Search Tools Links Login

You cannot use the new Windows Server 2003 well-known security principals


When you promote a Windows Server 2003 computer to a domain controller, the Local Service, and other well-known security principals, do not appear, and cannot be used.



This behavior will occur when the forest root domain controller that holds the PDC emulator role is running Windows 2000 server.



NOTE: When the forest root domain controller that holds the PDC emulator role is running Windows 2000 server, the CN=WellKnown Security Principals,CN=Configuration,DC= container is not updated with the new well-known security principals.



To resolve this problem, update the PDC emulator to Windows Server 2003.



To workaround this problem, use SubInACL.exe to script the security on the well-known security principals:



subinacl /keyreg "" /grant="local service"=r



would grant the Local Service account Read permissions on the key.



Some of the well-known security principals that were introduced with Windows Server 2003 are:



Digest Authentication

Local Service

Network Service

NTLM Authentication

Other Organization

Remote Interactive Logon

SChannel Authentication

This Organization

About this post

Posted: 2005-11-1
By: FortyPoundHead
Viewed: 1,625 times

Categories

Attachments

No attachments for this post


Loading Comments ...

Comments

No comments have been added for this post.

You must be logged in to make a comment.