Disabling interactive logon for service accounts
ankurj.hazarika
Member Posts: 56 ■■□□□□□□□□
Team,
Why is it important to disable interactive logons for service accounts in a windows environment? Please help me understand.
Thanks.
Ankur
Why is it important to disable interactive logons for service accounts in a windows environment? Please help me understand.
Thanks.
Ankur
Comments
-
iBrokeIT Member Posts: 1,318 ■■■■■■■■■□So that someone with the service account credentials cannot use it to log into the desktop environment on a system as the service account user with escalated privileges.2019: GPEN | GCFE | GXPN | GICSP | CySA+
2020: GCIP | GCIA
2021: GRID | GDSA | Pentest+
2022: GMON | GDAT
2023: GREM | GSE | GCFA
WGU BS IT-NA | SANS Grad Cert: PT&EH | SANS Grad Cert: ICS Security | SANS Grad Cert: Cyber Defense Ops | SANS Grad Cert: Incident Response -
Lexluethar Member Posts: 516Bingo - you don't want someone to go behind the scenes and log into a server with a service account. If they could log in with the service account there would be no way of knowing exactly who actually made server changes.
Same concept as changing the default admin password and storing it away so no one logs in using it. -
gespenstern Member Posts: 1,243 ■■■■■■■■□□Probably won't help against hackers, just a measure for preventing IT personnel from using these accounts to log on and do regular stuff.
-
TheFORCE Member Posts: 2,297 ■■■■■■■■□□It's a method of hardening the system. Accounts should only be used for the reason they were created for, as such any rights that are not needed should be removed.