Re: Ntbackup Windows 2003 SP1 issue (VSS/Security)

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 05/08/05


Date: Sun, 8 May 2005 08:27:27 -0700

Is the domain account VLM\ntbackupaccount a member of
the Users group on the machine where the access is throwing
an error? The accesses requested from services.exe are not
anything excessive.

-- 
Roger Abell
Microsoft MVP (Windows  Security)
MCSE (W2k3,W2k,Nt4)  MCDBA
<workinghard@news.postalias> wrote in message
news:%23gXHvL7UFHA.3240@TK2MSFTNGP10.phx.gbl...
> Hello,
>
> Since installing Windows 2003 SP1 on our servers we get following errors
> during an NT backup (see lower).  I believe this is a permission problem
and
> I wil try to give the Backup Operators group admin right as a test,
propably
> just read & execute rights on the services.exe might be enough ...  Is
there
> anything known about this issue?  Thx in advance.
>
> Application log:
>
> Volume Shadow Copy Service error: Unexpected error  OpenService
> (shSCManager, 'VSS', SERVICE_QUERY_STATUS).  hr = 0x80070005
>
>
> And in the security log:
>
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Object Access
> Event ID: 560
> Date:  5/8/2005
> Time:  11:23:24 AM
> User:  MYDOMAIN\NTBACKUPACCOUNT
> Computer: AOCSRV25
> Description:
> Object Open:
>   Object Server: SC Manager
>   Object Type: SC_MANAGER OBJECT
>   Object Name: ServicesActive
>   Handle ID: -
>   Operation ID: {0,20193990}
>   Process ID: 464
>   Image File Name: C:\WINDOWS\system32\services.exe
>   Primary User Name: AOCSRV25$
>   Primary Domain: VLM
>   Primary Logon ID: (0x0,0x3E7)
>   Client User Name: ntbackupaccount
>   Client Domain: VLM
>   Client Logon ID: (0x0,0x12DE8A4)
>   Accesses: READ_CONTROL
>    Connect to service controller
>    Enumerate services
>    Query service database lock state
>
>   Privileges: -
>   Restricted Sid Count: 0
>   Access Mask: 0x20015
>
>
>
>
>


Relevant Pages

  • MSDTC Security Log Failure Audits
    ... While scrolling through the Security logs of a Windows 2003 box, ... Event Type: Failure Audit ... Primary Logon ID: ... Client User Name: - ...
    (microsoft.public.windows.server.security)
  • WwK3 cluster + MSSQL sp3a upg.
    ... the setup for MS SQL sp3a it stops saying that it cannot detect the satus of ... We have applied a security template which might conflict with MS ... Primary Logon ID: ... Client User Name: NETWORK SERVICE ...
    (microsoft.public.sqlserver.clustering)
  • Re: 560 errors
    ... security policy. ... > Event Type: Failure Audit ... > Primary Logon ID: ... > Client User Name: - ...
    (microsoft.public.win2000.security)
  • Re: Why does this keep happening...
    ... here's what's showing up in my security log in the event ... Object Server: Security ... Primary Logon ID: ... Client User Name: - ...
    (microsoft.public.inetserver.iis.security)
  • lame server messages in named.log
    ... Mar 30 05:42:30.526 security: info: client 202.52.250.176#1052: ... query (cache) denied ...
    (RedHat)