具有本地管理员权限的用户 Windows Sharepoint 定时服务的网络服务权限

发布于 2024-07-08 00:49:26 字数 280 浏览 6 评论 0原文

是否可以创建一个同时具有本地管理员和NETWORK SERVICE权限的用户?

我有一个运行 stsadm 的 Sharepoint 计时器作业,它需要本地管理员权限。 另一方面,temer 作业也由需要 NETWORK SERVICE 权限的其他服务使用,并且权限集仅重叠,因此我需要一个具有权限“总和”的用户来运行 OWSTIMER。

(我知道您可以使用 stsadm 共享点管理 API 执行的大多数操作,在我的例子中,它是在内容数据库之间移动网站集的操作,而内容数据库似乎没有等效的 API)。

Is it possible to create a user with permissions of both a local administrator and NETWORK SERVICE?

I've got a Sharepoint timer job which runs stsadm for which it needs local administrator permissions. On the other hand temer jobs are also used by other services which need NETWORK SERVICE permissions and those to sets of permissions only overlap, so I need a user with the "sum" of the permissions to run OWSTIMER under.

(I know that most of the operations you can perform with stsadm sharepoint administration API can be used, by in my case it is the operation which moves a site collection between content databases for which there seems to be no API equivalent).

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(2

嘴硬脾气大 2024-07-15 00:49:26

我建议始终使用域帐户 - SharePoint 在连接到 Active Directory 服务器的服务器上运行效果最佳。 对于生产环境,最佳实践是使用最小权限帐户。 我总是创建以下专用于 SharePoint 服务的域帐户:

DOM\spservice

您无需向此帐户授予任何特殊权限,因为当您在设置期间指定帐户时,SharePoint 会自动为您执行此操作。

I recommend always using domain accounts - SharePoint works best on servers connected to an Active Directory server. For production environments a best practice is using a least privilege account. I always create the following domain account dedicated to SharePoint services:

DOM\spservice

You do not need to grant any special privileges to this account as SharePoint will automatically do this for you when you specify the account during setup.

猫腻 2024-07-15 00:49:26

我无法帮助您处理用户权限(拉尔斯指出了要点),但我想分享一些可能有用的信息。

您提到您正在尝试在内容数据库之间移动网站集,但尚未找到可以利用的 API。 您是否研究过 SharePoint 的内容部署 API(也称为 PRIME API)以查看它是否可以提供帮助? 我所说的类型位于 Microsoft.SharePoint.Deployment 命名空间中,它们为您提供了将网站集导出为 CAB 文件(通过 SPExport)的机制然后导入它们(通过SPImport)。

SharePoint 利用此命名空间中的类型来实现自己的内容部署路径和作业(在 MOSS 中); 它也是 STSADM.EXE 可执行文件用于导出 (STSADM.EXE -o export) 和补充导入操作的 API。 就此而言,SharePoint Designer 也使用它来进行网站“备份”和“恢复”操作。

有关如何利用此 API 的示例,请查看 CodePlex 上的 SharePoint 内容部署向导工具 (http:// www.codeplex.com/SPDeploymentWizard)。

我希望这为您提供了一个潜在的替代方案,可以在计时器工作中使用命令行!

I can't help you with the user permissions (Lars hit the important points), but I wanted to share some information that may be of use.

You mentioned that you're trying to move site collections between content databases and haven't found an API the can be leveraged. Have you looked into SharePoint's Content Deployment API (also know as the PRIME API) to see if it can assist? The types of which I'm speaking are located in the Microsoft.SharePoint.Deployment namespace, and they provide you with mechanisms to export (via SPExport) site collections as CAB files and then import them (via SPImport).

SharePoint leverages types in this namespace for its own content deployment paths and jobs (in MOSS); it's also the API that is leveraged by the STSADM.EXE executable for export (STSADM.EXE -o export) and complementary import operations. For that matter, it's also used by SharePoint Designer for it's site "backup" and "restore" operations.

For an example of how this API can be leveraged, check out the SharePoint Content Deployment Wizard tool on CodePlex (http://www.codeplex.com/SPDeploymentWizard).

I hope this gives you a potential alternative to shelling out to a command line in your timer job!

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文