This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Local Admin

We've recently had to remove the ARS svc account from the local admin of the server, but this causes the service account to fail with an access denied. If there a minimum amount of granular perms required to offset the need for a local admin? thanks!

Parents
  • @Terrance, fair enough - yes that is possible. Perhaps there is some security benefit in utilizing two accounts (I'd have to think harder upon it).

    Far more important in my opinion, and I'll mention it one last time since it is a GIGANTIC security hole that has/had existed for years within ARS until this methodology was released a version or two ago...

    support.software.dell.com/.../62472

    Without the above "fix", the server's registry holds the information as to the ARS administrator(s) and it is fully editable and in clear text, so it would not be extremely difficult for non-administrators to elevate themselves or other accounts to Domain Admins, i.e. by modifying the value, gaining complete control of the domain, and then doing whatever they wish. Anyway, I think OP should have plenty to think about by this point.  ;-)

Reply
  • @Terrance, fair enough - yes that is possible. Perhaps there is some security benefit in utilizing two accounts (I'd have to think harder upon it).

    Far more important in my opinion, and I'll mention it one last time since it is a GIGANTIC security hole that has/had existed for years within ARS until this methodology was released a version or two ago...

    support.software.dell.com/.../62472

    Without the above "fix", the server's registry holds the information as to the ARS administrator(s) and it is fully editable and in clear text, so it would not be extremely difficult for non-administrators to elevate themselves or other accounts to Domain Admins, i.e. by modifying the value, gaining complete control of the domain, and then doing whatever they wish. Anyway, I think OP should have plenty to think about by this point.  ;-)

Children
No Data