RE: At.exe Service Account - scripted or registry?

From: ATarasul@SpencerStuart.com
Date: 01/28/03

  • Next message: Raoul Armfield: "RE: Win2k log management"
    Date: Tue, 28 Jan 2003 10:47:52 -0600
    From: <ATarasul@SpencerStuart.com>
    To: <focus-ms@securityfocus.com>
    
    

    Additional information on the topic:

    Using RegMon it look like the values are stored into
    HKLM\SECURITY\Policy\Secrets\SANSC\(Default).

    -----Original Message-----
    From: Tarasul, Alexander
    Sent: Friday, January 24, 2003 12:36 PM
    To: focus-ms@securityfocus.com
    Subject: At.exe Service Account - scripted or registry?

    There is a trick to set "AT Service Account" to existing account , but
    wrong dummy password - front end validation validate only account name.
    In this case jobs scheduled with "at" - assuming attacker managed to run
    at - will not be able to execute. Any idea how to do this in script or
    by writing to registry to distribute through template/policy?

    Thanks
    Alexander

    Microsoft How-to is:
    Open Control Panel and double-click Scheduled Tasks.
    In the Scheduled Tasks window, open the Advanced menu and then choose AT
    Service Account.
    Click This Account and specify a particular user and password. Click OK.



    Relevant Pages

    • Re: error 0x80041003 reading registry across network
      ... >Wouter wrote: ... >> I'm using the script from the MS TechNet Script Center ... >> some reason on some servers I recieve error 0x80041003. ... >> The service account is setup in a W2K Active Directory, ...
      (microsoft.public.scripting.vbscript)
    • Task Scheduler inconsistency
      ... Currently I have a script which schedules nine tasks using the schtasks ... Log onto workstation with the service account. ... Launch script. ...
      (microsoft.public.windowsxp.general)
    • RE: Using ADMT to migrate service accounts on workstations
      ... > Oh, yes, I agree with you that the script would better in your scenario. ... >>The problem is that service account migration wizard would need every ... >>workstation to be switched on and available, ...
      (microsoft.public.windows.server.migration)
    • Re: GPO Logon Script that requires AD rights
      ... If that script is being run by user "A" under the credentials of user "B" using either the built-in runas command, a third-party runas utility such as the suggested "Steel Run-As", then objNetwork.UserName will return the name of user "B". ... If user "B" is the service account that will always be used, this defeats the purpose of the exercise, which is to move the computer to the interactive user's OU. ... If you could populate an AD attribute on the computer object with the department, which corresponds to the correct OU, that would seem like a better solution. ...
      (microsoft.public.scripting.vbscript)
    • Re: GPO Logon Script that requires AD rights
      ... The Steel Run-As suggestion seemed like a good idea so I tried that, ... In a script, the following retrieves the user name: ... Or I could go about making a service account for each ... If you could populate an AD attribute on the computer object with the ...
      (microsoft.public.scripting.vbscript)

    Loading