It does not matter if running regedit is disabled or not. Regular user cannot write to HKLM on Windows XP unless the permissions are changed.

There are some topics around on this board about runas (one N) and runnas (two N's). Runas is not secure because the username and password is in plain text in your script. Anyone can read this and therefore (ab)use the credentials. Runnas is a tokenized runas app that is much more secure then the first one.

Also you could warp the script in an executable. For example ASE can do that but there is also a free app on this board called kix2exe.

If there is no other way whatsoever I'd go for runnas (with the two N's).

The best (imho) and most secure way however would be to fix the AD and use GPO.
_________________________
Mart

- Chuck Norris once sold ebay to ebay on ebay.