Jump to content

Stopping Windows Services Being Disabled By My Users???


Recommended Posts

Hi Dave,

Are you looking for Local System Security Policy or Domain Security Policy? If it is for Local System, then only option is to remove those particular users from Administrator Group. And if it is for the Domain, then you can configure Group Policy for an OU and add those user in that particular OU to restrict them. :flowers:

Link to comment
Share on other sites

Hi Dave,

Are you looking for Local System Security Policy or Domain Security Policy? If it is for Local System, then only option is to remove those particular users from Administrator Group. And if it is for the Domain, then you can configure Group Policy for an OU and add those user in that particular OU to restrict them. :flowers:

All the PC's are in a member of a domain so I could apply a group policy to the machines...

What part of the policy would I need to configure?

Regards

DAve

Link to comment
Share on other sites

Ok Dave,

I have got simplest solution, it will surely help you. You will need to login to the System, where you want to apply Services restriction for certain group,

i) Create one OU, add those users to whom you want to restrict the services.msc access in that.

ii) Go to C:\windows\system32\services.msc. Right Click this file>Property>Security. Under Security Tab, Add that domain group and Deny that group from accessing the file. And allow Your login to access this file.

iii) Do not remove 'SYSTEM' users rights to access this file.

:flowers:

Link to comment
Share on other sites

Ok Dave,

I have got simplest solution, it will surely help you. You will need to login to the System, where you want to apply Services restriction for certain group,

i) Create one OU, add those users to whom you want to restrict the services.msc access in that.

ii) Go to C:\windows\system32\services.msc. Right Click this file>Property>Security. Under Security Tab, Add that domain group and Deny that group from accessing the file. And allow Your login to access this file.

iii) Do not remove 'SYSTEM' users rights to access this file.

:flowers:

Ah I see what you are getting at - litterally deny ntfs permissions to the services mmc....

Link to comment
Share on other sites

Hi,
Ah I see what you are getting at - litterally deny ntfs permissions to the services mmc....

Hope this has resolved your problem! :flowers:

Its a very good suggestion but I would like to see someway of deny a user to stop an individual service.

We use McAfee for our AV and that has the option to stop users from stopping the service, I thought they would just leverage some type of configuration from within windows...

Regards

Dave

Link to comment
Share on other sites

Hi Dave,

As we can restrict services.msc for particular user group. In the same way, we can restrict each process. You will need to open services.msc, there you will need to check each service path in its property page. Go to that path, Right Click the file>Property>Security. Under Security Tab, Add that domain group and Deny that group from accessing the file. And allow Your login to access this file. Same as before. :)

:flowers:

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy