Apply Service Hardening

Arellia has 2 built-in tasks to set security descriptors. The first is Set Restrictive Service Security Client Task and the second is Set Standard Service Security Client Task. For most customers, the default descriptors referenced in these tasks will accomplish what they are trying to do.

The Restrictive Service Security task will remove the ability for Administrator users to stop/modify a service. The Standard Service Security task will set the service security to the Windows default, where Administrator users can stop/modify a service.

To apply service security:

  1. Navigate to Tasks > Client Tasks > Local Security > Set Restrictive Service Security Client Task 
  2. (optional) Clone the client task
  3. Set the Service to the service you are targeting (ie. the Arellia Agent)
  4. (optional) Set the security descriptor the the manually created one
  5. Save the client task
  6. Select Run Now and execute the task on endpoints