Avatar of Se Lai
Se Lai
 asked on

Services Account Configuration

How the the service account configuration should be? Do we need to add the service account in administrators groups?
I think it should be only domain users with no password expiry and add it to ACT AS PART OF THE OPERATING SYSTEM in group policy. Let me know if there is any suggestion.

REgards
* permissionActive Directory

Avatar of undefined
Last Comment
Sean

8/22/2022 - Mon
Sean

What are you trying to accomplish with these? If it is just to run a program on a specific computer then I would add that service account as a local admin to that PC only and leave it as a standard user on the domain. If you are trying to use it to authenticate for LDAP querys then you don't need admin rights to do that so an standard user will work.

Only in an extreme case would I set a service account as an admin anywhere other than a local PC and be sure there is a policy to change that password often.

Any other account just set to never expire, generate a long cryptic password and document it and let it run.
Shaun Vermaak

  • Use managed service accounts whenever possible
  • Deny logon locally
  • Set User cannot change password and type password out for vendors (do not give them passwords)
  • Set maximum password (128 characters, use copy and paste) and do not reuse passwords
  • Never, ever give Domain Admin rights
  • Store passwords in vault
  • Always assign owner and give full descriptions
  • Follow proper naming-standard
Se Lai

ASKER
Thank you

Manage account mean? Can explain it little more
This is the best money I have ever spent. I cannot not tell you how many times these folks have saved my bacon. I learn so much from the contributors.
rwheeler23
SOLUTION
Don

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Se Lai

ASKER
I am trying to restrict all service accounts from domain rights. only allow them to able to run services... mean third party applications or exchange. SQL and so on.
ASKER CERTIFIED SOLUTION
Shaun Vermaak

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Sean

Best solutions.