside ProcessFalse (0)REG_DWORDSpecifies whether to re-add a user to the Administrators group, if they are removed by another process, e.g., a Group Policy refresh.
Allow Remote RequestsFalse (0)REG_DWORDSpecifies whether to allow requests for administrator rights from remote computers.
End Remote Sessions Upon ExpirationTrue (1)REG_DWORDSpecifies whether remote sessions are terminated when the user’s administrator rights expire.