Setting Administrative Rights for a Partition
Users assigned the Administrator role of the COM+ System Application are allowed to create, modify, and delete COM+ partitions. Within the Component Services administrative tool, administrative roles can be assigned to users by expanding the Roles folder of the COM+ System Application.
As of Windows Server 2003, the authentication capability for the COM+ System Application includes the value EOAC_DISABLE_AAA. This value, which disables activate-as-activator (AAA) activations, is used in the CoInitializeSecurity call when launching the System Application. Setting the authentication capability to EOAC_DISABLE_AAA allows an application that runs under a privileged account (such as LocalSystem) to help prevent its identity from being used to launch untrusted components.
Related topics