Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-6384: Restrict Logger service privileges

Centrify DirectControl ,  

12 April,16 at 11:01 AM

Applies to:  Centrify DirectControl Suite 2016 (CDC 5.3)

Question: 

"C:\Program Files\Common Files\Centrify Shared\logger.exe" service account is running as NT Authority/SYSTEM.  What privilege does this process actually require and how can the service account be run with less privilege?

Answer:

At Startup time, the Logger service has already been removed from all the unnecessary high-level privileges.  These changes were made in Suite 2015 with the privileges included below:

The following privileges are removed:

• SeAssignPrimaryTokenPrivilege
• SeAuditPrivilege
• SeBackupPrivilege
• SeCreatePermanentPrivilege
• SeCreateTokenPrivilege
• SeDebugPrivilege
• SeEnableDelegationPrivilege
• SeLoadDriverPrivilege
• SeManageVolumePrivilege
• SeRestorePrivilege
• SeSecurityPrivilege
• SeSyncAgentPrivilege
• SeSystemEnvironment
• SeTakeOwnershipPrivilege
• SeTcbPrivilege, aka. “Act as part of the operating system.”
• SeShutdownPrivilege
 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.