Click here to get back home

Allow user to restart service remotely

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Allow user to restart service remotely Jordan 07-27-2007
Posted by Roger Abell [MVP] on August 8, 2007, 12:52 am
Please log in for more thread options
> You should set the permission through GPO so it will be self documented,
> survive a reinstall and apply to many citrix server if necessary..
>

Perhaps, but not unless from a W2k3 server.
Doing so from an XP SP2 will munge up the ACL on the service
unless the XP SP2 has had a hotfix applied.

>
>> Thanks, I got SC and the documents however I don't know what to do for
>> the Service Descriptor Definition Language entry for giving the users the
>> right to restart the service. For example I need to have my
>> MYDOMAIN\Engineering group be able to restart the FlexLM service on
>> server \LicenseServer
>>
>> So far I believe the syntax is"
>>
>> sc \LicenseServer sdset FlexLM ???????
>>
>>
>>
>>
>>> and, sc also allows one to grant permissions over a service
>>> (see sc sdshow and sc sdset)
>>>
>>> Roger
>>>
>>>> We have a program that uses a license manager service on the server.
>>>> The program is not all that stable so occasionally the program will
>>>> bomb out and the license service on the server thinks that they are
>>>> still logged in. The only way to clear out the connection is to
>>>> restart the service on the server which means I have to do it.
>>>>
>>>> Naturally I don't want users to have access to the server locally or
>>>> remotely, but I would like to have some way they can restart the
>>>> service when the program bombs out. Any ideas?
>>>>
>>>
>>>
>>
>>
>



Posted by Roger Abell [MVP] on August 8, 2007, 12:58 am
Please log in for more thread options
One approach is to search on msdn2.microsoft.com for SDDL
Another is to use sdshow and then locate the ACE for Administrators,
it is the () set ending with ;BA) for Builtin Administrators, and copy
that part, replacing the BA with the SID for the group that should have
rights equal to BA over that one service.
Another is to use the Security Templates to define a template in which
you set that service with a grant as desired for your custom group.
After the template is saved you may use notepad to find the SDDL part
for the custom group. If you want to you could apply the template or
import it into a GPO - but if you do so be careful that it duplicates the
existing grants, only adding the new ACE and not leaving any out.
As mentioned in other posting this thread, XP SP2 is not where you
should do this if you choose to alter GPOs. Do it on a W2k3.

> Thanks, I got SC and the documents however I don't know what to do for
> the Service Descriptor Definition Language entry for giving the users the
> right to restart the service. For example I need to have my
> MYDOMAIN\Engineering group be able to restart the FlexLM service on server
> \LicenseServer
>
> So far I believe the syntax is"
>
> sc \LicenseServer sdset FlexLM ???????
>
>
>
>
>> and, sc also allows one to grant permissions over a service
>> (see sc sdshow and sc sdset)
>>
>> Roger
>>
>>> We have a program that uses a license manager service on the server.
>>> The program is not all that stable so occasionally the program will bomb
>>> out and the license service on the server thinks that they are still
>>> logged in. The only way to clear out the connection is to restart the
>>> service on the server which means I have to do it.
>>>
>>> Naturally I don't want users to have access to the server locally or
>>> remotely, but I would like to have some way they can restart the service
>>> when the program bombs out. Any ideas?
>>>
>>
>>
>
>



Similar ThreadsPosted
Win2003 SP1 remotely restart service June 14, 2005, 1:02 pm
Re: Previous post should say Grant user right to remotely start stop Service - can anybody help? March 10, 2006, 1:04 pm
Restart service permission June 8, 2005, 3:34 pm
Service writing on Win2003 remotely. October 26, 2007, 8:59 am
Re: Grant user right to remotely start stop server - can anybody help? March 10, 2006, 12:32 pm
Re: Grant user right to remotely start stop server - can anybody help? March 10, 2006, 12:41 pm
Start and Stop Services Remotely Under Non-Administrative User April 26, 2006, 5:01 pm
Password Policy require server restart March 11, 2006, 9:37 am
Event 529, User Name: SERVICE February 13, 2006, 3:41 pm
restricting user to control of one service? April 11, 2006, 5:58 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap