John,
The
easiest way to manage this IMHO, is the Security Configuration Toolset.
Load up MMC /A, add in Security Configuration and then choose the Services node
after selecting / creating a new database and doing the analysis. Set the
permissions on the services the way that you want / need them to be, then
configure the computer.
This
is the way that I typically do it, as I use teplates to define my baseline for
all systems (restricted groups, registry and file system settings, security,
etc) then build incremental templates that define a class or role for specific
server types, i.e Web Server, File / Print, etc.
Hope
this helps.
Rick Kingslan MCSE, MCSA, MCT
Microsoft MVP - Active Directory
Associate Expert
Expert Zone - www.microsoft.com/windowsxp/expertzone
Microsoft MVP - Active Directory
Associate Expert
Expert Zone - www.microsoft.com/windowsxp/expertzone
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of John F. Hann
Sent: Friday, February 14, 2003 9:56 PM
To: ActiveDir List
Subject: [ActiveDir] Security Priv over Services on a DCWhat/Where would I adjust the security to allow a group to start/stop services on a DC?Obviously, I would only do this for certain services, since this group will not have DA level access.John HannBancorpSouth662.678.7179
