Re: Computer accounts in NTFS permissions

From: Miroslaw Slawek Chorazy (mchorazy_at_depaul.edu)
Date: 02/23/05

  • Next message: Matthew S Barnes: "Re: Domain Controller Best Practice"
    Date: Wed, 23 Feb 2005 16:23:43 -0600
    To: <dschmidt@buddyrents.com>, <bkmlstsgohere@comcast.net>
    
    

    Marshall
    >The computer account -- not System or some other account on the
    computer --
    >isn't ever going to be accessing files (at least not in any examples I
    can
    >think of).

    In an AD environment, the computer account will indeed be used during
    the startup process and will need appropriate permissions and rights
    associated with it to read AD Objects like GPOs and scripts.
    In some environments, the AD DNS dynamic name registration is also
    performed using the SID associated with the Computer.

    slawek

    >>> "Bruce K. Marshall" <bkmlstsgohere@comcast.net> 2/23/2005 14:23
    >>>
    Daniel,

    The computer account -- not System or some other account on the
    computer --
    isn't ever going to be accessing files (at least not in any examples I
    can
    think of). And permissions won't be enforced just because a user or
    service
    account happens to be operating from that computer. So, setting using
    a
    computer security principal in NTFS ACLs won't have any effect.

    If a service on the computer is trying to access the file then you
    should be
    able to set up NTFS ACLs using the appropriate account (System, Local
    Service, Network Service, etc.).

    ----
    Bruce K. Marshall - bmarshall@securityps.com 
    Security PS - Kansas City
    ----- Original Message ----- 
    From: "Daniel Schmidt" <dschmidt@buddyrents.com>
    To: <focus-ms@securityfocus.com>
    Sent: Wednesday, February 23, 2005 9:32 AM
    Subject: Computer accounts in NTFS permissions
    > It is my understanding that computer accounts can be used as
    security
    > principals, but using them in a NTFS ACL seems to have no effect. 
    Does
    > computer account authentication only authorize accesses from the
    SYSTEM
    > account?  Can anyone point me toward some useful reading on the
    subject?
    >
    > Daniel Schmidt 
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Matthew S Barnes: "Re: Domain Controller Best Practice"

    Relevant Pages

    • Re: what is reset account?
      ... Such doesn't require perfect security, ... the GPO team's updates to the production domain and the ACL got wiped in ... can force the client to do a password change. ... computer account, along with repairing all other DNS problems etc, ...
      (microsoft.public.win2000.active_directory)
    • Re: what is reset account?
      ... adding the computer to the group and what accessit grants. ... Such doesn't require perfect security, ... can force the client to do a password change. ... computer account, along with repairing all other DNS problems etc, ...
      (microsoft.public.win2000.active_directory)
    • Re: having problems creating packages - access denied..
      ... Check out the SMS Technical FAQ: ... full share permission and also full local security permission. ... Make sure you have specified a valid package source directory on ... >> The site server computer account needs access to the source. ...
      (microsoft.public.sms.admin)
    • RE: Remote Installation Services, DoOldStyleDomainJoin=Yes
      ... > This security setting determines which groups or users can add workstations ... > provide domain account credentials to join the computer account to the ...
      (microsoft.public.windows.group_policy)
    • Re: Service running as Local system account Unable to map drive on ano
      ... If kerberos auth is being used, you simply grant rights for the computer account from AD on the share and the file system. ... The security concern is that ANYTHING running as localsystem on the specific computer will have access to the share. ... For anonymous access you enable the null session share and set the ACL on the file system to everyone read or write depending on the access you want. ...
      (microsoft.public.security)

  • Quantcast