S
Steven Cheng[MSFT]
Hi Magdelin,
As for the questions you listed , here are my understanding on them:
1. Is it sufficient if the domain\hpac is granted SE_TCB_NAME privilege on
the application server Server2?
==========================
It's enough for impersonate and have better add it into admin group.
2. Should the domain\hpac account have SE_TCB_NAME privilege on the domain
controller so that it allows us to get the account authenticated from
Server2?
===============================
No, I don't think it necessary.
3. Is it sufficient if domain\hpac has SE_TCB_NAME privilege to impersonate
or does it also need SE_IMPERSONATE_PRIVILEGE?
===============================
Yes, it's enough. SE_IMPERSONATE_PRIVILEGE is unnecessary
4. Does domain\hpac get SE_IMPERSONATE_PRIVILEGE automatically when
SE_TCB_NAME privilege is granted? If no, how do we grant
SE_IMPERSONATE_PRIVILEGE explicitly to a user using the tool Local Security
Policies?
=========================================
Will consult to confirm.
5. Is SE_TCB_NAME privilege required on both Win 2K and Win 2003 servers
for authenticating a user with LogonUser API and impersonating a user using
WindowsImpersonateContext.Impersonate()?
==================================================
Yes, we have to grant this privilege.
Also, I'll consult some further experts on this and will let you know if
I've got any further infos. Thanks.
Regards,
Steven Cheng
Microsoft Online Support
Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)
Get Preview at ASP.NET whidbey
http://msdn.microsoft.com/asp.net/whidbey/default.aspx
As for the questions you listed , here are my understanding on them:
1. Is it sufficient if the domain\hpac is granted SE_TCB_NAME privilege on
the application server Server2?
==========================
It's enough for impersonate and have better add it into admin group.
2. Should the domain\hpac account have SE_TCB_NAME privilege on the domain
controller so that it allows us to get the account authenticated from
Server2?
===============================
No, I don't think it necessary.
3. Is it sufficient if domain\hpac has SE_TCB_NAME privilege to impersonate
or does it also need SE_IMPERSONATE_PRIVILEGE?
===============================
Yes, it's enough. SE_IMPERSONATE_PRIVILEGE is unnecessary
4. Does domain\hpac get SE_IMPERSONATE_PRIVILEGE automatically when
SE_TCB_NAME privilege is granted? If no, how do we grant
SE_IMPERSONATE_PRIVILEGE explicitly to a user using the tool Local Security
Policies?
=========================================
Will consult to confirm.
5. Is SE_TCB_NAME privilege required on both Win 2K and Win 2003 servers
for authenticating a user with LogonUser API and impersonating a user using
WindowsImpersonateContext.Impersonate()?
==================================================
Yes, we have to grant this privilege.
Also, I'll consult some further experts on this and will let you know if
I've got any further infos. Thanks.
Regards,
Steven Cheng
Microsoft Online Support
Get Secure! www.microsoft.com/security
(This posting is provided "AS IS", with no warranties, and confers no
rights.)
Get Preview at ASP.NET whidbey
http://msdn.microsoft.com/asp.net/whidbey/default.aspx