Re: Access and roles in DCOM technology



No, it is not necessary for the domain account to be an
administrator on the involved machines, and, in fact the
account should definitely not be.
It sounds like you are not taking DCom launch/access
permissions into account. These are defined on a per
COM+ component basis (when the defaults are not
sufficient), which is within the Components mmc and
which may be set for the components by the installer
during installation by an admin. Notice also that XP SP2
and W2k3 Sp1 added further DCom/Com+ security
settings (in the Security Options part of group policy)
but these should only come into play when an application
is relying on the default values (for launch/access/etc).
You would be best off adjusting the permissions that are
specific to your components - admins will be resistant to
either granting admin or over loosening for all just for the
sake of your application (or at least they should be).

"ef" <ef@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:36D021A2-5627-45D6-ACC7-FD89262C199B@xxxxxxxxxxxxxxxx
> Hi everybody,
>
> I have a system consists of 4 servers. On each server there are services
> and
> COM+ components installed. The services and components run under
> applicative
> user. The 4 servers interact via DCOM technology. If the applicative user
> is
> a regular user in the Domain, the DCOM operations fail because of "Access
> denied". If this user is local administrator on 4 servers everything works
> fine. Does anyone know, what are the minimal roles needed for the
> applicative
> user so the DCOM technology will work between the servers? Must he be an
> administrator? The operation system is Windows 2003.
> Thank you in advance for any help
>
> Efrat
>


.



Relevant Pages

  • Re: MS Exchange Relay Authentication
    ... I've seen this on a few servers in various environments. ... The account was still named Administrator ... It seems that account passwords are being cracked. ...
    (NT-Bugtraq)
  • Re: Administrator Account Locking Out
    ... the Administrator account, or possibly our RADIUS server might be using it ... 2003 Servers and Windows 2000 servers. ... I have looked in both the event logs, turned on netlogon logging, etc. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Super Admin Account
    ... Does he usually go to servers and mess with that? ... Does he have sufficient knowledge to mess with DCs? ... Rename the Administrator account, create a new account ...
    (microsoft.public.windows.server.active_directory)
  • Re: Changing Administrator Password On Server 2003 Domain Controll
    ... you should limit use of Administrator account for logging into domain ... It is in fact the Domain Administrator password I am speaking of. ... the same password will then be required on DC Two and the Member Servers ... on domain controllers there is DSRM ...
    (microsoft.public.windows.server.general)
  • Re: Changing Administrator Password On Server 2003 Domain Controll
    ... you should limit use of Administrator account for logging into domain ... It is in fact the Domain Administrator password I am speaking of. ... the same password will then be required on DC Two and the Member Servers ... on domain controllers there is DSRM ...
    (microsoft.public.windows.server.general)