Run as Account for Sharepoint Monitoring
We are using "local System" as default action account. We configured sharepoint 2010 Monitoring with SCOm 2007r2 using different account (ABC) that is local admin on SP boxes, SQL servers and has DB access on SP DB's residing on SQL server
After the SP diagram got populated, we have to remove that account (ABC) from local admins of SQL servers (SQL is clustered). We are not allowed to add service aacounts to local admins or allow logon locally GPO on SQL servers. Now we
are getting alerts from SQL servers for the service account (ABC) which is "the health service could not log on the specfied run as account beacuse it has not been granted the log on locally right"
Is there any workaround to fix this?
In case we live with this warning for that account (ABC), how much will it effect the MOnitoring?
Appreciate any help in advance~Cheers, Rohit Kochher
May 24th, 2012 5:01pm
Hi Rohit,
The following permissions are needed to get this working correctly:
local admin on all SP2010 Front End and Application servers local admin on all SQL boxes that host SharePoint 2010 Databases dbo for the actual SharePoint databases full farm admin rights within SharePoint 2010
For more info:
http://blogs.technet.com/b/operationsmgr/archive/2011/03/10/tips-on-using-the-sharepoint-2010-management-pack-for-opsmgr-2007.aspx
Thanks,
Varun
Free Windows Admin Tool Kit Click here and download it now
May 25th, 2012 2:51am
Hey varun
we followed same post and configured SP MP accordingly. my queries are related to post installation of MP
~Cheers, Rohit Kochher
May 25th, 2012 3:13am
Hi Rohit,
As far as my understanding the Run As account must have sufficient privilege to allow discovery and monitoring to run properly.
Thanks,
Varun
Free Windows Admin Tool Kit Click here and download it now
May 25th, 2012 4:21am
Thanks Varun.
Folks,
Inspite of that warning from SQL servers about Sharepoint run as account, we are still able to monitor. Also perf data ie being populates.
I am interested to know hidden/know impact of continuous monitoring with warning for particulat run as account on SP-SQL servers~Cheers, Rohit Kochher
May 25th, 2012 3:36pm
Hi All
We are still able to monitor our SQL servers even with the warning that run as account cannot log on locally.
Performance data is also being collected. SO can we live with the warning, or there are soem hidden impacts
Our security team does not allow service account to have logon locally right.
Appreciate any help in advance!~Cheers, Rohit Kochher
Free Windows Admin Tool Kit Click here and download it now
June 13th, 2012 10:20am


