Re: Services account issue

Tech-Archive recommends: Fix windows errors by optimizing your registry



You really shouldn't give a service domain admin rights. It is almost certainly far more rights than it actually needs. Look into delegation.

Outside of that, you cannot completely block an ID from being used in any way but to start a service, there are multiple ways IDs can be used outside of interactive auth such as NET USE /USER and through RUNAS or some other tools that allow using alternate creds.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


BT wrote:
Thanks

How about if it is a domain user account with domain admin right? I've to do it in domain secuirty policy or domain controller security policy?

Please advice.
BT


"Jerold Schulman" <Jerry@xxxxxxxxxx> wrote in message news:er9es21mlukv1oh8p5gg49ena0unihj7up@xxxxxxxxxx
On Mon, 5 Feb 2007 19:04:20 +0800, "BT" <barrytsiu@xxxxxxxxxxx> wrote:

Hi all

Is it possible to create a services account so that it will use to startup
the services only, but cannot logon to workstation?

Please advice.
Thanks
BT

Yes. Simply grant the account Logon as a Service and Deny logon locally using
Computer Configuration / Windows Settings / Security Settings / Local Policies / User Rights Assignment.

Jerold Schulman
Windows Server MVP
JSI, Inc.
http://www.jsiinc.com

.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... I am using WSS 3.0 and I have 3 WSS web ... are running under the domain user account of "Domain\Sharepoint_AppID" ... I then delegated the rights for the same ... when you had that account set as a domain admin for the domain, ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Reboot command no longer works in Task Scheduler
    ... What kind of account do you use for the task, ... Did you grant the user rights assignment "Logon as a batch job" and "Backup files and directories"? ... "Meinolf Weber" wrote: ...
    (microsoft.public.win2000.general)
  • Re: Authenticating a user on Windows Server 2003
    ... > missing privileges (by privileges I mean rights on the acct i.e. does the ... > client user acct have interactive logon privileges and other necessary ... > Are you able to execute "runas" successfully as the user account (with the ...
    (microsoft.public.platformsdk.security)
  • Re: IIS 5 Authentication problem- solved
    ... In Local Security Policies/User Rights Assignment I had ... Can you log in using an administrator account, ... >> case there is no group, it is just the one server, ... >> interactive logon or using basic authentication. ...
    (microsoft.public.inetserver.iis.security)
  • Re: running .bat files
    ... Yes on Batch job and service. ... I do not see the rights to start and stop ... Has the account the rights "Logon as a bacth job" and "Logon a s a ... I set the user account that it runs as as Administrator, ...
    (microsoft.public.windows.server.security)