Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

group policy service restriction prolicy

Posted on 2013-05-26
11
Medium Priority
?
394 Views
Last Modified: 2013-07-15
Hi Experts,

In my environment, everyone is a local administrator and I want to prevent some of the essential services to be disabled by them. I tried to use the "system services" policy in computer configuration -> windows settings -> security settings but I found difficulties to know what permission i need to assign to a particular service. I tried to follow what I found in the service.msc to assign full control to system, local service and network service but still no luck, it caused services like event viewer, firewall, WMI to stop startup.

What i have setup is like this, e.g, windows firewall, i tried 2 different permission set:-

set 1:
1> remove local administrators group
2> add local service and give it full permission
3> keep the default system permission (full)
4> keep the default interactive permission (read)
5> add domain admins to have full permission

set 2:
1> keep local administrators group and remove the "start, stop, pause" permission
2> keep the default system permission (full)
3> keep the default interactive permission (read)
4> add domain admin to have full permission

anyone know how or what I can do to achieve my goal?
0
Comment
Question by:nokyplease
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 2
  • 2
  • +1
11 Comments
 
LVL 9

Expert Comment

by:jsdray
ID: 39197568
You're setting yourself up for a headache. ;)  Your best bet is to not give everyone local admin.  If they are trusted on their local machines, then let them kill what they want and deal with it.  If they are not trusted to stop certain services, then remove the user(s) from local admin.
0
 

Author Comment

by:nokyplease
ID: 39197573
I can't because they need the local admin rights and I know best to not give them this permission.....
0
 
LVL 56

Accepted Solution

by:
McKnife earned 2000 total points
ID: 39199879
Hi.

You found the right spot to modify the ACLs of the services. Grant the right to start the service to domain admins and remove (NOT deny) the "stop service" privilege from administrators - that's all.

But be aware that local admins stay local admins - if they wanted, they could free themselves of GPO restrictions for good.
0
 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

 
LVL 59

Expert Comment

by:LeeTutor
ID: 39264462
I've requested that this question be deleted for the following reason:

Not enough information to confirm an answer.
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39264463
0
 

Author Comment

by:nokyplease
ID: 39268390
i still have problem of some services failed to start after i changed a lot of service ACL in group policy by removing the stop permission of local admins. do i need to specify the local service and/or network service as well in the group policy?
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39269185
Ah, still there? :)
If you remove a stop permission, this will not result in anyone being able to start it.
Please quote the error on starting and also tell us what account is being used to start the service, account system or a user account?
0
 
LVL 59

Expert Comment

by:LeeTutor
ID: 39326353
I've requested that this question be deleted for the following reason:

Not enough information to confirm an answer.
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39326354
Hi LeeTutor.

I had objected already.
http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_28139284.html#a39199879 solves it as anyone can quickly verify. "
This is verifiable. If nokyplease ceases to respond, it is still verifiable as solution. Please do verify. As this is not nuclear physics but simple ACLs, the outcome is obvious. Stating "Not enough information to confirm an answer." makes me feel my efforts are being ignored, repeating it without further notice even ridicules them from my perspective.
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Here's a look at newsworthy articles and community happenings during the last month.
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question