Discussion:
How to allow my domain user to start/stop service action in their computer?
(too old to reply)
choipo
2007-05-12 20:18:30 UTC
Permalink
is it possible to allow domain user to perform "start/stop service" action
in their computer?
how ?

Thanks
Herb Martin
2007-05-12 22:31:37 UTC
Permalink
Post by choipo
is it possible to allow domain user to perform "start/stop service" action
in their computer? how ?
Add the user to the local administrations group OR delegate
specific services to that user perhaps with a GPO.
AJ
2007-05-13 09:18:17 UTC
Permalink
Post by Herb Martin
Post by choipo
is it possible to allow domain user to perform "start/stop service" action
in their computer? how ?
Add the user to the local administrations group OR delegate
specific services to that user perhaps with a GPO.
Yes you can achieve that. If you do NOT want the users to be Local
Admins on the boxes, then use System Services group policy and define
the permissions for Domain Users if you want.

Note: If you are running some third party services on the machines,
then opening group policy on the DC would NOT list those services..
What to do then ?? :-) Install GPMC on a machine that has the third
party service and then if you browse to system services then you can
see the services and apply the permissions!!

~Cheers,

Ajay Sarkaria
Jeremy
2007-05-13 09:58:33 UTC
Permalink
You can do this using the "System Services" part of a GPO.

If you open up GPO you can see under: Computer Configuration -> System
Services. These will all say "Not Defined" under both the Startup and
Permission columns. If the service on the target system isn't listed you
will have to edit the policy from the system where it is installed in order
to see it.

To grant a user the right to start and stop a particular service then you
must double click on it and define the Startup type. You can't delegate the
permissions without doing this (odd, I agree). If you click OK now, without
clicking on "Edit Security" you will now see that the setting reflected in
the Startup column while the Permission column will still say "Not Defined"

Go in again and click on "Edit Security". As you will see, one of the
permissions here is "Start, stop pause". This is how you do it.

Now a word of warning. When you click on "Edit Security" the entries here
*don't* reflect the current permission settings on that particular service.

For example using the "Security Configuration and Analysis" MMC snap-in I
can see that the following permissions are set on the "Application
Management" service:

Authenticated Users: Special
Administrators: Full Control
Users: Special
INTERACTIVE: Special

These permission include the ability for users logged on Interactively to
start the service.

If you open this same service under a GPO and click Edit Security then click
OK, without making any changes, these entries will *replace* the default
settings rendering users unable to install GPO assigned or published
applications.

So, to cut a long story short, make sure you include the default permissions
for built-in services in your policy in addition to the users whom you want
to grant the rights to.

HTH.

Cheers,
Jeremy
Post by choipo
is it possible to allow domain user to perform "start/stop service" action
in their computer?
how ?
Thanks
Continue reading on narkive:
Loading...