Solved

Log On As A Batch Job Service Security

Posted on 2012-03-26
3
750 Views
Last Modified: 2012-06-22
Can someone please tell me if Backup Operators and PerfMon Users groups actually need to be given this right?  We follow DISA Stigs and this was a finding.  We need to know if they can be removed safely and if not, sound justification.  Thanks in advance.
0
Comment
Question by:BrianRB
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 40

Accepted Solution

by:
Adam Brown earned 500 total points
ID: 37768172
They can be removed unless those accounts are operating scheduled batch jobs for running backups or performance monitoring. If you're not, you can remove that right.

On the other hand, if you have scheduled backups that are running with the credentials of users in those groups or performing scheduled perfmon tasks doing the same, you would either modify those tasks to run under the system account, or note on the findings that you have system processes running that require those permissions because they are running under accounts that require those permissions. Another option is to note which accounts need this permission and grant it to them specifically or with a custom group and remove the default groups from that right.

Also, if you're not even *using* those groups (no users in either group), you can tell the auditors that those groups aren't in use and leave it at that. Having worked as a a DIACAP auditor I can tell you with complete confidence that the vast majority of DIACAP auditors don't know their own nose from a hole in the ground and don't check the configurations to make sure that a finding really is a finding. Sometimes you have to smack them with a rolled up newspaper and show them why the problem isn't a problem.
0
 
LVL 2

Author Closing Comment

by:BrianRB
ID: 37771538
Excellent info, thank you so much.
0
 
LVL 2

Author Comment

by:BrianRB
ID: 37771545
0

Featured Post

Backup Solution for AWS

Read about how CloudBerry Backup fully integrates your backups with Amazon S3 and Amazon Glacier to provide military-grade encryption and dramatically cut storage costs on any platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question