Windows Server - System service and UAC

Asked By Phil Sanderson
20-Nov-09 08:13 AM
Hi, we are producing a system service for Windows Server 2008.  One of the
tasks of the service is to create a user and a group.  The service runs as a
minimally-privileged user created on installation.  This service user is
added to the Power Users group, as specified in the documentation for,  say,
NetLocalGroupAdd.  The service's executable also has a manifest with
and we get ERROR_ACCESS_DENIED (5) returned by NetLocalGroupAdd.  The  server
is free-standing (i.e. not a member or controller of a domain).

What am I missing?  I can understand membership of Power Users not being
enough, but what about the evelation requested by the manifest?  UAC is
configured to prompt for credentials when a user requires elevation, but how
does that work when the application is a non-interactive system service?
Should we just run the service as LocalSystem and impersonate the
lower-privileged user?

I'd be very grateful for any assistance, thank you.
Windows Server 2008
(1)
Windows Installer
(1)
LocalSystem
(1)
RequireAdministrator
(1)
UAC
(1)
  Wilson, Phil replied to Phil Sanderson
20-Nov-09 12:51 PM
A service is not going to be prompting for credentials on UAC systems.
They're denied access to the desktop. Running as system and impersonating
seems like the way to go when required.
--
Phil Wilson
The Definitive Guide to Windows Installer
http://www.apress.com/book/view/1590592972
Create New Account
help
Windows Server 2008, Intel Xenon 7500 series SQL Server 2008? Windows Server What challenges will the Intel Xeon 7500 series together with Windows Server 2008 R2 and SQL Server 2008 R2 help address for my business? Windows Server
Windows server 2008 registry value for MaxUserPort Windows Server What is the equalvilent registry value for MaxUserPort (which is considered in Windows Server 2003) under Windows Server 2008? Windows Server Discussions Windows Server (1) MaxUserPort (1) Vista (1) Windows (1) WS
Functional Level Windows Server Can a domain that is built using purely Windows Server 2008 R2 DC's be rolled back to Windows Server 2008? No Recycle Bin. Windows Server Active Directory Discussions Windows Server 2008 R2 (1) Windows Server
Windows Server 2008 R2 Windows Server Windows Server 2008 R2 and Windows 7 share the same code? how is that possible when Windows 7
sending mails in windows server 2008 Windows Server Hi Does windows server 2008 accepts outlook express?if yes where can i download it?if not what is the