Agent Reference Guide
...
Advanced Policy

Advance Policy for Windows Services

5 min

Windows services can be policed via Kron PAM. Local admin users can be restricted or normal users can have rights on the Windows services which needs administrator privileges. Policies can be written for a single user or user group over an agent or agent group.

  • To do that go to the Services section of Advance Policy Screen.
  • The click Add button.
Document image

  • Give a name for your Service Policy and choose the user or user group.
Advance Service Policy Config
Advance Service Policy Config


Service rule can be enabled or disabled, When it is disabled rule will be reverted.

  • Select the agent or agent groups.
Document image

  • Choose the policy according to needs. If a user is a local administrator, you can restrict its rights with remove + allow or add + deny. If the user isn't a local administrator, you can give right it with add + allow or remove + deny. Each type is supported.
Document image

  • Lastly, you need to choose the service name from the drop-down menu and save the configuration.
Advance Service Policy Config
Advance Service Policy Config


* While giving rights to Windows Services, sometimes we can have errors due to Windows default Service permissions. We may not apply to given rights on Windows Services. Please check the detailed logs.