AddIPAddress / DeleteIPAddress和Permissions [英] AddIPAddress/ DeleteIPAddress and Permissions

查看:241
本文介绍了AddIPAddress / DeleteIPAddress和Permissions的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

您好,

我正在使用Windows服务中的AddIPAddress和DeleteIPAddress方法。



要使用这些API,我需要这项服务从本地系统帐户登录,这是我想要避免的。



还有另一种方法吗?



谢谢!

解决方案

想象一下: -



受限用户可以成为Network Configuration Operators组的成员。



网络配置操作员该组的成员可以更改TCP / IP设置,他​​们可以更新和释放TCP / IP地址。该组没有默认成员。 •并且没有默认用户权限



这样,服务不会以更高的权限运行,但仍然可以执行与网络配置相关的任务。



以下链接有详细信息: -

https://technet.microsoft.com/en-us/library/cc771990.aspx

https://support.microsoft.com/en-us/kb/297938

https://technet.microsoft.com/en-us/library/cc754921(v=ws.10)的.aspx

Hello,
I am using AddIPAddress and DeleteIPAddress methods from a windows Service.

To use these APIs, I need the service to Logon from the "Local System" account which is something I want to avoid.

Is there another way of doing this?

Thanks!

解决方案

Figured this:-

The restricted user can be made a member of the Network Configuration Operators group.

Network Configuration Operators Members of this group can make changes to TCP/IP settings, and they can renew and release TCP/IP addresses. This group has no default members. • and No default user rights

This way the service doesn't run with higher privileges but can still do network configuration related tasks.

Following links have details on this:-
https://technet.microsoft.com/en-us/library/cc771990.aspx
https://support.microsoft.com/en-us/kb/297938
https://technet.microsoft.com/en-us/library/cc754921(v=ws.10).aspx


这篇关于AddIPAddress / DeleteIPAddress和Permissions的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆