Services Account Configuration

Se Lai
Se Lai used Ask the Experts™
on
How the the service account configuration should be? Do we need to add the service account in administrators groups?
I think it should be only domain users with no password expiry and add it to ACT AS PART OF THE OPERATING SYSTEM in group policy. Let me know if there is any suggestion.

REgards
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
SeanSystem Engineer

Commented:
What are you trying to accomplish with these? If it is just to run a program on a specific computer then I would add that service account as a local admin to that PC only and leave it as a standard user on the domain. If you are trying to use it to authenticate for LDAP querys then you don't need admin rights to do that so an standard user will work.

Only in an extreme case would I set a service account as an admin anywhere other than a local PC and be sure there is a policy to change that password often.

Any other account just set to never expire, generate a long cryptic password and document it and let it run.
Shaun VermaakSenior Consultant
Awarded 2017
Distinguished Expert 2018

Commented:
  • Use managed service accounts whenever possible
  • Deny logon locally
  • Set User cannot change password and type password out for vendors (do not give them passwords)
  • Set maximum password (128 characters, use copy and paste) and do not reuse passwords
  • Never, ever give Domain Admin rights
  • Store passwords in vault
  • Always assign owner and give full descriptions
  • Follow proper naming-standard
Se LaiSystem Administrator

Author

Commented:
Thank you

Manage account mean? Can explain it little more
DonNetwork Administrator
Commented:
Se LaiSystem Administrator

Author

Commented:
I am trying to restrict all service accounts from domain rights. only allow them to able to run services... mean third party applications or exchange. SQL and so on.
Senior Consultant
Awarded 2017
Distinguished Expert 2018
Commented:
Was still editing...

SeanSystem Engineer

Commented:
Best solutions.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial