fortypoundhead.com

You cannot use the new Windows Server 2003 well-known security principals

Posted On 2005-11-1 by FortyPoundHead
Keywords: Windows 2003 Security
Tags:  
Views: 1397


When you promote a Windows Server 2003 computer to a domain controller, the Local Service, and other well-known security principals, do not appear, and cannot be used.



This behavior will occur when the forest root domain controller that holds the PDC emulator role is running Windows 2000 server.



NOTE: When the forest root domain controller that holds the PDC emulator role is running Windows 2000 server, the CN=WellKnown Security Principals,CN=Configuration,DC= container is not updated with the new well-known security principals.



To resolve this problem, update the PDC emulator to Windows Server 2003.



To workaround this problem, use SubInACL.exe to script the security on the well-known security principals:



subinacl /keyreg "" /grant="local service"=r



would grant the Local Service account Read permissions on the key.



Some of the well-known security principals that were introduced with Windows Server 2003 are:



Digest Authentication

Local Service

Network Service

NTLM Authentication

Other Organization

Remote Interactive Logon

SChannel Authentication

This Organization


About the Author

FortyPoundHead has posted a total of 1974 articles.

 


Comments On This Post

No comments on this post yet!


Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:107.22.46.59

Before you can post, you need to prove you are human. If you log in, this test goes away.



Recent Forum Posts

List of Shady Characters
dwirch posted on April 25, 2017 at about 16:39 in Webmaster Stuff

Job Spammer: Bilal Uddin
dwirch posted on April 25, 2017 at about 11:00 in Spammers

Bug Fix: Contact Form Error
dwirch posted on April 21, 2017 at about 11:38 in Site News

Bug Fix: Ophion Time Tracker
dwirch posted on April 9, 2017 at about 11:30 in Site News

Job Spammer: Yogesh Kapadne
dwirch posted on March 31, 2017 at about 8:04 in Spammers

Job Spammer: Sathya Narayana
dwirch posted on March 15, 2017 at about 7:18 in Spammers