Re: Threat vector of running a service using a domain account



Sure, what I normally do is place my denies at the domain level.... so I would edit the group policy that is linked to my domain. That way the service account is denied those user rights for my whole domain.

to find the deny settings expand computer configuration, windows setting, security settings, local policy, user right assignments, scan down the list and you will see

Deny access to this computer from the network
Deny logon as a batch job
Deney logon locally
Deny logon through Terminal Services

normally I deny access to this computer from the network, deny logon on locally and deny logon through terminal services.


Take Care and Have Fun --John

PS if you doing alot of work with gpo's you should check out http://www.gpoguy.com/

-------------- Original message ----------------------
From: "Ali, Saqib" <docbook.xml@xxxxxxxxx>
Hello,

On 9/12/07, jfvanmeter@xxxxxxxxxxx <jfvanmeter@xxxxxxxxxxx> wrote:
Hello, service accounts are a great way to use less privelgee, so yes I think
the resk is managable. I would also add deny log on terminal services, and if
its not running as a batch job I would also deny that user right. I would also
make the password random and at least 24 charactors.

Can you please explain how I can deny TS logon and batch job.

Thanks
saqib
http://security-basics.blogspot.com/



Relevant Pages

  • Re: Deny logon locally
    ... the 'deny logon' via group policy and it works for me. ... Run 'gpresult /z' or use RSOP to verify that the policy ... >> Harald Haitsma says... ...
    (microsoft.public.windows.server.active_directory)
  • The Local Policy of This System Does Not Permit You to Log on Interactively
    ... Deny access to this computer from the network ... Deny logon as a service ... The Local Policy of This System Does Not Permit You to Log ...
    (microsoft.public.windows.server.sbs)
  • The Local Policy of This System Does Not Permit You to Log on Interactively.
    ... Deny access to this computer from the network ... Deny logon as a service ... The Local Policy of This System Does Not Permit You to Log ...
    (microsoft.public.win2000.advanced_server)
  • Re: Deny Logon through Terminal Services Issue
    ... If I recall correctly the user rights to log on via TS or to deny the same ... Windows 2003 SP1 Server Environment ... I set the "Deny log on through Terminal Services" from 'Not Defined' ...
    (microsoft.public.windows.server.security)
  • Re: Locking Down TS Sessions
    ... On the Security tab of the loopback "lockdown" GPO you can check the Deny ... "Apply Group Policy" for Domain Admins. ... to be running some other software that the Administrator will have to ...
    (microsoft.public.windows.terminal_services)