Click here to get back home

Is NETWORK SERVICE Member of Users Group?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Is NETWORK SERVICE Member of Users Group? Will 03-12-2007
Posted by Will on March 12, 2007, 4:39 pm
Please log in for more thread options
Is the NETWORK SERVICE account an implied member of the Users group? A
Microsoft support rep is telling me it is, but I have plenty of cases here
where I am not able to give that account access to a resource with Users,
but only with either Authenticated Users or with an explicit DACL permission
to NETWORK SERVICE.

Also, please confirm that NT_AUTHORITY\NetworkService is the same as the
local computer object named NETWORK SERVICE.

--
Will



Posted by Roger Abell [MVP] on March 16, 2007, 12:10 am
Please log in for more thread options
> Is the NETWORK SERVICE account an implied member of the Users group? A
> Microsoft support rep is telling me it is, but I have plenty of cases here
> where I am not able to give that account access to a resource with Users,

strange as its token has builtin\Users in it

> but only with either Authenticated Users or with an explicit DACL
> permission
> to NETWORK SERVICE.
>
> Also, please confirm that NT_AUTHORITY\NetworkService is the same as the
> local computer object named NETWORK SERVICE.

AFAIK yes, just differently displayed.



Posted by Will on March 16, 2007, 1:45 am
Please log in for more thread options
>> Is the NETWORK SERVICE account an implied member of the Users group? A
>> Microsoft support rep is telling me it is, but I have plenty of cases
>> here
>> where I am not able to give that account access to a resource with Users,
>
> strange as its token has builtin\Users in it


Under Windows 2003, Users group normally has INTERACTIVE and Authenticated
Users inside of it. I normally remove Authenticated Users from Users and
add it back selectively to resources that need it.

That may explain the Microsoft rep thinking that NETWORK SERVICE was in
Users? Maybe its membership is indirect via Authenticated Users?

And it would explain my SACL failures from NETWORK SERVICE, since I remove
NETWORK SERVICE from Users by removing Authenticated Users from Users.

--
Will




Posted by Roger Abell [MVP] on March 16, 2007, 11:54 am
Please log in for more thread options
>>> Is the NETWORK SERVICE account an implied member of the Users group? A
>>> Microsoft support rep is telling me it is, but I have plenty of cases
>>> here
>>> where I am not able to give that account access to a resource with
>>> Users,
>>
>> strange as its token has builtin\Users in it
>
>
> Under Windows 2003, Users group normally has INTERACTIVE and Authenticated
> Users inside of it. I normally remove Authenticated Users from Users and
> add it back selectively to resources that need it.
>
Similarly here, except remove both, rarely add back either . . .

> That may explain the Microsoft rep thinking that NETWORK SERVICE was in
> Users? Maybe its membership is indirect via Authenticated Users?
>
At first I was thinking along those lined, but it is not so.
Network Server, at least whereever I have peeks as result of your post,
is _directly_ a member in the local Users group. So, it is not a case as
with Local System where Users membership is only due to Authenticated
Users (which they both have in their tokens) or INTERACTIVE if that is
in play.

> And it would explain my SACL failures from NETWORK SERVICE, since I remove
> NETWORK SERVICE from Users by removing Authenticated Users from Users.

The one thing that may explain is understanding at what point in your
processes
the access denial occurs. Network Service "transitions" to being machine$
when
it is accessing resources that are off-box. This machine$ is usually the
domain
identity of Local System. Local System is _not_ directly in Users. So, is
the
eventing you are seeing resultant from some off-box activity ?? as I could
see
why MS may have let for example the on-box mashalling due to off-box
activity
happen in context used for off-box - as it would avoid a lot of overhead
needed
for the context switching and passing of the marshalled to the on-box
context.

Roger

>



Similar ThreadsPosted
Can I delete 'Athenticated Users' group form local 'Users' group January 29, 2008, 11:52 am
"Network Service" account is UNABLE to write to a network shared folder April 18, 2007, 7:01 pm
How to let user group member to share files and folders August 26, 2006, 12:16 am
Is local system account member of local Administrators group? June 21, 2005, 11:33 am
'NT Authority\Network Service' Account July 26, 2005, 4:03 am
openCertStore() denied to Network Service September 19, 2007, 3:04 pm
accessing HKCU of network service account December 21, 2005, 4:23 pm
Boot Volume NTFS Permissions for Network Service July 3, 2006, 10:45 pm
Users browsing network via Office 2003 October 7, 2006, 7:49 am
SCEP - Network Device Enrollment Service on Windows 2008 Standard March 31, 2008, 10:32 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap