> From: Tomasz Chmielewski [mailto:mangoo at wpkg.org] ... > > Are you sure that SYSTEM user uses computer account to access shares? > > Because as I tested it with Samba a year ago or so (and a workstation > > which has joined the domain), SYSTEM user "guest" account to access shares. > > s/SYSTEM user/SYSTEM used/ Yes, I am sure - as far as DFS (\\DOMAINNAME\dfs) is concerned. This is needed also for software packages assigned by AD Group policies. For other UNC paths (\\XYZ\ABC) it might look different. Maybe it can be adjusted by Group Policy. I don't have a proper reference, but just found some hints are here: http://www.microsoft.com/technet/security/guidance/serversecurity/serviceacc ount/sspgch02.mspx http://www.microsoft.com/technet/security/guidance/serversecurity/serviceacc ount/sspgch03.mspx The Local Service account would use anonymous credentials. Bye, Kai Pastor. |