You are on page 1of 2

How To Configure Group Policies to Set Security for System Services in Windows Serve...

Page 1 of 2

Article ID: 324802 - Last Review: December 3, 2007 - Revision: 8.4


How To Configure Group Policies to Set Security for System Services in
Windows Server 2003

System Tip
This article applies to a different version of Windows than the one you are using. Content in this
article may not be relevant to you.Visit the Windows XP Solution Center

This article was previously published under Q324802

This article describes how to use Group Policy to set security for system services for
an organizational unit in Windows Server 2003.

When you implement security on system services, you can control who can manage
services on a workstation, member server, or domain controller. Currently, the only
way to change a system service is through a Group Policy computer setting.

If you implement Group Policy as the Default Domain Policy, the policy is applied to
all computers in the domain. If you implement Group Policy as the Default Domain
Controllers policy, the policy applies only to the servers in the domain controller's
organizational unit. You can create organizational units that contain workstation
computers to which policies can be applied. This article describes the steps to
implementing a Group Policy on an organizational unit to change permissions on
system services.

How to Assign System Service Permissions

1. Click Start, point to Administrative Tools, and then click Active


Directory Users and Computers.
2. Right-click the domain to which you want to add the organizational unit,
point to New, and then click Organizational Unit.
3. Type a name for the organizational unit in the Name box, and then click OK.

The new organizational unit is listed in the console tree.


4. Right-click the new organizational unit that you created, and then click
Properties.
5. Click the Group Policy tab, and then click New. Type a name for the new
Group Policy object (for example, use the name of the organizational unit for
which it is implemented), and then press ENTER.
6. Click the new Group Policy object in the Group Policy Objects Links list (if
it is not already selected), and then click Edit.
7. Expand Computer Configuration, expand Windows Settings, expand
Security Settings, and then click System Services.
8. In the right pane, double-click the service to which you want to apply
permissions.

The security policy setting for that specific service is displayed.


9. Click to select the Define this policy setting check box.

http://support.microsoft.com/kb/324802 4/7/2011
How To Configure Group Policies to Set Security for System Services in Windows Serve... Page 2 of 2

10. Click Edit Security.


11. Grant the appropriate permissions to the user accounts and groups that you
want, and then click OK.
12. Under Select service startup mode, click the startup mode option that you
want, and then click OK.
13. Close the Group Policy Object Editor, click OK, and then close the Active
Directory Users and Computers tool.

NOTE: You must move the computer accounts that you want to manage into the
organizational unit. After the computer accounts are contained in the organizational
unit, the authorized user or groups can manage the service.

APPLIES TO

Keywords:  kbmgmtservices kbacl kbenv kbgpo kbhowto kbhowtomaster


kbsecconfiged KB324802

Get Help Now


Contact a support professional by E-mail, Online, or Phone

Microsoft Support ©2011 Microsoft

http://support.microsoft.com/kb/324802 4/7/2011

You might also like