Windows Command #46 – sc qprivs (Windows OS)

Terminal-focused Windows service privileges query on a workstation inside an industrial server room.

sc.exe qprivs queries the required-privileges configuration for a Windows service. It is a read-only Service Control Manager command: it shows which Windows privileges a service declares that it needs when its process starts, without changing the service.

This continues the Service Control Manager sequence after Windows Command #45 – sc qfailureflag. The command that changes this setting is sc.exe privs; this lesson focuses only on inspecting the current configuration safely.

What required privileges mean

Windows services run inside a security context. That account may possess many operating-system privileges, but Windows Service Hardening lets a service declare a smaller required set. When that list is configured, the Service Control Manager removes privileges that the service did not request from the process token when the process starts. This reduces the power available to the service if it is compromised.

Windows Group Policy Management Editor open to Security Settings and User Rights Assignment.
Windows exposes many system privileges and user rights through its security policy tools. A service’s required-privilege list is a separate Service Control Manager configuration that can further reduce its process token. Source: Microsoft Learn.

Basic syntax

sc.exe qprivs SERVICE_NAME

Replace SERVICE_NAME with the service name, not necessarily the friendly display name. For a disposable example service:

sc.exe qprivs DemoService

A successful query can return privilege names such as SeImpersonatePrivilege, SeCreateGlobalPrivilege, or SeIncreaseWorkingSetPrivilege. The exact list depends on the service. Do not assume that every service should have the same privileges.

This Windows service-account hardening discussion focuses on reducing the attack surface created by excessive service privileges.

An empty list does not mean no privileges

This is the most important interpretation rule. Microsoft documents that if no required-privilege list is configured, the Service Control Manager uses the privileges normally available to the service process token. In other words, an empty qprivs result can mean that no privilege-reduction list has been configured—not that the service runs with zero privileges.

For compatibility, SeChangeNotifyPrivilege is never removed from a service process token by this mechanism, even when it is not explicitly listed.

Shared-process services need extra care

Many Windows services share a host process such as svchost.exe. When multiple services share one process, Windows computes the union of the privileges required by every service in that process. One service can therefore cause a privilege to remain available to the shared process even when another service does not request it.

This is why qprivs should be interpreted alongside the service type and hosting model. Use sc.exe qc SERVICE_NAME and sc.exe queryex SERVICE_NAME when you need more context about configuration and process identity.

Query a remote system

sc.exe \\SERVER01 qprivs DemoService

Remote queries require network connectivity and sufficient Service Control Manager permissions on the target computer. An access-denied response means the query was not authorized; it does not prove that the service has no required-privilege configuration.

Why this matters for security

Privileges are powerful operating-system capabilities. Some allow a process to impersonate another security context, back up protected data, restore files, change system time, or perform other sensitive operations. A service that does not need a capability should not retain it merely because the underlying account has it.

The goal is least privilege: enough rights for the service to function, but no more. qprivs gives administrators a fast way to audit the configured list before making changes.

Related social discussion: r/sysadmin discussion on Windows privilege requirements, including SeTcbPrivilege, SeIncreaseQuotaPrivilege, and SeAssignPrimaryTokenPrivilege.

Do not change service privileges casually

qprivs is safe because it only reads configuration. The companion sc.exe privs command changes the required-privilege list and can prevent a service from working if a needed privilege is removed. Microsoft explicitly recommends determining the minimum required set and testing changes thoroughly in an isolated environment.

Required privileges also cannot magically grant a service rights that its configured account does not possess. The mechanism is designed to reduce available privileges, not to elevate the account.

Useful verification commands

  • sc.exe qprivs SERVICE_NAME — read the required-privilege list.
  • sc.exe qc SERVICE_NAME — inspect the service configuration and account.
  • sc.exe queryex SERVICE_NAME — inspect status plus process information.
  • sc.exe qsidtype SERVICE_NAME — inspect the service SID type.
  • whoami /priv — inspect privileges in the current interactive process token; this is not the same as the service’s configured required-privilege list.

Practice lab

  1. Open an elevated Command Prompt on a lab Windows system.
  2. Choose a noncritical service and record its service name.
  3. Run sc.exe qc SERVICE_NAME and note the service account and process type.
  4. Run sc.exe qprivs SERVICE_NAME and record the output exactly.
  5. If the list is empty, explain why that does not mean the process has no privileges.
  6. Run the same query against a second service and compare the results.
  7. Do not modify the privilege list during this exercise.

Knowledge check

  1. What does sc.exe qprivs query?
  2. Does an empty result prove that the service has no privileges?
  3. What happens to unneeded privileges when a required list is configured?
  4. How does Windows handle required privileges when multiple services share one process?
  5. Which privilege is retained for compatibility even when it is not explicitly requested?
  6. Does qprivs change the service?

Answer guide

  1. The service’s configured required-privilege list.
  2. No. It can mean no required-privilege restriction has been configured, so the account’s normal process privileges may be used.
  3. The Service Control Manager removes privileges that are not required from the process token when the process starts.
  4. It computes the union of the privileges required by all services sharing that process.
  5. SeChangeNotifyPrivilege.
  6. No. It is a read-only query command.

Key takeaway

sc.exe qprivs is an audit command for Windows Service Hardening. It shows the privilege-reduction list a service has declared, but the output must be interpreted carefully—especially when the list is empty or the service shares a process with other services.

References

Primary references: Microsoft Learn — SERVICE_REQUIRED_PRIVILEGES_INFO, Microsoft Learn — Configuring a Service Using SC, and Microsoft — Windows Service Hardening.


Advertisement

BitcoinVersus.Tech Editor’s Note:

We volunteer daily to ensure the credibility of the information on this platform is Verifiably True. If you would like to support our independent technical education work, please donate Bitcoin here: 3C9o19EH5HSiwEPyCTmEKzxhNCbo2X6TTb

BitcoinVersus.tech is not a financial advisor. This lesson is for informational and educational purposes.

Leave a Reply