Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I need to make a service account for an external company but I've no idea how.:rolleyes: I've looked at this guide on Microsofts website but I'm too stupid to follow it.

https://technet.microsoft.com/en-us/library/dd548356(v=ws.10).aspx

 

Does anyone have a better idiots guide in how to do this?

 

These are the requirements they want me to provide them with.

For user & machine auth

 

I need a user account (service account)

 

User name and password (password that will never expire)

 

Bind DN of the user (EG [email protected])

 

Base DN of the users and machines (eg dc=mydomain,dc=me,dc=net)

Posted
From your description, it sounds like you need an account for doing some kind of authentication lookup in AD. Basically, you should just need to create a user with just the domain users group. Then create a new group called service accounts (or similar) and add the user to this group. You then need to make a GPO that denies logon locally for that group (I found a handy guide at https://4sysops.com/archives/deny-and-allow-workstation-logons-with-group-policy/ which can describe it better than me).
Posted

Hi Ric, yeah that sounds exactly like what I need. They are an external company that are providing a managed Wi-Fi solution for a shared network.

 

The Microsoft article makes it sound way more complicated than it should be. I guess a service account is just an account with restricted permissions in group policy?

Posted

Use a normal Domain User Account if the account just needs to be used for LDAP lookup/authentication should not need to be a domain admin. Do not make it any part of security groups that give permissions to anything else not needed i.e. Staff groups, Admin groups.

 

You can try to limit where the account logs into on the account tab once you have tested that it works first.

 

However if you are ever creating a service account for MDT to add computers to the domain etc never use a domain admin just delegate permissions on a specific OU.

 

That article goes into depth too much for what you need.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...