“Allow log on locally” permission (SetInteractiveLogonRight) for SCOM 2012

Hi Experts,

Do we need to have  Allow log on locally permission (SetInteractiveLogonRight) for any of the SCOM accounts in 2012 R2?

If yes why?

Regards,

Prajul Nambiar

February 20th, 2015 2:58pm

Yes, The default action account must have the following minimum privileges:
Member of the local Users group
Member of the local Performance Monitor Users group
Allow log-on-locally permission (SetInteractiveLogonRight)

because SCOM provide you with monitoring for agents which need to access event viewer of this server to show you any issue that happened.

  • Monitoring and collecting Windows event log data.
  • Monitoring and collecting Windows performance counter data.
  • Monitoring and collecting Windows Management Instrumentation (WMI) data.
  • Running actions such as scripts or batches.

Also you can refer below link

https://technet.microsoft.com/en-us/library/hh212808.aspx

Free Windows Admin Tool Kit Click here and download it now
February 20th, 2015 4:32pm

Hi,

You may check Action Accounts part in the link below:

Account Information for Operations Manager

https://technet.microsoft.com/en-us/library/hh457003.aspx

Regards,

Yan Li

February 21st, 2015 9:11am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics