Re: Problem changing Service Accounts

From: Steve Thompson (SteveThompson_at_nomail.please)
Date: 04/26/04

  • Next message: Jasper Smith: "Re: Granting EXEC to all my user sprocs in one hit"
    Date: Mon, 26 Apr 2004 14:03:58 -0400
    
    

    The following article does a nice job of laying out which registry, NTFS and
    other permissions are required to modify the service account to a non-admin
    account. You don't have to use EM to make the change, the permissions have
    to be correct or the change will fail.
    http://support.microsoft.com/default.aspx?scid=kb;en-us;283811&Product=sql2k

    Steve
    "David Riddiford" <anonymous@discussions.microsoft.com> wrote in message
    news:50C3327A-4284-4177-A2A8-B5314EA61CCA@microsoft.com...
    > Hi,
    >
    > I have a standalone machine running XP Professional and SQL Server 2000
    Developer Edition.
    >
    > I am using Microsoft Baseline Security Analyser 1.2 to ensure that the
    machine is secure as I can get it.
    >
    > One of the suggestions was to change the service account for SQL Server
    and Agent from LocalSystem to another account with less rights.
    LocalService, NetworkService, or a domain account were all options.
    >
    > Various threads and information on msdn suggest that changing the service
    accounts using Enterprise Manager is the way to go because it automatically
    sets the correct permissions for the selected account and doesn't muck up
    full text search in the process.
    >
    > However, no matter what I do, I can't seem to get Enterprise Manager to
    recognize any account other than LocalSystem. I have tried using a fully
    qualified name for a user that I have set up to do it. I have also tried
    LocalService but without any success.
    >
    > I have also tried using the services list in computer management to change
    the accounts and this works, but then the service won't start because it
    doesn't have the right permissions. I'd prefer to let Enterprise Manager
    handle this itself.
    >
    > If anyone has any suggestions on how to resolve this problem it would be
    greatly appreciated.
    >
    > Thanks,
    > David.


  • Next message: Jasper Smith: "Re: Granting EXEC to all my user sprocs in one hit"

    Relevant Pages

    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Win2k - Account Operator not working properly
      ... You very likely have other ACL issues other than what was mentioned and I can point them out here for you for free or you can pay someone $200-500 an hour to come check it out. ... In order for that to result in inheritence protection it means the schema had to be modified. ... set the account in the GUI to inherit from its parents. ... Used the delegation wizard, on the top level OU, to assign the desired permissions. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
      (microsoft.public.sharepoint.windowsservices)
    • Consider Windows XP File Security and Group Policies
      ... If you are running Windows XP and are using the NTFS file system, ... Account from being able to purge its history footprint files. ... Changing Folder permissions to Read-Execute instead of Full ... you globally apply Full Control for the Administrators group and the SYSTEM ...
      (microsoft.public.windowsxp.general)