How To: Disable Interactive Logon for a Service Account

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to prevent a SecureAuth service account from logging on interactively, using Group Policy.

    Service accounts usually carry additional permissions that let them do work a normal user account is not allowed to do. Corporate security policy commonly requires that this kind of privileged service account not be allowed to log on interactively, so that the elevated permissions cannot be used directly from an interactive session.

     

    Disable Interactive Logon for a Service Account

    1. Open the Group Policy Object (GPO) that applies to the service account — either a local GPO on the server, or a domain-wide GPO, depending on how the account should be restricted.
    2. Go to Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment.
    3. Add the service account to the Deny log on locally policy.
    4. Add the service account to the Deny log on through Remote Desktop Services policy.

    Local Group Policy Editor showing User Rights Assignment, with the Deny log on locally and Deny log on through Remote Desktop Services policies both set to include the service account.

     
     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.