12 Jun 2025 07:30 AM
Expecting some guidelines/recommendations for installing oneagents in domain controllers since running service with LocalSystem with give unrestricted access to AD services.
Extract from Microsoft documentation with respect to domain controllers
==================================================================================
In particular, a service running as LocalSystem on a domain controller (DC) has unrestricted access to Active Directory Domain Services. This means that bugs in the service, or security attacks on the service, can damage the system or, if the service is on a DC, damage the entire enterprise network.
==================================================================================
Reference Microsoft documentation -- https://learn.microsoft.com/en-us/windows/win32/ad/the-localsystem-account