Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Database & SysAdmin
  3. System Admin
  4. Network privileges of localsystem account in Windows

Network privileges of localsystem account in Windows

Scheduled Pinned Locked Moved System Admin
sysadminquestion
8 Posts 2 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R Offline
    R Offline
    rana74
    wrote on last edited by
    #1

    Is there any difference in the privileges of the 'localsystem' account under XP,2000 and 2003 server? We are launching a browser from an INTERACTIVE windows service (running under 'localsystem' account),and make it navigate to a url. The url in turns redirects to another page. This navigation/redirection is allowed in 2000 and XP ;but fails in 2003. Is this a result of difference in network privileges for localsystem account?

    D 1 Reply Last reply
    0
    • R rana74

      Is there any difference in the privileges of the 'localsystem' account under XP,2000 and 2003 server? We are launching a browser from an INTERACTIVE windows service (running under 'localsystem' account),and make it navigate to a url. The url in turns redirects to another page. This navigation/redirection is allowed in 2000 and XP ;but fails in 2003. Is this a result of difference in network privileges for localsystem account?

      D Offline
      D Offline
      Dave Kreskowiak
      wrote on last edited by
      #2

      The LocalSystem account doesn't have network priv's. It also has it's own copy of the default IE configuration, which you CAN NOT CHANGE! Since Windows 2003 locks down IE access from the server to the otuside world, it's essentially crippled. You CAN NOT make any changes to it's configuration since you can not login as the LocalSystem account and change its settings. This should be done using other methods, not a browser control, and using an account setup specifically for your service without any interaction.

      Dave Kreskowiak Microsoft MVP - Visual Basic

      R 1 Reply Last reply
      0
      • D Dave Kreskowiak

        The LocalSystem account doesn't have network priv's. It also has it's own copy of the default IE configuration, which you CAN NOT CHANGE! Since Windows 2003 locks down IE access from the server to the otuside world, it's essentially crippled. You CAN NOT make any changes to it's configuration since you can not login as the LocalSystem account and change its settings. This should be done using other methods, not a browser control, and using an account setup specifically for your service without any interaction.

        Dave Kreskowiak Microsoft MVP - Visual Basic

        R Offline
        R Offline
        rana74
        wrote on last edited by
        #3

        Thanks a lot for the help Dave. Since this same code works for 2000 and XP - are these restrictions only applicable to 2003? Is it possible for you to send links to any relevant documentation on this - because there seems to a distinct lack of documentation in this area.

        D 1 Reply Last reply
        0
        • R rana74

          Thanks a lot for the help Dave. Since this same code works for 2000 and XP - are these restrictions only applicable to 2003? Is it possible for you to send links to any relevant documentation on this - because there seems to a distinct lack of documentation in this area.

          D Offline
          D Offline
          Dave Kreskowiak
          wrote on last edited by
          #4

          By default, on 2003 IE can't visit any web sites off the local machine. It's locked down very tightly. To find this out, all you have to do is logon locally to the servers console and launch IE yourself.

          Dave Kreskowiak Microsoft MVP - Visual Basic

          R 1 Reply Last reply
          0
          • D Dave Kreskowiak

            By default, on 2003 IE can't visit any web sites off the local machine. It's locked down very tightly. To find this out, all you have to do is logon locally to the servers console and launch IE yourself.

            Dave Kreskowiak Microsoft MVP - Visual Basic

            R Offline
            R Offline
            rana74
            wrote on last edited by
            #5

            Hi Dave, What did you mean by 'logon locally to the servers console' ? Is there some way possible to logon to a console with the 'localsystem' account privileges - to simulate the bhaviour?

            D 1 Reply Last reply
            0
            • R rana74

              Hi Dave, What did you mean by 'logon locally to the servers console' ? Is there some way possible to logon to a console with the 'localsystem' account privileges - to simulate the bhaviour?

              D Offline
              D Offline
              Dave Kreskowiak
              wrote on last edited by
              #6

              That means logon to the server at it's keyboard and mouse. As I already said, it's impossible to logon to the server using that account.

              Dave Kreskowiak Microsoft MVP - Visual Basic

              R 1 Reply Last reply
              0
              • D Dave Kreskowiak

                That means logon to the server at it's keyboard and mouse. As I already said, it's impossible to logon to the server using that account.

                Dave Kreskowiak Microsoft MVP - Visual Basic

                R Offline
                R Offline
                rana74
                wrote on last edited by
                #7

                Sorry for the misunderstanding Dave. Is there some write-up(or search terms) on the 2003 restrictions that you mentioned related to IE settings? I have searched a lot but do not find adequate documentation on the way 2003 'localsystem' locks IE up. Unfortunately,i would require some write-up to back me up on this arguement. It will be a great help - thanks again for your support.

                D 1 Reply Last reply
                0
                • R rana74

                  Sorry for the misunderstanding Dave. Is there some write-up(or search terms) on the 2003 restrictions that you mentioned related to IE settings? I have searched a lot but do not find adequate documentation on the way 2003 'localsystem' locks IE up. Unfortunately,i would require some write-up to back me up on this arguement. It will be a great help - thanks again for your support.

                  D Offline
                  D Offline
                  Dave Kreskowiak
                  wrote on last edited by
                  #8

                  I don't have anything on it. Your search can't find anything because you're focused on the LocalSystem account. Don't. Just search for the default locked down IE setup on 2003. At the very least, it's documented in the Windows Server 2003 Reosurce Kit.

                  Dave Kreskowiak Microsoft MVP - Visual Basic

                  1 Reply Last reply
                  0
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups