Click here to get back home

The privilege to start a Windows service

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
The privilege to start a Windows service William 06-13-2006
Posted by William on June 13, 2006, 6:37 am
Please log in for more thread options
Hi all,
I'm a newbie to Windows environment. Currently I meet some problems
while porting UNIX services to Windows platform. I list them as below.

1. Could a normal user without administrators privilege start a Windows
service? I have been looking for a privilege mapping document for
Windows service for a while, but found nothing. Maybe you guys could
point me to a right place.

2. When I start a Windows service which logon as LocalSystem, I get an
error "Access is denied". This problem could be fixed by granting
read/execution privilege to SERVICE group. I would not grant the
permission to Everyone. Could anybody show me a solution to grant the
permission the user exactly needs.

MSDN is huge resource pool, I was told. But I can't find any useful
information with a search there. Perhaps it's my fault...

Any response is appreciated!

-William


Posted by Steven L Umbach on June 13, 2006, 12:02 pm
Please log in for more thread options
See if the following documents in the links below help on how to manage
service permissions. The free setacl utility will also work and is more user
friendly then subinacl. A user will also need permission to start services
that the service depends on, if any, in case they are stopped. It may help
trying to use the sc command to start the service as you may get more
helpful information as to why it failed. Sc /? will show the details of the
sc command. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
http://setacl.sourceforge.net/html/examples.html --- see example 23
http://www.microsoft.com/technet/security/topics/serversecurity/serviceaccount/default.mspx
--- The Services and Service Accounts Security Planning Guide

> Hi all,
> I'm a newbie to Windows environment. Currently I meet some problems
> while porting UNIX services to Windows platform. I list them as below.
>
> 1. Could a normal user without administrators privilege start a Windows
> service? I have been looking for a privilege mapping document for
> Windows service for a while, but found nothing. Maybe you guys could
> point me to a right place.
>
> 2. When I start a Windows service which logon as LocalSystem, I get an
> error "Access is denied". This problem could be fixed by granting
> read/execution privilege to SERVICE group. I would not grant the
> permission to Everyone. Could anybody show me a solution to grant the
> permission the user exactly needs.
>
> MSDN is huge resource pool, I was told. But I can't find any useful
> information with a search there. Perhaps it's my fault...
>
> Any response is appreciated!
>
> -William
>



Posted by William on June 13, 2006, 10:44 pm
Please log in for more thread options

Thanks Steven for your quick response.

One more issue -- I don't find example 23 in
http://setacl.sourceforge.net/html/examples.html.

Steven L Umbach wrote:
> See if the following documents in the links below help on how to manage
> service permissions. The free setacl utility will also work and is more user
> friendly then subinacl. A user will also need permission to start services
> that the service depends on, if any, in case they are stopped. It may help
> trying to use the sc command to start the service as you may get more
> helpful information as to why it failed. Sc /? will show the details of the
> sc command. --- Steve
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
> http://setacl.sourceforge.net/html/examples.html --- see example 23
> http://www.microsoft.com/technet/security/topics/serversecurity/serviceaccount/default.mspx
> --- The Services and Service Accounts Security Planning Guide


Posted by Steven L Umbach on June 13, 2006, 11:08 pm
Please log in for more thread options
Hmm. I can see it at the bottom of the page. Anyhow here it is. --- Steve

Example 23 SetACL.exe -on "\server1\W32Time" -ot srv -actn ace
-ace "n:domain1\group1;p:start_stop"Sets permissions to start and
stop the Windows time service on server 'server1' for group 'group1' in
domain 'domain1'.


>
> Thanks Steven for your quick response.
>
> One more issue -- I don't find example 23 in
> http://setacl.sourceforge.net/html/examples.html.
>
> Steven L Umbach wrote:
>> See if the following documents in the links below help on how to manage
>> service permissions. The free setacl utility will also work and is more
>> user
>> friendly then subinacl. A user will also need permission to start
>> services
>> that the service depends on, if any, in case they are stopped. It may
>> help
>> trying to use the sc command to start the service as you may get more
>> helpful information as to why it failed. Sc /? will show the details of
>> the
>> sc command. --- Steve
>>
>> http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
>> http://setacl.sourceforge.net/html/examples.html --- see example 23
>> http://www.microsoft.com/technet/security/topics/serversecurity/serviceaccount/default.mspx
>> --- The Services and Service Accounts Security Planning Guide
>


begin 666 spacer.gif
K1TE&.#EA`0`!`( ``/___P```"'Y! $`````+ `````!``$```("1 $`.P``
`
end


Posted by William on June 14, 2006, 5:37 am
Please log in for more thread options
Thanks a lot!

Steven L Umbach wrote:
> Hmm. I can see it at the bottom of the page. Anyhow here it is. --- Steve
>
> Example 23 SetACL.exe -on "\server1\W32Time" -ot srv -actn ace
> -ace "n:domain1\group1;p:start_stop"Sets permissions to start and
> stop the Windows time service on server 'server1' for group 'group1' in
> domain 'domain1'.


Similar ThreadsPosted
RPC Security Service fails to start on Windows 2003 Server July 12, 2007, 6:11 am
allow user to Start, Stop and Pause a Windows Service on a Workgroup Computer December 12, 2006, 10:18 am
allow start/stop a specific service through GPO November 14, 2006, 8:37 am
set service start permissions to Administrator only August 17, 2007, 6:13 pm
Setting Permission to user to start a service October 19, 2006, 4:11 am
start/stop service as user from task scheduler April 3, 2006, 11:25 am
Certificate Authority service fails to start due to corrupt log fi April 22, 2008, 10:00 pm
KDC service hangs on start + cert error in event log at every boot March 30, 2007, 2:58 am
Re: Previous post should say Grant user right to remotely start stop Service - can anybody help? March 10, 2006, 1:04 pm
Could not start the Windows Time Error 1300 June 22, 2005, 10:03 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap