Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Access Required to Read Windows Server 2012 Security Settings and User Permissions

Posted on 2016-09-14
2
Medium Priority
?
71 Views
Last Modified: 2016-09-20
I want to create a service account that can connect to a Windows Server 2012 operating system and read the following:

- Users' permissions (Read, Write, etc.) to certain directories - not just for the service account but for ALL users;

- Log on settings like Password Length, Password Complexity, and Maximum Logon Failures.

It is really important for this service account to have as little access to change, delete, or create data as possible.  Ideally, It would be Read access.

What is the minimum access permissions the service account will need to be able to do this?

I am obviously not a Windows expert.  If the service account needs to be an Admin to do this, is there some way to restrict the access of an Admin account to disable its ability to change, delete, and create data on the Windows Server 2012 operating system
0
Comment
Question by:humbleamateur
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 38

Accepted Solution

by:
Mahesh earned 2000 total points
ID: 41799533
are you using active directory?

If yes, you can get password complexity and length details from default domain policy (group policy)

If your server is workgroup server, not you can implement local security policy for password settings above

To read the permissions on all directories, you can export file \ folder permissions for analysis
for that you don't need special account, your admin can generate that report and provide to auditor guy

There are number of tools available on internet to export file \ folders security
Like, http://cjwdev.co.uk/Software/NtfsReports/Info.html
https://mywinsysadm.wordpress.com/2011/08/17/powershell-reporting-ntfs-permissions-of-windows-file-shares/

You may use Microsoft SubinACL tool also
https://blogs.technet.microsoft.com/justinturner/2009/02/26/quick-tip-back-up-your-ntfs-security-permissions/
0
 

Author Closing Comment

by:humbleamateur
ID: 41807066
Thanks so much!!!
0

Featured Post

Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
This tutorial will walk an individual through the process of configuring basic necessities in order to use the 2010 version of Data Protection Manager. These include storage, agents, and protection jobs. Launch Data Protection Manager from the deskt…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

609 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question