How do I create a service account?

How do I create a service account?

Secure Home | Search | About

Microsoft Applications Security - Microsoft's general security discussions and announcements 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
How do I create a service account? damongar 08-06-2007
Posted by =?Utf-8?B?ZGFtb25nYXI=?= on August 6, 2007, 5:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I want to create a service account that has administrator permissions on
servers but I do not want this account to be able to log in to the console of
any server, is this possible?

Thanks
Ray

Posted by =?Utf-8?B?VGltIFN0YXJpZA==?= on August 6, 2007, 6:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
No, Administrator can always login to the console. You could create a
non-admin account and elevate the permissions though to match an Admin.

"damongar" wrote:

> I want to create a service account that has administrator permissions on
> servers but I do not want this account to be able to log in to the console of
> any server, is this possible?
>
> Thanks
> Ray

Posted by =?Utf-8?B?ZGFtb25nYXI=?= on August 7, 2007, 9:02 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Right, what I want is an account that has the same permissions as an admin
but cannot login to a console. I have not been able to do this, either it has
permissions to login to the console or it cannot connect to remote computer
because the rights specified no interactive logins.

"Tim Starid" wrote:

> No, Administrator can always login to the console. You could create a
> non-admin account and elevate the permissions though to match an Admin.
>
> "damongar" wrote:
>
> > I want to create a service account that has administrator permissions on
> > servers but I do not want this account to be able to log in to the console
of
> > any server, is this possible?
> >
> > Thanks
> > Ray

Posted by Roger Abell [MVP] on August 8, 2007, 12:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options
You do know that you just expanded the spec when saying

or it cannot connect to remote computer
because the rights specified no interactive logins

What is it that you do want the account able to do?

Usually Administrators group will be granted the login rights.
You seem to want an account in that group but without some of
the login rights. In that case you either need to remove the grant
of login rights to Administrators and replace it with grant to the
accounts in Administrators that should have the right (I would
recommend defining a custom group for the purpose), or, you
leave the grant to Administrators in place but disallow the one
account by the Deny user right for local login.

But then, that only addresses your inital specification, not the
new "connect to remote computer" part.

Roger

> Right, what I want is an account that has the same permissions as an admin
> but cannot login to a console. I have not been able to do this, either it
> has
> permissions to login to the console or it cannot connect to remote
> computer
> because the rights specified no interactive logins.
>
> "Tim Starid" wrote:
>
>> No, Administrator can always login to the console. You could create a
>> non-admin account and elevate the permissions though to match an Admin.
>>
>> "damongar" wrote:
>>
>> > I want to create a service account that has administrator permissions
>> > on
>> > servers but I do not want this account to be able to log in to the
>> > console of
>> > any server, is this possible?
>> >
>> > Thanks
>> > Ray



Posted by Roger Abell [MVP] on August 7, 2007, 1:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
The account needs grant of the Log on as service user right, but not
the Log on locally user right, or if you want to be overly certain use
the Deny log on locally setting. You might also want to make sure
it does not have the Network login right.
That said, running a service with administrators group membership
is not the best of ideas.

Roger

>I want to create a service account that has administrator permissions on
> servers but I do not want this account to be able to log in to the console
> of
> any server, is this possible?
>
> Thanks
> Ray



Similar ThreadsPosted
How to create a LDAP service account user and assign permissions July 10, 2006, 11:21 am
Assign permissions to create other users to Users account November 9, 2006, 4:05 am
Service Account Certficates June 16, 2005, 4:37 pm
Service Log On Account Problem September 19, 2005, 9:41 am
Service Account modified January 20, 2009, 8:14 am
NTRights & SQL Service Account Security November 4, 2008, 10:04 am
maximum services service account can start April 27, 2006, 4:09 pm
Creating a very limited user account to run a service September 6, 2006, 11:04 am
Service Accounts & Account Lock out Policy February 15, 2007, 3:41 am
What rights on a machine does an account have when logging on as a service? March 15, 2008, 8:39 pm

The site map in XML format XML site map

Contact Us | Privacy Policy