Microsoft Secure Tech Accelerator
Apr 13 2023, 07:00 AM - 12:00 PM (PDT)
Microsoft Tech Community
Service account is not secure in its current configuration
Published Nov 01 2019 02:08 PM 341 Views
Microsoft

First published on MSDN on Aug 28, 2015

Used to secure the following MIM PAM Service Accounts



    • Application Pool ( For Rest API )

 

    • PAM Component Service

 

    • Privileged Access Management Monitoring Service



Issue:

 

When installing the "PAM" Privileged Access Management Features you are presented with one or all of the below warnings about the service accounts to be used. This is a warning and will not prevent you from continuing but it is recommended to secure the accounts at your earliest availability. See Resolution

 

 

 

Images:



    • Rest API Application Pool account is not secure in its current configuration





    • Component Service account is not secure in its current configuration





    • Monitoring Service account is not secure in its current configuration



 

 

 

Cause:



    • Prior to installing the PAM Feature the Service Accounts to be used were not secured.



Resolution:



    1. On the server that the PAM Features will be installed on or has already been installed on:
        1. on the server that host the Forefront Identity Manger Synchronization Service open up Local Security Policy

        1. Expand Local Polices

        1. Click on User Rights Assignment

        1. Scroll down to locate the following policies
            1. Deny log on as a batch job

            1. Deny log on locally

            1. Deny access to this computer from the network



 

 

 

Questions? Comments? Love FIM / MIM so much you can't even stand it?

 

 

 

EMAIL US>EMAIL US<

 

 

 

## http://blogs.msdn.com/connector_space ##

Version history
Last update:
‎Feb 20 2020 12:53 PM
Updated by: