Gaz Posted November 23, 2016 Posted November 23, 2016 I need to make a service account for an external company but I've no idea how. I've looked at this guide on Microsofts website but I'm too stupid to follow it. https://technet.microsoft.com/en-us/library/dd548356(v=ws.10).aspx Does anyone have a better idiots guide in how to do this? These are the requirements they want me to provide them with. For user & machine auth I need a user account (service account) User name and password (password that will never expire) Bind DN of the user (EG [email protected]) Base DN of the users and machines (eg dc=mydomain,dc=me,dc=net)
Ric_ Posted November 23, 2016 Posted November 23, 2016 From your description, it sounds like you need an account for doing some kind of authentication lookup in AD. Basically, you should just need to create a user with just the domain users group. Then create a new group called service accounts (or similar) and add the user to this group. You then need to make a GPO that denies logon locally for that group (I found a handy guide at https://4sysops.com/archives/deny-and-allow-workstation-logons-with-group-policy/ which can describe it better than me).
Gaz Posted November 23, 2016 Author Posted November 23, 2016 Hi Ric, yeah that sounds exactly like what I need. They are an external company that are providing a managed Wi-Fi solution for a shared network. The Microsoft article makes it sound way more complicated than it should be. I guess a service account is just an account with restricted permissions in group policy?
Davit2005 Posted November 24, 2016 Posted November 24, 2016 Use a normal Domain User Account if the account just needs to be used for LDAP lookup/authentication should not need to be a domain admin. Do not make it any part of security groups that give permissions to anything else not needed i.e. Staff groups, Admin groups. You can try to limit where the account logs into on the account tab once you have tested that it works first. However if you are ever creating a service account for MDT to add computers to the domain etc never use a domain admin just delegate permissions on a specific OU. That article goes into depth too much for what you need.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now