Active Directory Certificate Services - run the service using a domain service account


hello,

is possible have service "active directory certificate services" runing using domain account instead of "local system account"?
if so, what's configuration needed for (for eg. : make ad account member of local administrator group, gpo : "log on service", "replace process level token" ...) ?

thanks in advance !

hi,

in theory, it’s possible. however, there no official document guide operation. may need change many permission settings work , these changes may affect system security, it’s not suggested , not worth so.

thanks.


this posting provided "as is" no warranties, , confers no rights.


Windows Server  >  Directory Services



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client