service control delegation using GP

  • Thread starter Thread starter barabba
  • Start date Start date
B

barabba

Hello all,

I have the following problem:

I delegated the management of a particular service (not MS) using
Gropu Policy.
The trouble is, I only added the global group that includes the users
whom I am delegating the service control to and omitted to add the
system and administrators group accounts.

The result is that only this group can control the service while us,
domain admins, cannot touch it !
I then revised the policy and added system and administrators but
still I have no control whatsoever over it.
I tried to start and stop it using filemon and regmon to see where the
fault is but cannot see anything. Registry permissions seem fine...

Can anybody shed some light on how to restore correct permissions ?
Thanx
Bar
 
If you used a security group to name those who should control the service
instead of implicitly adding them one by one, then you could add Domain
Admins and other admin groups you wanted to control the service.

::plink, plink::

Ken
 
Back
Top