80
Secondary Logon
Service Name
Member Server
Default
Legacy Client
Enterprise Client High Security Client
seclogon Automatic Disabled Disabled Disabled
Important:
The
Secondary Logon
system service should be set to
Automatic
on HP NAS server systems
having 3
rd
party applications that execute functions using a secondary user or group account.
The
Secondary Logon
system service allows the user to create processes in the context of different
security principals. Restricted users commonly use this service to log on as a user with elevated
privileges for temporarily running administrative programs. This service enables users to start
processes under alternate credentials. These features are not required in the baseline server
environment. While this service is beneficial on client computers, it is not appropriate on most servers
because users logging onto them interactively will be members of the IT team performing some sort of
maintenance tasks that typically require administrative privileges. Therefore, this service is configured
to
Disabled
in the three environments defined in this guide.
Security Accounts Manager
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
SamSs Automatic Automatic Automatic Automatic
The
Security Accounts Manager
(SAM) system service is a protected subsystem that manages user and
group account information. In Windows 2000 and the Windows Server 2003 family, the SAM in the
local computer registry stores workstation security accounts and domain controller accounts are stored
in Active Directory. This service should not be disabled.
Server
Service
Name
Member Server
Default
Legacy Client
Enterprise Client
High Security Client
lanmanserver Automatic
Automatic Automatic Automatic
The
Server
system service provides RPC support, file, print, and named pipe sharing over the network.
For these reasons, it is recommended to set the value for this service to
Automatic
in the three
environments defined in this guide.
Shell Hardware Detection
Service Name
Member Server
Default
Legacy Client
Enterprise Client High Security Client
ShellHWDetection Automatic
Disabled Disabled Disabled
The
Shell Hardware Detection system
service monitors and provides notification for AutoPlay
hardware events. This service is not a requirement for the baseline server policy. Therefore, this
service is configured to
Disabled
in the three environments defined in this guide.