Machine Account Can Access the Network. Why?


 this started when notice able sql server databases network shares on different servers even though sql server services logging in "local system", aka "nt authority\system". looked @ login information on destination machine while backup occurring , saw domain\mahinename$ accessing share. have done on @ least 2 separate servers, although servers in same domain.
i not understand why happening for two reasons. first, "local system" account not supposed able access network resources, , second, have not granted machine account access of shares have backed sql server. understanding of situation sql server must running under domain account in order have access network resources, , account must have thr proper rights on network resource in order use it.
the network admin here is stumped, , several people on various sql server forums stumped.

i ears ideas on situation. can post more information requested.

thanks,
chris

stamey,

  following msdn article quite clear: http://msdn.microsoft.com/en-us/library/ms684190.aspx

the relevant snippet follows:

"the localsystem account predefined local account used service control manager. account not recognized security subsystem, cannot specify name in call lookupaccountname function. has extensive privileges on local computer, and acts computer on network."

localsystem off box machine account.

andrew



Windows Server  >  Security



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file