Thursday, May 17, 2018

Backup Operators are only special because of assigned privileges

One user wanted to know how to replicate the effect of the Backup Operators group on a Windows edition that doesn't have it. In their case, there was an easier solution: making the backup user a full administrator wasn't a problem. In other cases, a Backup Operators-like group can be created by assigning any group the following privileges in the Local Security Policy snap-in's User Rights Assignment section:

  • Back up files and directories
  • Log on as a batch job
  • Restore files and directories
  • Shut down the system
The most important privileges are the ability to back up and restore files and directories. Logging on as a batch job is useful for scheduled tasks; shutting down the system is just something server managers might need to do.

The NTRights utility can be used on systems without the Local Security Policy tool to assign SeBackupPrivilege, SeBatchLogonRight, SeRestorePrivilege, and SeShutdownPrivilege to the group.

No comments:

Post a Comment