Grant access to stop and start a service on an on premise domain controller without domain admin rights

Pat Reagan 106 Reputation points
2020-07-29T15:26:09.467+00:00

Due to a successful breach during a pen test by using the print spooler service on a domain controller, we are being challenged to stop/disable the print spooler service on all of our domain controllers. With the pruning responsibility of the print spooler on a domain controller for domain published printers, we would like to schedule a start and stop of the print spooler service on a DC using a scheduled task. We attempted to use the Local Service account to run the task, but it fails to start the service with no errors or warning in the logs. We need to complete this task as a non domain administrator. Any suggestions?

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,519 questions
0 comments No comments
{count} vote

Accepted answer
  1. Pat Reagan 106 Reputation points
    2020-07-30T18:13:11.997+00:00

    OK. So we used a GPO to set the service to manual, and deliver a a scheduled task, using System context to run the process. No account required to give access to the DC.

    Hope this helps someone else!

    Thanks

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Leon Laude 85,816 Reputation points
    2020-07-29T16:28:31.72+00:00

    Hi,

    Have you tried giving Windows service permissions to a domain account by using the SC.exe (Service controller) tool?

    How to Allow Non-Admin Users to Start/Stop Windows Service?
    http://woshub.com/set-permissions-on-windows-service/

    Best regards,
    Leon

    0 comments No comments

  2. Pat Reagan 106 Reputation points
    2020-07-29T16:58:14.897+00:00

    We have thought about this option. But don't know if changing the permissions for a service on a DC can cause issues since the service is used to interact with the domain. Or am I over thinking it?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.