Solved

Access Required to Read Windows Server 2012 Security Settings and User Permissions

Posted on 2016-09-14
2
37 Views
Last Modified: 2016-09-20
I want to create a service account that can connect to a Windows Server 2012 operating system and read the following:

- Users' permissions (Read, Write, etc.) to certain directories - not just for the service account but for ALL users;

- Log on settings like Password Length, Password Complexity, and Maximum Logon Failures.

It is really important for this service account to have as little access to change, delete, or create data as possible.  Ideally, It would be Read access.

What is the minimum access permissions the service account will need to be able to do this?

I am obviously not a Windows expert.  If the service account needs to be an Admin to do this, is there some way to restrict the access of an Admin account to disable its ability to change, delete, and create data on the Windows Server 2012 operating system
0
Comment
Question by:humbleamateur
2 Comments
 
LVL 35

Accepted Solution

by:
Mahesh earned 500 total points
ID: 41799533
are you using active directory?

If yes, you can get password complexity and length details from default domain policy (group policy)

If your server is workgroup server, not you can implement local security policy for password settings above

To read the permissions on all directories, you can export file \ folder permissions for analysis
for that you don't need special account, your admin can generate that report and provide to auditor guy

There are number of tools available on internet to export file \ folders security
Like, http://cjwdev.co.uk/Software/NtfsReports/Info.html
https://mywinsysadm.wordpress.com/2011/08/17/powershell-reporting-ntfs-permissions-of-windows-file-shares/

You may use Microsoft SubinACL tool also
https://blogs.technet.microsoft.com/justinturner/2009/02/26/quick-tip-back-up-your-ntfs-security-permissions/
0
 

Author Closing Comment

by:humbleamateur
ID: 41807066
Thanks so much!!!
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
In this Micro Tutorial viewers will learn how to use Windows Server Backup to create full image of their system. Tutorial shows how to install Windows Server Backup Feature on Windows 2012R2 and how to configure scheduled Bare Metal Recovery backup.…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

25 Experts available now in Live!

Get 1:1 Help Now