Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » Merits and demerits of Local System Account and Service Logon Account

Merits and demerits of Local System Account and Service Logon Account

Posted on 31/07/201901/10/2023 Christian By Christian No Comments on Merits and demerits of Local System Account and Service Logon Account
What are the merits and demerits of Local System Account and Service Logon Account

Exploring the merits and demerits of the Local System Account is essential for effective computer system management. This account type has its own strengths and weaknesses, which impact system performance and security. By understanding these pros and cons, administrators can make better choices when setting up their computer systems.

For related guides see: Local System Account: Running Programs in Windows, Resolve Account restrictions are preventing this user from signing in. and Configure Local Administrators Account lockout.

Why use it?

One advantage of running your services using the Local System account is that the service has complete unrestricted access to local resources. And it is by default one of the built-in local accounts. The others are Local Service, Network Service.

One of the disadvantages of running services with Local System rights is that it can bring an entire system down. Especially a service running as Local System on a Domain Controller (DC) has unrestricted access to Active Directory Domain Services. This means that bugs in the service, or security attacks on the service, can damage the system.

Service Logon Accounts

Simply put, a Service Logon Account is an account that determines the security context it runs in. This is simply an alternative to using the built-in Local System Account which has access to the entire system resources.

Therefore, manually create a service account with limited access needed to run the service (i.e, the permissions it needs to access its resources).

Here are the advantages and disadvantages of using a service Logon Account:
– Advantage: You have total control over the account’s privileges rights), which you do not have control over when you use one of the built-in accounts.

– Disadvantage: This depends on your Domain or Local Group Policy, You will have to manually enter the passwords when they are changed or else these services will not run.

Note: These Service Logon Passwords cannot automatically be changed. But for the Local built-in Services, these automatic password changes is available.

I hope you found this blog post on the merits and demerits of Local System Account and Service Logon Account helpful. If you have any questions, please let me know in the comment session

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Active Directory, Microsoft Windows, Service Logon Account, Windows 10

Post navigation

Previous Post: How to create a bootable USB using Rufus on Windows
Next Post: How to Reset a Cisco 3650 Catalyst Switch

Related Posts

  • CAL Removal
    How to Remove and Manage RDS Licenses Web Server
  • rdp4
    How to change the default RDP port in Windows Network | Monitoring
  • KMS server setup
    How to set up and configure the Key Management System (KMS) Windows Server
  • sid5
    How to Find Security Identifier on Windows [Part 2] Windows
  • FileZilla
    Access FTP Server from your browser: How to create a shortcut and access Filezilla from Windows Explorer Windows Server
  • Active Directory migration
    Migrate Active Directory Domain and Forest with Veeam Replica Backup

More Related Articles

CAL Removal How to Remove and Manage RDS Licenses Web Server
rdp4 How to change the default RDP port in Windows Network | Monitoring
KMS server setup How to set up and configure the Key Management System (KMS) Windows Server
sid5 How to Find Security Identifier on Windows [Part 2] Windows
FileZilla Access FTP Server from your browser: How to create a shortcut and access Filezilla from Windows Explorer Windows Server
Active Directory migration Migrate Active Directory Domain and Forest with Veeam Replica Backup

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • Veeam Plugin update for Proxmox
    Update Veeam Backup for Proxmox Plugin to support PVE 9.0 Backup
  • header picture 1
    Azure CI/CD: Configuring Email Notifications in Azure DevOps AWS/Azure/OpenShift
  • Simple Notification Service AWS SNS
    Create Simple Notification Service (SNS) Notification on AWS AWS/Azure/OpenShift
  • Could not load file or assembly
    Unable to edit MDT XML unattended file: Could not load file Windows Server
  • connect to RDP automatically
    RDP Configuration Settings: Connect automatically to RDP session Windows
  • Machine does not support XSAve
    How to disable side-channel mitigations on VMware Workstation Virtualization
  • Repository time shift detected
    Fix Repository time shift detected: Immutability flag cannot be set Backup
  • Snapshot
    Create or delete snapshots on VMware Workstation Backup

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,821 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.