Click here to get back home

Need Help Assigning Permissions to Services in Group Policy

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Need Help Assigning Permissions to Services in Group Policy Will 03-12-2008
Posted by Will on March 12, 2008, 7:24 pm
Please log in for more thread options
I am for the first time trying to use group policy to enforce starting
services on particular computers. My first use case was the Windows
Firewall service. I set group policy to start this service automatically
in our domain on all computers. Okay, I screwed this one up but good.
Apparently the group policy not only changes the default start setting of
the service, but also changes the security ACL on the service!! And,
apparently, the default ACL in Microsoft group policy is NOT compatible with
at least some of our computers. Starting Windows Firewall service on the
affected computers fails with a

0x80004015 the class is configured to run as a security id different
from the caller

The default ACL for group policy apparently gives Full Control to
Administrators and SYSTEM, and Read access to INTERACTIVE. Conspicuously
missing from this list is the Authenticated Users entity, which I believe is
how Local Service and Network Service reserved user accounts get access to
services.

Knowledge base 892199 discusses this issue, but the knowledge base is quite
dense and I find the security descriptor representations they are using to
be just borderline understandable by a human being who is not daily immersed
in that obscure syntax.

Using group policy, what ACL should I set for a service that I want to have
enforced as Automatic on Windows XP and Windows 2003? I don't want to
twiddle with the security descriptors on individual computers, but want to
fix the ACL using the ACL GUI in group policy. I need an ACL that is
compatible with starting the service by Network Service or Local Service
user accounts.

--
Will



Similar ThreadsPosted
Windows 2003 Problem with Group Policy for Services Startup and Permissions April 27, 2006, 7:27 am
local group / global group permissions problem August 18, 2005, 12:42 pm
Domain Controller Policy setting "Allow log on through Terminal Services" April 1, 2008, 12:01 pm
Group Policy???? June 26, 2005, 11:39 am
Group Policy April 25, 2006, 11:58 pm
Group Policy May 7, 2007, 3:57 pm
Deny Right to Local Admin Group to Log On Via Terminal Services? May 24, 2007, 12:28 pm
Set MaximumDynamicBacklog via Group Policy? October 26, 2005, 11:12 am
IAS server and group policy November 2, 2005, 11:04 am
A question on Group Policy November 17, 2005, 9:26 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap