Setting Machine-Wide Access Permissions

Machine-wide access permissions specify users who are granted or denied access to COM applications that do not provide their own access permissions. For overview information, see Access Permissions.

To set machine-wide access permissions

  1. In the console tree of the Component Services administrative tool, right-click the computer whose machine-wide access permissions you want to modify and then click Properties.

  2. Select the Default COM Security tab.

  3. Under Access Permissions, click the Edit Default button.

  4. To remove a user account or group, select the group or user in the Group or user names list and then click Remove. The selected user account or group no longer appears in the list.

  5. To add a user account or group, click Add. Then, in the Select Users, Computers, or Groups window, in the bottom pane, type the fully qualified name of the user or group you want to add. If you do not know the name, click the Advanced button and then click Find Now to view a list of users and groups in the selected domain. Select a user or group from the Name (RDN) list, and click OK. The added user account or group appears in the Group or user names list.

  6. In the Group or user names list, select the group or user whose default access permission you want to change.

  7. In the Permissions list, select whether to Allow or Deny access permission for the selected group or user name.

  8. Click OK to return to the Default COM Security page.

  9. Click OK.

The new machine-wide access permissions are available the next time an application on the computer is started. Applications that are currently running are not affected until they are restarted.