Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows Server » Merits and demerits of Local System Account and Service Logon Account

Merits and demerits of Local System Account and Service Logon Account

Posted on 31/07/201901/10/2023 Christian By Christian No Comments on Merits and demerits of Local System Account and Service Logon Account
What are the merits and demerits of Local System Account and Service Logon Account

Exploring the merits and demerits of the Local System Account is essential for effective computer system management. This account type has its own strengths and weaknesses, which impact system performance and security. By understanding these pros and cons, administrators can make better choices when setting up their computer systems.

For related guides see: Local System Account: Running Programs in Windows, Resolve Account restrictions are preventing this user from signing in. and Configure Local Administrators Account lockout.

Why use it?

One advantage of running your services using the Local System account is that the service has complete unrestricted access to local resources. And it is by default one of the built-in local accounts. The others are Local Service, Network Service.

One of the disadvantages of running services with Local System rights is that it can bring an entire system down. Especially a service running as Local System on a Domain Controller (DC) has unrestricted access to Active Directory Domain Services. This means that bugs in the service, or security attacks on the service, can damage the system.

Service Logon Accounts

Simply put, a Service Logon Account is an account that determines the security context it runs in. This is simply an alternative to using the built-in Local System Account which has access to the entire system resources.

Therefore, manually create a service account with limited access needed to run the service (i.e, the permissions it needs to access its resources).

Here are the advantages and disadvantages of using a service Logon Account:
– Advantage: You have total control over the account’s privileges rights), which you do not have control over when you use one of the built-in accounts.

– Disadvantage: This depends on your Domain or Local Group Policy, You will have to manually enter the passwords when they are changed or else these services will not run.

Note: These Service Logon Passwords cannot automatically be changed. But for the Local built-in Services, these automatic password changes is available.

I hope you found this blog post on the merits and demerits of Local System Account and Service Logon Account helpful. If you have any questions, please let me know in the comment session

Rate this post

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows Server Tags:Active Directory, Microsoft Windows, Service Logon Account, Windows 10

Post navigation

Previous Post: How to create a bootable USB using Rufus on Windows
Next Post: How to Reset a Cisco 3650 Catalyst Switch

Related Posts

  • DC Name
    Install and configure Active Directory Domain Services on Windows Server Windows
  • connect to RDP automatically
    RDP Configuration Settings: Connect automatically to RDP session Windows
  • login keyboard feature
    Sign-In Method Not Allowed: Contact Network Administrator Windows Server
  • asdfgh
    All Group Policies (GPO) available to configure Microsoft Edge settings Windows Server
  • unnamed 1
    NSlookup Displays Error: UnKnown Default Server Windows Server
  • adac
    Enable Active Directory Recycle Bin: How to delete and restore objects using Active Directory Administrative Center Windows Server

More Related Articles

DC Name Install and configure Active Directory Domain Services on Windows Server Windows
connect to RDP automatically RDP Configuration Settings: Connect automatically to RDP session Windows
login keyboard feature Sign-In Method Not Allowed: Contact Network Administrator Windows Server
asdfgh All Group Policies (GPO) available to configure Microsoft Edge settings Windows Server
unnamed 1 NSlookup Displays Error: UnKnown Default Server Windows Server
adac Enable Active Directory Recycle Bin: How to delete and restore objects using Active Directory Administrative Center Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • SA
    How to Create Service Accounts, Organisation Units and Active Directory Security Groups Windows Server
  • Windows10 11
    Block Upgrade to Windows 11 via Group Policy or Registry Windows
  • ClamAV
    How to install and manage ClamAV and ClamTK on Ubuntu Linux Anti-Virus Solution
  • IAM AWS
    Creating IAM Users, Adding MFA and Policies on AWS AWS/Azure/OpenShift
  • Zit Error
    How to fix Domain Join Error during Windows Deployment Windows Server
  • Screenshot 1
    Using IBM Library with Veeam Network | Monitoring
  • Proxmox VM backup with VBR
    How to create a backup job for Proxmox VMs using VBR Backup
  • Screenshot 2020 12 30 at 01.03.14
    Device cannot use a Trusted Platform Module: Allow BitLocker without a compatible TPM Windows

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,808 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.