Configuring user access permissions to manage the Kaspersky Security Service
During installation, Kaspersky Industrial CyberSecurity for Nodes registers the application service - Kaspersky Security Service - in Windows. Thus, the application includes functional components that start at operating system startup. To reduce the risk of third-party access to application functionality and security settings of the protected device using the application service, you can restrict the permissions to manage the Kaspersky Security Service.
By default, access permissions for managing the Kaspersky Security Service are granted to users in the Administrators group on the protected device. Read permissions are granted to the SERVICE and INTERACTIVE groups, and read and execute permissions are granted to the SYSTEM group.
You cannot delete the SYSTEM user account or edit permissions for this account. If the permissions for the SYSTEM account are edited, the maximum privileges are restored for this account when you save the changes.
Users who have access to functions of the Edit permissions level can grant access permissions for managing the Kaspersky Security Service to other users registered on the protected device or included in the domain.
You can choose one of the following preset levels of access permissions for a user or group of users of Kaspersky Industrial CyberSecurity for Nodes for managing the Kaspersky Security Service:
- Full control: ability to view and edit general settings and user permissions for the Kaspersky Security Service, and to start and stop the Kaspersky Security Service.
- Read: ability to view Kaspersky Security Service general settings and user permissions.
- Edit: ability to view and edit Kaspersky Security Service general settings and user permissions.
- Execute: ability to start and stop the Kaspersky Security Service.
You can also configure advanced access permissions: allow or deny access to specific Kaspersky Industrial CyberSecurity for Nodes functions (see the table below).
Access permissions for Kaspersky Security Service functions
Feature
|
Description
|
Read service settings
|
Ability to view Kaspersky Security Service general settings and user permissions.
|
Request service status from Service Control Manager
|
Ability to request the execution status of the Kaspersky Security Service from the Microsoft Windows Service Control Manager.
|
Request service status
|
Ability to request the service execution status from the Kaspersky Security Service.
|
Read list of dependent services
|
Ability to view a list of services which the Kaspersky Security Service depends on and which depend on the Kaspersky Security Service.
|
Modify service settings
|
Ability to view and edit Kaspersky Security Service general settings and user permissions.
|
Start service
|
Ability to start the Kaspersky Security Service.
|
Stop service
|
Ability to stop the Kaspersky Security Service.
|
Pause / resume service
|
Ability to pause and resume the Kaspersky Security Service.
|
Read permissions
|
Ability to view the list of Kaspersky Security Service users and each user's access privileges.
|
Edit permissions
|
Ability to:
- Add and remove Kaspersky Security Service users.
- Edit user access permissions for the Kaspersky Security Service.
|
Remove service
|
Ability to unregister the Kaspersky Security Service in the Microsoft Windows Service Control Manager.
|
User defined requests to service
|
Ability to create and send user requests to the Kaspersky Security Service.
|
You can edit the list of users and user groups allowed to manage the Kaspersky Security Service, and also edit the access permissions of those users and user groups.
How to configure user permissions to manage the Kaspersky Security Service in the Kaspersky Security Center Administration Console
- In the Kaspersky Security Center Administration Console tree, select the Policies folder.
- Select the necessary policy and double-click to open the policy properties.
- In the policy properties window, select Supplementary.
- In the User access permissions for Kaspersky Security Service management section, click Settings.
This opens the form for configuring user access permissions.
- Add an Active Directory user or group for which you want to configure Kaspersky Security Service user permissions.
- Select a user or group of users to which you want to grant access to managing the application.
- In the list of permissions, configure user permissions to manage the Kaspersky Security Service.
- If necessary, configure special permissions for users:
- Click Additional.
- This opens a window; in that window, select a user account.
- Double-click to open the user account properties.
- This opens a window; in that window, click the Show additional permissions link.
- This opens a window; in that window, configure special permissions for the user.
- Save your changes. To apply the policy on computers, close the locks
.
How to configure user permissions to manage the Kaspersky Security Service in the Application Console
- In the Application Console tree, select the Kaspersky Industrial CyberSecurity for Nodes node and select User access permissions for Kaspersky Security Service management from the context menu of the node.
- In the window that opens, in the Permissions block, click the Add button.
This opens the form for configuring user access permissions.
- Add an Active Directory user or group for which you want to configure Kaspersky Security Service user permissions.
- Select a user or group of users to which you want to grant access to managing the application.
- In the list of permissions, configure user permissions to manage the Kaspersky Security Service.
- If necessary, configure special permissions for users:
- Click Additional.
- This opens a window; in that window, select a user account.
- Double-click to open the user account properties.
- This opens a window; in that window, click the Show additional permissions link.
- This opens a window; in that window, configure special permissions for the user.
- Save your changes.
How to configure user permissions to manage the Kaspersky Security Service in the Kaspersky Security Center Web Console
- In the main window of the Web Console, select Assets (Devices) → Policies & profiles.
- Click the name of the Kaspersky Industrial CyberSecurity for Nodes policy.
The policy properties window opens.
- Select the Application settings tab.
- Go to Supplementary → User access permissions for Kaspersky Security Service management and click the Configure button.
The User access permissions for Kaspersky Security Service management window opens.
- Add an Active Directory user or group for which you want to configure Kaspersky Security Service user permissions.
- Select a user or group of users to which you want to grant access to managing the application.
You cannot configure special permissions to manage the application service in the Web Console.
- Save your changes. To apply the policy on computers, close the locks
.
Page top