Mark,
Maybe
I'm being obtuse, but what leads you to believe that they don't exist
locally? Simply because there is no local SAM to create the account
in? The domain has an Administrator account, which resides in Active
Directory. Where would the IUSR and IWAM accounts reside if you install
IIS on a particular DC? It would reside in the Users container in AD, and
the name would be IUSR_<machine-name> and
IWAM_<machine-name>.
The
concern for installing SUS on a DC is because of the IIS requirements,
IMHO. IIS on a DC is a prelude to disaster. You might as well hang
out a 'Hackers welcome!" sign and not bother to lock down the
DC.
Rick Kingslan MCSE, MCSA, MCT
|
Title: Message
- [ActiveDir] OT: SUS on a W2K DC Abbiss, Mark
- RE: [ActiveDir] OT: SUS on a W2K DC Mulnick, Al
- RE: [ActiveDir] OT: SUS on a W2K DC Abbiss, Mark
- RE: [ActiveDir] OT: SUS on a W2K DC Kingslan, Rick T.
- RE: [ActiveDir] OT: SUS on a W2K DC Free, Bob