Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Contact
  • Reviews
  • Toggle search form
Home » Windows Server » Merits and demerits of Local System Account and Service Logon Account
  • Docker Installation on Ubuntu
    Docker Engine Installation on Ubuntu Network | Monitoring
  • image 190
    Creating Profiles for your AWS Access Credentials for AWS Toolkit in Visual Studio AWS/Azure/OpenShift
  • BitLocker Recovery Password Rotation in Active Directory
    Perform BitLocker Recovery Password Rotation in Active Directory Windows Server
  • adfs training
    Post-Deployment of Active Directory Federation Service (ADFS) Windows Server
  • ddedw
    You require permission from trustedinstaller: How to delete or rename files protected by Trusted Installer Network | Monitoring
  • Prevent OS Reinstallation When Switching from Legacy BIOS to UEFI
    Prevent OS Reinstallation: Change from legacy BIOS to UEFI Windows
  • Featured image 1
    Transfer Windows License from one PC to the other on Windows Windows
  • How to Register Devices to Microsoft Intune and EntraID Using My Company Portal
    Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift

Merits and demerits of Local System Account and Service Logon Account

Posted on 31/07/201901/10/2023 Christian By Christian No Comments on Merits and demerits of Local System Account and Service Logon Account
What are the merits and demerits of Local System Account and Service Logon Account

Exploring the merits and demerits of the Local System Account is essential for effective computer system management. This account type has its own strengths and weaknesses, which impact system performance and security. By understanding these pros and cons, administrators can make better choices when setting up their computer systems.

For related guides see: Local System Account: Running Programs in Windows, Resolve Account restrictions are preventing this user from signing in. and Configure Local Administrators Account lockout.

Why use it?

One advantage of running your services using the Local System account is that the service has complete unrestricted access to local resources. And it is by default one of the built-in local accounts. The others are Local Service, Network Service.

One of the disadvantages of running services with Local System rights is that it can bring an entire system down. Especially a service running as Local System on a Domain Controller (DC) has unrestricted access to Active Directory Domain Services. This means that bugs in the service, or security attacks on the service, can damage the system.

Service Logon Accounts

Simply put, a Service Logon Account is an account that determines the security context it runs in. This is simply an alternative to using the built-in Local System Account which has access to the entire system resources.

Therefore, manually create a service account with limited access needed to run the service (i.e, the permissions it needs to access its resources).

Here are the advantages and disadvantages of using a service Logon Account:
– Advantage: You have total control over the account’s privileges rights), which you do not have control over when you use one of the built-in accounts.

– Disadvantage: This depends on your Domain or Local Group Policy, You will have to manually enter the passwords when they are changed or else these services will not run.

Note: These Service Logon Passwords cannot automatically be changed. But for the Local built-in Services, these automatic password changes is available.

I hope you found this blog post on the merits and demerits of Local System Account and Service Logon Account helpful. If you have any questions, please let me know in the comment session

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Active Directory, Microsoft Windows, Service Logon Account, Windows 10

Post navigation

Previous Post: How to create a bootable USB using Rufus on Windows
Next Post: How to Reset a Cisco 3650 Catalyst Switch

Related Posts

  • Windows 11 taskbar features remove 1
    How to modify Windows 11 Taskbar via Intune and GPO Windows
  • Screenshot 2020 07 28 at 15.34.51
    Nslookup unknown: Fix cannot find non-existent domain Windows Server
  • 1 kajkbmlyehn0inifwrh 8w
    How to install Kerberos packages with Cygwin on Windows Windows Server
  • OpenSSL on Windows
    How to Install OpenSSL on Windows Computers Windows
  • banner
    How to install and configure FSRM in Microsoft Windows Server Windows Server
  • ETWindows
    An Overview of Event Tracing for Windows Windows

More Related Articles

Windows 11 taskbar features remove 1 How to modify Windows 11 Taskbar via Intune and GPO Windows
Screenshot 2020 07 28 at 15.34.51 Nslookup unknown: Fix cannot find non-existent domain Windows Server
1 kajkbmlyehn0inifwrh 8w How to install Kerberos packages with Cygwin on Windows Windows Server
OpenSSL on Windows How to Install OpenSSL on Windows Computers Windows
banner How to install and configure FSRM in Microsoft Windows Server Windows Server
ETWindows An Overview of Event Tracing for Windows Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a
 
  • Docker Installation on Ubuntu
    Docker Engine Installation on Ubuntu Network | Monitoring
  • image 190
    Creating Profiles for your AWS Access Credentials for AWS Toolkit in Visual Studio AWS/Azure/OpenShift
  • BitLocker Recovery Password Rotation in Active Directory
    Perform BitLocker Recovery Password Rotation in Active Directory Windows Server
  • adfs training
    Post-Deployment of Active Directory Federation Service (ADFS) Windows Server
  • ddedw
    You require permission from trustedinstaller: How to delete or rename files protected by Trusted Installer Network | Monitoring
  • Prevent OS Reinstallation When Switching from Legacy BIOS to UEFI
    Prevent OS Reinstallation: Change from legacy BIOS to UEFI Windows
  • Featured image 1
    Transfer Windows License from one PC to the other on Windows Windows
  • How to Register Devices to Microsoft Intune and EntraID Using My Company Portal
    Register Devices to Intune and EntraID Using Company Portal AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,841 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.