Domain User Service Account
This replication enables the user to quickly and easily log on from any part of the domain.
Domain user service account. Thus you can try the third method to modify the registry. The service has whatever local and network access is granted to the account or to any groups of which the account is a member. Many server to server activities can be performed only with a domain user account. Passwords are managed and reset automatically.
A managed service account provides the same benefits of using a domain user account with these improvements. Does anyone know what would be the minimum rights i would need to grant to a domain user account in order to run a windows service as that user. No network access no custom event logs etc. When the domain is running at the windows server 2008 r2 functional level the service principal name spn doesn t need to be managed as with local accounts.
For simplicity assume that the service does nothing over and above starting stopping and writing to the application event log i e. Active directory managed service accounts are similar to domain user accounts but the password is reset regularly and automatically. The service can support kerberos mutual authentication. If the service must interact with network services access domain resources like file shares or if it uses linked server connections to other computers running sql server you might use a minimally privileged domain account.
With active directory managed service accounts you can only assign one user account per computer and each account can be used with multiple services on the computer. A domain user account enables the service to take full advantage of the service security features of windows and microsoft active directory domain services.