RE: NetworkService Account alternative

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi Max,

For your scenario, you have the following options:

1. configure your ASP.NET application to use a custom application pool
identity( process account) which can be authenticated by the remote SQL
Server machine. You can follow the following referece about how to create a
custom account which also inclulde grant the custom acount the proper
permission:

#How To: Create a Service Account for an ASP.NET 2.0 Application
http://msdn.microsoft.com/en-us/library/ms998297.aspx


2. You can use impersonate to make your ASP.NET page request running under
an impersonate account (instead of the worker process account). Impersonate
can be done via web.config statically or in code dynamically(more
flexible). Here are some useful articles introduced how to use impersonate
in ASP.NET:

#How To: Use Impersonation and Delegation in ASP.NET 2.0
http://msdn.microsoft.com/en-us/library/ms998351.aspx

#Understanding ASP.NET Impersonation Security
http://www.west-wind.com/WebLog/posts/2153.aspx

Sincerely,

Steven Cheng

Microsoft MSDN Online Support Lead


Delighting our customers is our #1 priority. We welcome your comments and
suggestions about how we can improve the support we provide to you. Please
feel free to let my manager know what you think of the level of service
provided. You can send feedback directly to my manager at:
msdnmg@xxxxxxxxxxxxxx

==================================================
Get notification to my posts through email? Please refer to
http://msdn.microsoft.com/subscriptions/managednewsgroups/default.aspx#notif
ications.

Note: The MSDN Managed Newsgroup support offering is for non-urgent issues
where an initial response from the community or a Microsoft Support
Engineer within 1 business day is acceptable. Please note that each follow
up response may take approximately 2 business days as the support
professional working with you may need further investigation to reach the
most efficient resolution. The offering is not appropriate for situations
that require urgent, real-time or phone-based interactions or complex
project analysis and dump analysis issues. Issues of this nature are best
handled working with a dedicated Microsoft Support Engineer by contacting
Microsoft Customer Support Services (CSS) at
http://msdn.microsoft.com/subscriptions/support/default.aspx.
==================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
From: "Max2006" <alanalan1@xxxxxxxxxxxxxxxx>
Subject: NetworkService Account alternative
Date: Tue, 24 Jun 2008 17:33:43 -0400


Hi,

I want my ASP.NET application connects to a SQL Server through windows
authentication.

To do this, I assume that my application pool should be under a windows
identity instead of NetworkService. (right?)

Since the ASP.NET's application pool user identity should be as restricted
and secured as NetworkService, is there any guideline how to limit and
secure the new user?

Thank you,
Max




.



Relevant Pages

  • RE: Impersonate
    ... saving a Excel document in ASP.NET webapplication, ... Regarding on the problem you mentioned, I think the account is the first ... You should either impersonate through the web.config setting or use code. ... Microsoft MSDN Online Support Lead ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Product ID For Online Support
    ... >Not sure about support for the Home Use program since it ... >account will be deleted without reading. ... As I mentioned in my thread, OE and Outlook ...
    (microsoft.public.office.misc)
  • Re: help
    ... Windows Live ID Support ... MSN Premium Account support ... I've been locked out of my msn email account ... And have you contacted MSN or Hotmail Support about this? ...
    (microsoft.public.internet.mail)
  • I am separately loud, so I decline you.
    ... Neil, have a far account. ... charge revolutionary bottles in support of the fond literary ... extreme conferences. ... Roxanne debates the egg as to hers and rigidly ...
    (sci.crypt)
  • Re: Sql Reporting Serviced - > ASP.NET ACCESS DENIED!
    ... The account you are logging in to when on the server doesn't have the ... do you have <Impersonate> set to True? ... > Exception Details: System.UnauthorizedAccessException: Access to the path ...
    (microsoft.public.dotnet.framework.aspnet.security)