Skip to main content

Notifications

Announcements

No record found.

Microsoft Dynamics CRM (Archived)

CRM Service Accounts Security Question (Network Service vs Domain accounts)

Posted on by

I have been reading and re-reading the CRM Deployment guide where it discusses how to set up the accounts that will run various CRM services.

"When you specify an identity to run a Microsoft Dynamics CRM service, you can choose either a domain user account or the Network Service account.

If the service interacts with network services, accesses domain resources like file shares or if it uses linked server connections to other computers, you can use a minimally-privileged domain account. Many server-to-server activities can be performed only with a domain user account and can provide the most secure option. This account should be pre-created by domain administration in your environment."

Is running the services under Network Service (in multi-server environment, CRM cluster, SQLAlwaysOn) totally insecure? Are the chances of hijacking a user account are less than hijacking Network Service Account?

If anything, is there a service that is 'strongly recommended' to run as a Domain Account?

Thanks in advance

Microsoft Dynamics CRM Sandbox Processing Service NT AUTHORITY\NETWORK SERVICE
Microsoft Dynamics CRM Asynchronous Processing Service NT AUTHORITY\NETWORK SERVICE
Microsoft Dynamics CRM Asynchronous Processing Service (maintenance) services NT AUTHORITY\NETWORK SERVICE
Microsoft Dynamics CRM Monitoring Service NT AUTHORITY\NETWORK SERVICE
Microsoft Dynamics CRM VSS Writer service NT AUTHORITY\NETWORK SERVICE

*This post is locked for comments

  • Suggested answer
    razdynamics Profile Picture
    razdynamics 17,304 User Group Leader on at
    RE: CRM Service Accounts Security Question (Network Service vs Domain accounts)

    Hi NYC,

    It is Best Practice and Highly recommend that you specify separate domain user accounts for these application pools instead of using the Network Service account and no other ASP.NET-connected application be installed under these application pools.You should really be setting up dedicated service accounts with the corresponding privileges, technet.microsoft.com/.../hh699825.aspx

    Also see;

    technet.microsoft.com/.../hh699761.aspx

    Best Wishes, Raz

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

December Spotlight Star - Muhammad Affan

Congratulations to a top community star!

Top 10 leaders for November!

Congratulations to our November super stars!

Tips for Writing Effective Suggested Answers

Best practices for providing successful forum answers ✍️

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 291,280 Super User 2024 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 230,214 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,156

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans