Click here to get back home

Boot Volume NTFS Permissions for Network Service

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Boot Volume NTFS Permissions for Network Service Will 07-03-2006
Posted by Will on July 3, 2006, 10:45 pm
Please log in for more thread options
Windows 2003 introduces new userids for services to run under: Network
Service and Local Service. Does anyone have a recommended ACL for what
parts of the boot volume these services need to access read-only and what
parts they need to access read-write?

--
Will



Posted by Roger Abell [MVP] on July 4, 2006, 1:14 pm
Please log in for more thread options
Is saying that, AFAIK these have no requirements that are
any different from those given to limited Users unsatisfying?
Of course, there may be added areas due to the third-party
services, or some MS optional components like IIS, for
which these may be used as the service account.

> Windows 2003 introduces new userids for services to run under: Network
> Service and Local Service. Does anyone have a recommended ACL for what
> parts of the boot volume these services need to access read-only and what
> parts they need to access read-write?
>
> --
> Will
>
>



Posted by Will on July 4, 2006, 4:19 pm
Please log in for more thread options
Roger, my security audit logfiles are filled with attempts by Network
Service to take actions deleting or writing to various logfiles nested deep
in system32. So apparently the Network Service user needs more boot volume
access than an ordinary user should have.

--
Will

> Is saying that, AFAIK these have no requirements that are
> any different from those given to limited Users unsatisfying?
> Of course, there may be added areas due to the third-party
> services, or some MS optional components like IIS, for
> which these may be used as the service account.



Posted by Roger Abell [MVP] on July 4, 2006, 11:36 pm
Please log in for more thread options
Yes, but I would categorize those as one-off grants each needed due to
the uses being made of Network Service (i.e. the logs related to the
services running in that account). In all fairness, MS should have done
right when transiting services to that context (ditto Local Service).
Your question however is I think correctly answered that there is no
extra grant that one needs to make generically, but only ones due to
the uses made of the account. Now, if the log files you mention were
collected such as in system32\Logfiles instead of scattered as most
are and accumulated at system32 root, then you could just adjust on
system32\LogFiles. You are now turning me to an area in which
I have a fair degree of disappointment in the MS implementation.

> Roger, my security audit logfiles are filled with attempts by Network
> Service to take actions deleting or writing to various logfiles nested
> deep
> in system32. So apparently the Network Service user needs more boot
> volume
> access than an ordinary user should have.
>
> --
> Will
>
>> Is saying that, AFAIK these have no requirements that are
>> any different from those given to limited Users unsatisfying?
>> Of course, there may be added areas due to the third-party
>> services, or some MS optional components like IIS, for
>> which these may be used as the service account.
>
>



Posted by Roger Abell [MVP] on July 4, 2006, 11:44 pm
Please log in for more thread options
PS Will, when you get to postnig about the failures you see when
you enable auditing of global system objects, well, you will be on
your own for that one . . . it is a surprising mess ;-(

> Roger, my security audit logfiles are filled with attempts by Network
> Service to take actions deleting or writing to various logfiles nested
> deep
> in system32. So apparently the Network Service user needs more boot
> volume
> access than an ordinary user should have.
>
> --
> Will
>
>> Is saying that, AFAIK these have no requirements that are
>> any different from those given to limited Users unsatisfying?
>> Of course, there may be added areas due to the third-party
>> services, or some MS optional components like IIS, for
>> which these may be used as the service account.
>
>



Similar ThreadsPosted
System Volume Information folder visable on network! August 2, 2006, 4:11 am
KDC service hangs on start + cert error in event log at every boot March 30, 2007, 2:58 am
"Network Service" account is UNABLE to write to a network shared folder April 18, 2007, 7:01 pm
ntfs permissions, ownership, adding permissions January 13, 2006, 2:03 pm
Share permissions conflicting with NTFS permissions May 18, 2006, 1:16 pm
'NT Authority\Network Service' Account July 26, 2005, 4:03 am
openCertStore() denied to Network Service September 19, 2007, 3:04 pm
NTFS Permissions February 20, 2006, 7:11 pm
NTFS Permissions August 16, 2006, 4:44 am
accessing HKCU of network service account December 21, 2005, 4:23 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap