Re: ADAM Service Account



The best option is to use the default, Network Service.
It provides just sufficient privileges on the local machine (admin is too much), and it also has sufficient permissions in the domain, to be able to register SPNs on the computer account (which is needed for mutual auth), and to create SCPs.

Using a named service account means you have to take care of password changes, assigning appropriate permissions in AD for SPN registration and SCPs, assigning local permissions on the box to open an LDAP listener and to log security events, and maybe a few others... It only makes sense (in my view), if there's many different services running on the same machine, and you don't want to expose them to each other by sharing the service account. If ADAM is the only service on the box, then using NetworkService makes most sense.

--
Dmitri Gavrilov
SDE, Exchange

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at http://www.microsoft.com/info/cpyright.htm

"jskalicky" <jskalicky@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message news:EB564BA8-4BEE-49B0-9693-4874BE0039E8@xxxxxxxxxxxxxxxx
I am trying to install ADAM in our domain on two seperate servers. One will
be the Master and the other will be a replica. I will be using a domain
account for the service. What permissions are necessary for the ADAM service
account in a domain? Do I just need to make it an admin on the local box?
Please advise....

.



Relevant Pages

  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: NTFS owner problem
    ... power options, ... permissions that control access. ... to which any admin account should have full access. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: 2003 Server Client/Delegation and Data Issues
    ... The test account has the same issue as the junior admin. ... The AD information is up to date - I could view the account I ... I am starting to suspect a permissions conflict as I have poked around ... The jr admin is a member of the Remote Desktop Users group at the domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)