Minimum OS Privileges for Server & Agent

From: Bob Atkinson (Bob.Atkinson@tdh.state.tx.us)
Date: 10/29/02


From: "Bob Atkinson" <Bob.Atkinson@tdh.state.tx.us>
Date: Tue, 29 Oct 2002 09:00:10 -0800


We do not want server & agent to run with
domain/administrator privileges. But we do replication and
cross-network backup and log-shipping.

What are the minimal OS privileges or roles sufficient to
run server and agent?

Without replication and cross-network backup and log-
shipping, then what are the minimal OS privileges?

Currently the account that runs the server and agent is in
the local groups:
  backup-operators
  power-users
with plocal policy privileges to:
  lock-pages-in-memory
  log on as batch job
  log on as a service

This is not sufficient to start the service :-(

TIA



Relevant Pages

  • Re: Minimum OS Privileges for Server & Agent
    ... > domain/administrator privileges. ... > cross-network backup and log-shipping. ... > run server and agent? ...
    (microsoft.public.sqlserver.security)
  • Re: CGI apps break after DCPROMO an IIS6 server
    ... This is one of those things different on a DC vs a member server in regards ... The "built in" accounts have the minimum and necessary privileges to run ... >privileges listed in F1-help of IIS Manager UI required ...
    (microsoft.public.inetserver.iis.security)
  • Re: Win2000 Impersonation weirdness? (or is it a conundrum?)
    ... But why does the XP box work (allowing LogonUser calls from a process ... running without SE_TCB_NAME) while the Win2K does not? ... And what specifically do you mean by "system privileges"? ... > Is the server joined to a domain? ...
    (microsoft.public.security)
  • Re: Win2000 Impersonation weirdness? (or is it a conundrum?)
    ... But why does the XP box work (allowing LogonUser calls from a process ... running without SE_TCB_NAME) while the Win2K does not? ... And what specifically do you mean by "system privileges"? ... > Is the server joined to a domain? ...
    (microsoft.public.win2000.security)
  • Re: How to turn linux into VMS - memory refresher for Dave ...
    ... >> need to find a way to get elevated priv's on an OpenVMS server before ... privileges and there will not be any way for them to gain privileges. ... (Unfortunately on Unix systems local exploits which elevate users to root ...
    (comp.os.vms)