Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Security > NTFS/registry permissions for a service-specific SID

Reply
Thread Tools Display Modes

NTFS/registry permissions for a service-specific SID

 
 
Sharon2323
Guest
Posts: n/a

 
      08-03-2006
Hello:

Possible to assign NTFS/registry permissions to a service-specific SID other
than running that service as a user account or as Local System? I know that
that SID is assigned dynamically at start-up, and that there is a 1:1
mapping from service name to that SID, but it appears you can just assign
NTFS/registry permissions to the service name.

I've seen
http://www.microsoft.com/technet/win...cfeat.mspx#EHF
and the PPT slides from the PDC conference, but no mention of how to change
permissions with SC.EXE for a service (to change user rights, yes, but not
perms).

Thank You!






 
Reply With Quote
 
 
 
 
Sharon2323
Guest
Posts: n/a

 
      08-03-2006
CORRECTION:

> but it appears you can just assign...


but it appears you cannot just assign...



 
Reply With Quote
 
Joe Richards [MVP]
Guest
Posts: n/a

 
      08-05-2006
I am not exactly sure what you are saying here. Services run under the
service context of either a user ID or a well known security principal
such as LocalSystem, LocalService, or Network Service. There is not a
SID assigned to individual service applications.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Sharon2323 wrote:
> Hello:
>
> Possible to assign NTFS/registry permissions to a service-specific SID other
> than running that service as a user account or as Local System? I know that
> that SID is assigned dynamically at start-up, and that there is a 1:1
> mapping from service name to that SID, but it appears you can just assign
> NTFS/registry permissions to the service name.
>
> I've seen
> http://www.microsoft.com/technet/win...cfeat.mspx#EHF
> and the PPT slides from the PDC conference, but no mention of how to change
> permissions with SC.EXE for a service (to change user rights, yes, but not
> perms).
>
> Thank You!
>
>
>
>
>
>

 
Reply With Quote
 
Joe Richards [MVP]
Guest
Posts: n/a

 
      08-05-2006
Ah hold on, I didn't realize I had clicked on the vista group, I was
shooting for win2000.security which is just above this one in my current
config of Thunderbird. I did hear rumours about this for Vista but I
haven't seen any real documentation and haven't debugged it to check
what was actually done.

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm


Joe Richards [MVP] wrote:
> I am not exactly sure what you are saying here. Services run under the
> service context of either a user ID or a well known security principal
> such as LocalSystem, LocalService, or Network Service. There is not a
> SID assigned to individual service applications.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> Author of O'Reilly Active Directory Third Edition
> www.joeware.net
>
>
> ---O'Reilly Active Directory Third Edition now available---
>
> http://www.joeware.net/win/ad3e.htm
>
>
> Sharon2323 wrote:
>> Hello:
>>
>> Possible to assign NTFS/registry permissions to a service-specific SID
>> other
>> than running that service as a user account or as Local System? I
>> know that
>> that SID is assigned dynamically at start-up, and that there is a 1:1
>> mapping from service name to that SID, but it appears you can just assign
>> NTFS/registry permissions to the service name.
>>
>> I've seen
>> http://www.microsoft.com/technet/win...cfeat.mspx#EHF
>>
>> and the PPT slides from the PDC conference, but no mention of how to
>> change
>> permissions with SC.EXE for a service (to change user rights, yes, but
>> not
>> perms).
>>
>> Thank You!
>>
>>
>>
>>
>>
>>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
The Windows Firewall service terminated with service-specific erro DaMnIt Windows Vista Security 7 10-10-2007 05:34 PM
NTFS Permissions on System Folders in Vista Todd Bowlsby Windows Vista General Discussion 10 07-12-2007 04:32 AM
NTFS permissions for a domain user RedParanoid Windows Vista Networking 0 04-28-2007 07:04 AM
Do NTFS File Permissions migrate with Acronis backups to different drives ?? Synapse Syndrome Windows Vista General Discussion 3 02-20-2007 08:46 PM
NTFS Security Permissions (HOW TO RESET?) Mike (Bryett Enterprise LTD) Windows Vista Security 4 06-14-2006 05:54 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59