Click here to get back home

Access the service only

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Access the service only Philip Tsang 01-04-2006
Posted by Philip Tsang on January 4, 2006, 2:31 am
Please log in for more thread options
Hi All

We have one Windows 2000 Server and 20 x computer, i am Administrator on
domain. Now, one domain user need to remote the server to stop one
"Services" in "Administrator Tools". I success let user logon server by
Terminal, but I don't know how to let he cannot do anything such as access
document on server. just approve he only can stop or start the Service in
server. Do you know how to do ? Thanks you for help

Philip



Posted by Steven L Umbach on January 4, 2006, 3:10 am
Please log in for more thread options
You would have to configure NTFS permissions so that he can not access any
folders he is not supposed to. For instance if you have a folder with
documents in it either make sure he is not in a member of any group that has
any permissions to the folder or give his user account explicit deny
permissions to the folder. I am assuming he is not a local administrator on
that server or he utilimately could give himself permissions to such a
folder. The links below explain more. --- Steve

http://support.microsoft.com/default.aspx?kbid=300691
http://support.microsoft.com/default.aspx?scid=kb;EN-US;308419 --- mostly
applies to Windows 2000 also,

> Hi All
>
> We have one Windows 2000 Server and 20 x computer, i am Administrator on
> domain. Now, one domain user need to remote the server to stop one
> "Services" in "Administrator Tools". I success let user logon server by
> Terminal, but I don't know how to let he cannot do anything such as access
> document on server. just approve he only can stop or start the Service in
> server. Do you know how to do ? Thanks you for help
>
> Philip
>
>



Posted by Philip Tsang on January 4, 2006, 5:20 am
Please log in for more thread options
Is it possiable enable the right of service only for user ?

Philip

撰寫於郵件新聞:e3iNgZQEGHA.1508@TK2MSFTNGP15.phx.gbl...
You would have to configure NTFS permissions so that he can not access any
folders he is not supposed to. For instance if you have a folder with
documents in it either make sure he is not in a member of any group that has
any permissions to the folder or give his user account explicit deny
permissions to the folder. I am assuming he is not a local administrator on
that server or he utilimately could give himself permissions to such a
folder. The links below explain more. --- Steve

http://support.microsoft.com/default.aspx?kbid=300691
http://support.microsoft.com/default.aspx?scid=kb;EN-US;308419 --- mostly
applies to Windows 2000 also,

> Hi All
>
> We have one Windows 2000 Server and 20 x computer, i am Administrator on
> domain. Now, one domain user need to remote the server to stop one
> "Services" in "Administrator Tools". I success let user logon server by
> Terminal, but I don't know how to let he cannot do anything such as access
> document on server. just approve he only can stop or start the Service in
> server. Do you know how to do ? Thanks you for help
>
> Philip
>
>




Posted by Steven L Umbach on January 4, 2006, 4:06 pm
Please log in for more thread options
See the links below on a couple different ways to add a user to the
permissions for a service using either Group Policy/computer
configuration/Windows settings/services for a domain computer or subinacl.
The user will also need to be able to start any service that the service
"depends on" if any. --- Steve

http://support.microsoft.com/?kbid=288129 --- How to grant users rights
to manage services in Windows 2000

> Is it possiable enable the right of service only for user ?
>
> Philip
>
> 撰寫於郵件新聞:e3iNgZQEGHA.1508@TK2MSFTNGP15.phx.gbl...
> You would have to configure NTFS permissions so that he can not access any
> folders he is not supposed to. For instance if you have a folder with
> documents in it either make sure he is not in a member of any group that
> has
> any permissions to the folder or give his user account explicit deny
> permissions to the folder. I am assuming he is not a local administrator
> on
> that server or he utilimately could give himself permissions to such a
> folder. The links below explain more. --- Steve
>
> http://support.microsoft.com/default.aspx?kbid=300691
> mostly
> applies to Windows 2000 also,
>
>> Hi All
>>
>> We have one Windows 2000 Server and 20 x computer, i am Administrator on
>> domain. Now, one domain user need to remote the server to stop one
>> "Services" in "Administrator Tools". I success let user logon server by
>> Terminal, but I don't know how to let he cannot do anything such as
>> access
>> document on server. just approve he only can stop or start the Service in
>> server. Do you know how to do ? Thanks you for help
>>
>> Philip
>>
>>
>
>
>



Posted by Roger Abell [MVP] on January 5, 2006, 8:28 am
Please log in for more thread options
You would probably be better off not letting them have local
login rights but instead provide them with a small script that
can manage the service remotely.
Then, with network access and right to specific service(s) only
granted using info Steve has provided, they should be able to
do what you want at least if they are on the internal network
and the machine is not tightly filtering its ports relative to the
machine from which the service would be managed (RPC
would likely be needed).

> Hi All
>
> We have one Windows 2000 Server and 20 x computer, i am Administrator on
> domain. Now, one domain user need to remote the server to stop one
> "Services" in "Administrator Tools". I success let user logon server by
> Terminal, but I don't know how to let he cannot do anything such as access
> document on server. just approve he only can stop or start the Service in
> server. Do you know how to do ? Thanks you for help
>
> Philip
>
>



Similar ThreadsPosted
Restrict access to ATL COM service June 3, 2005, 2:08 pm
Minimum File System Access Needed for a Service? December 6, 2005, 3:14 am
Windows service denied access to mapped drive May 4, 2007, 7:06 am
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. April 12, 2007, 6:03 pm
An attempt was made to access a socket in a way forbidden by its access permissions March 13, 2008, 1:44 pm
Controlling access through a remote access policy August 19, 2005, 7:00 am
Cisco 1300 series wireless access point/bridge Vs Linksys WAP54GPE Access Point Anyone know the basic pros & cons? November 28, 2007, 3:34 pm
how to add a service in gp? December 6, 2006, 10:34 am
RPC service property July 19, 2005, 6:19 am
Certificate Service September 17, 2005, 11:34 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap