Re: Local System account and network resource access
- From: "Pegasus \(MVP\)" <I.can@xxxxxxx>
- Date: Sun, 19 Aug 2007 10:49:17 +0200
If a domain account has access to a shared resource then
this domain account can be used either for console sessions
or for scheduled tasks. Test the account in the foreground
first, then use it under the Task Scheduler.
Note that accounts used by the Task Scheduler ***must***
have a non-blank password.
"ykffc" <ykffc@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5560A8D3-83FD-4ECD-8508-DC2C5228B4CF@xxxxxxxxxxxxxxxx
No, we don't have any problem to do what we try to do via a scheduled task
if
it is run under a normal user acccount.
Then someone suggests we should be able to do the same without a (Domain)
user account and he said he had seen some tasks running that access shared
resources without problem. I tried very hard for many hours but still
receiving the "access denied" message. That is why I ask here.
If there no ways we can specify a share that allows the scheduled task to
access network resource, our discussion (within IT team in our Company) is
over.
"Pegasus (MVP)" wrote:
As I said, the System account has no access to shared resources.
If it had access then this would open a nice can of works, e.g.
issues with passwords and issues with accessing shares on
other computers for which you have no access privileges.
If you explain what you're actually trying to do then someone
may offer a solution that does not involve the System account.
"ykffc" <ykffc@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:BAA7BC71-B14E-46BD-B419-20756439A43E@xxxxxxxxxxxxxxxx
<quote> The local System account cannot access any networked resources.
This is by design. </quote>
Is there are exceptions? When we define a share in machine1, I thought
we
can if delete all users in the permission list but add a machine name
(domanName\machine2$) in the permission list, that would mean I allow
this
share to be accessable by ANY users ( including a local system user )
as
long
as the user sits on machine2.
"Pegasus (MVP)" wrote:
"ykffc" <ykffc@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F79F2FCE-8AB4-4AEC-BC41-0E534BDAE37B@xxxxxxxxxxxxxxxx
Does anyone know whether the system account NT AUTHORITY/SYSTEM is
able
to
access network resource like ordinary authenticated user?
According to my research it appears it should be able. I have tried
it
but
it always give me an "Access denied" error message. I simply try to
do
a
"dir
\\xxx.xx.xx.xx\shareName" command.
Everything works for me with what was described in the following
link
(except I can't access network resource).
http://security.fnal.gov/cookbook/LocalSystem.html
No. The local System account cannot access any networked resources.
This is by design.
.
- Follow-Ups:
- References:
- Re: Local System account and network resource access
- From: Pegasus \(MVP\)
- Re: Local System account and network resource access
- From: Pegasus \(MVP\)
- Re: Local System account and network resource access
- From: ykffc
- Re: Local System account and network resource access
- Prev by Date: Re: Local System account and network resource access
- Next by Date: Re: Local System account and network resource access
- Previous by thread: Re: Local System account and network resource access
- Next by thread: Re: Local System account and network resource access
- Index(es):
Relevant Pages
|
Loading