Restrict interactive logon on AD service accounts

61 views
Skip to first unread message

Max Coder

unread,
Jun 7, 2024, 5:24:59 PMJun 7
to ntsysadmin
Hi,


There is a service account that is a member of the domain admins group. We are trying to restrict our service accounts in AD to do interactive logon process for Domain Controller machines.  What is the best way to lock out the ability to use that account without affecting the purpose of a service account?

Can we safely check the "Deny log on locally" and "Deny log on through Terminal Services" tickbox in AD under Default Domain controller policy?

Aakash Shah

unread,
Jun 7, 2024, 8:48:18 PMJun 7
to ntsys...@googlegroups.com

You can add only the DCs into the “Log on to” field (under the Account tab) of the user. This will prevent this service account from being used from other computers that are not listed in the “Log on to” field.

 

-Aakash Shah

--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ntsysadmin+...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/ntsysadmin/00dadf80-1384-4e41-a6cf-1e4ba9df4378n%40googlegroups.com.

Charles F Sullivan

unread,
Jun 10, 2024, 11:48:14 AMJun 10
to ntsys...@googlegroups.com
This doesn't answer your question, but if the account only needs access to the DCs, you should make the account a member of <domain>\Administrators rather than <domain>\Domain Administrators. That way it narrows the computers to which it has Admin rights down to just the DCs.



--

Charlie Sullivan

Principal Windows Systems Administrator

Orlebeck, Geoffrey

unread,
Jun 11, 2024, 1:18:25 PMJun 11
to ntsys...@googlegroups.com

What is the service account doing that requires Domain Admin membership? Much of AD work can be delegated to a lower-level privilege, so would be curious on “the why” of the service account being a Domain Admin.

Reply all
Reply to author
Forward
0 new messages