Click here to get back home

restricting user to control of one service?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
restricting user to control of one service? msft-sql 04-11-2006
Posted by msft-sql on April 11, 2006, 5:58 pm
Please log in for more thread options
Hi All: Is it possible to create a security policy where a user has the
right to start/stop a specific service, without giving them unfettered
access to all the services?

--




Posted by Steven L Umbach on April 11, 2006, 6:43 pm
Please log in for more thread options
Yes it is possible and the KB article can show a couple ways to do such.
However if the users in question are local administrators they could grant
themselves access to any service if they knew how to and had the desire to
do so. --- Steve

http://support.microsoft.com/default.aspx?scid=kb;en-us;288129

> Hi All: Is it possible to create a security policy where a user has the
> right to start/stop a specific service, without giving them unfettered
> access to all the services?
>
> --
>
>
>



Posted by msft-sql on April 12, 2006, 11:36 am
Please log in for more thread options
> Yes it is possible and the KB article can show a couple ways to do such.
> However if the users in question are local administrators they could grant
> themselves access to any service if they knew how to and had the desire to
> do so. --- Steve
>
> http://support.microsoft.com/default.aspx?scid=kb;en-us;288129

Thanks Steven. It seems like subinacl.exe would be the best solution, but
I'm still a little confused.

If I create a standard "user", can that user be granted control privileges
over a service, or does that user have to be a "power user", in which case I
would have to deny them access to every service except this one?

This is a situation where I am the admin of a standalone 2003 server, and I
want to grant a particular user the ability to log on through RD, and they
then need to be able to start/stop a specific service they're concerned
with. I just want to strictly limit what they can do when they're logged in.



>
>> Hi All: Is it possible to create a security policy where a user has the
>> right to start/stop a specific service, without giving them unfettered
>> access to all the services?
>>
>> --
>>
>>
>>
>
>



Posted by Steven L Umbach on April 12, 2006, 11:58 am
Please log in for more thread options
The user can be a regular user. They also would need to be able to start any
services that the service in question "depends on". You may also want to
check out setacl which is free. Subinacl can give me a headache trying to
get it to work right. --- Steve

http://setacl.sourceforge.net/html/examples.html --- see example 23.

>> Yes it is possible and the KB article can show a couple ways to do such.
>> However if the users in question are local administrators they could
>> grant themselves access to any service if they knew how to and had the
>> desire to do so. --- Steve
>>
>> http://support.microsoft.com/default.aspx?scid=kb;en-us;288129
>
> Thanks Steven. It seems like subinacl.exe would be the best solution, but
> I'm still a little confused.
>
> If I create a standard "user", can that user be granted control privileges
> over a service, or does that user have to be a "power user", in which case
> I would have to deny them access to every service except this one?
>
> This is a situation where I am the admin of a standalone 2003 server, and
> I want to grant a particular user the ability to log on through RD, and
> they then need to be able to start/stop a specific service they're
> concerned with. I just want to strictly limit what they can do when
> they're logged in.
>
>
>
>>
>>> Hi All: Is it possible to create a security policy where a user has the
>>> right to start/stop a specific service, without giving them unfettered
>>> access to all the services?
>>>
>>> --
>>>
>>>
>>>
>>
>>
>
>



Similar ThreadsPosted
Restricting service accounts that have administrator privileges July 8, 2007, 12:10 pm
Service control manager May 16, 2007, 6:08 pm
restricting user May 9, 2006, 3:19 am
domain access control for local user of domain computer? April 3, 2008, 5:14 pm
Event 529, User Name: SERVICE February 13, 2006, 3:41 pm
Allow user to restart service remotely July 27, 2007, 11:28 pm
Setting Permission to user to start a service October 19, 2006, 4:11 am
start/stop service as user from task scheduler April 3, 2006, 11:25 am
Passing user ID crenditials along the path within web service call February 26, 2007, 7:51 am
Re: Previous post should say Grant user right to remotely start stop Service - can anybody help? March 10, 2006, 1:04 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap