Permissions needed for SCOMAction account

Hi, can anyone give me precise answer for this question: Which permissions SCOMAction account does need to have in order to SCOM 2012 R2 work properly?
I found on many sources that SCOMAction account DOES need to be member of local administrators group on all computers agent was deployed to. Having installed agents only on all my domain controllers using my domain admin account I have not experienced any
problems yet - since DCs do not have local administrators group if above is a MUST that means I would have to give SCOMAction account domain admins right i.e. put it into domain admins group which certainly is huge overkill (in that case SCOMAction account
would be automatically local administrator on all domain computers).
I have to repeat again: I deployed agents to all my DCs using my domain admin account - SCOMAction account does not have any special permission except being local administrator account on SCOM server itself along with SCOMDataAccess, SCOMDataReader
and SCOMDataWriter accounts. Everything works well but there is a possibility something is wrong because of the fact that SCOMAction account does not have needed perms on DCs and I have not noticed yet. Almost 10 hours passed since I deployed agents to DCs
and start monitoring them (I have imported Windows Server MP, AD MP, GPO MP, DFS-R MP, DNS MP . . .) - I have not noticed any errors caused by lack of perms for any of SCOM accounts.

SCOM Action account does not required to be local administator of agent machine
The action account is used to gather information about, and run responses on, the managed computer (a managed computer being either a management server or a computer with an agent installed). The MonitoringHost.exe processes run under the action account or
a specific Run As account.
You may use local system or domain account for agent action account.
For Domain user agent's action account, you can use a low-privileged account by ensurin that the account have the following minimum privileges:
• Member of the local Users group
• Member of the local Performance Monitor Users group
•“Allow log on locally” permission (SetInteractiveLogonRight)
https://technet.microsoft.com/en-us/library/hh212808.aspx
Roger

Similar Messages

  • Permissions needed for mobile account file sync

    Hello,
    I have set up my account as mobile account in an AD domain.
    When FileSync syncs the files automatically, then I often get errors as follows:
    File xyz could not be synced.
    Permission denied.
    What permissions does FileSync need to work correctly?
    Regards
    Florian

    SCOM Action account does not required to be local administator of agent machine
    The action account is used to gather information about, and run responses on, the managed computer (a managed computer being either a management server or a computer with an agent installed). The MonitoringHost.exe processes run under the action account or
    a specific Run As account.
    You may use local system or domain account for agent action account.
    For Domain user agent's action account, you can use a low-privileged account by ensurin that the account have the following minimum privileges:
    • Member of the local Users group
    • Member of the local Performance Monitor Users group
    •“Allow log on locally” permission (SetInteractiveLogonRight)
    https://technet.microsoft.com/en-us/library/hh212808.aspx
    Roger

  • Permissions needed for Applying SQL Tuning Sets/SQL Plans 11g?

    What permission are needed for a user to apply/activate sql tuning sets (sql plans) in 11g? The user can capture and move the the sql tuning sets from a 10g database to an 11g database but is getting "ORA-01031: insufficient privileges" when trying to activate/apply the sqlplans in 11g.
    The user has:
    ADMINISTER SQL MANAGEMENT OBJECT and ADMINISTER SQL TUNING SET and EXECUTE on SYS.DBMS_SPM
    The user is an administrator for our Data Warehouse team but they do not have sysdba priviliges.
    Do you also know of a good white paper that covers the step by step instructions and permissions needed for aquiring and applying/activating sqlplans?
    If more information is needed in order to respond please advise.
    Thank you

    What permission are needed for a user to apply/activate sql tuning sets (sql plans) in 11g? The user can capture and move the the sql tuning sets from a 10g database to an 11g database but is getting "ORA-01031: insufficient privileges" when trying to activate/apply the sqlplans in 11g.
    The user has:
    ADMINISTER SQL MANAGEMENT OBJECT and ADMINISTER SQL TUNING SET and EXECUTE on SYS.DBMS_SPM
    The user is an administrator for our Data Warehouse team but they do not have sysdba priviliges.
    Do you also know of a good white paper that covers the step by step instructions and permissions needed for aquiring and applying/activating sqlplans?
    If more information is needed in order to respond please advise.
    Thank you

  • Local NTFS permissions needed for Palm software?

    Does anyone know the NTFS permissions needed on the local computer for a standard user to run the Palm software?
    Post relates to: Palm TX

    Hello Cajuntank and welcome to the Palm forums.
    Palm Desktop needs to be installed with the local administrator priviledge during the install of Palm Desktop, the HotSync Manager, the first HotSyn sync, and the installation of any third-party conduits on the desktop.
    After that, the local admin rights can be revoked.
    Alan G

  • Need for Purchase Accounting

    Hi,
    My client has given a requirement to implement the Purchase Accounting.
    Now for india there is no legal reqmnt for purchase accounting.
    Now i want to ask all you there what can be the advantages & dis advantages after implementing the Purchase accounting.
    For config point, there are hardly 3-4 settings to be done.
    So based on your experience & interaction with client, plz suggest.
    regards
    AV M
    Points will be rewarded

    HI,
    Why do you want to capture them via reports? These all have its own importance. The account keys defined are the media to integrate the transactions between FI & MM. Whatever the cost you are incurring for freight, Taxes, customs etc etc. how you are going t account them. You need to capture these costs automatically to some chart of accounts(COA) which your company manages and these will reflect in you balance sheet or P/L accounts. If you try to do it manually these will be a hectic job.
    Suppose tomorrow your client ask you, what is the freight expense for Raw Material? how will you show them. If you maintain these accounts, you will get these from standard report. no need of any ABAPer.
    So these accounts are required for proper functioning and healthy implementation.
    Hope this has cleared your doubts.
    Regards

  • App Pool Account permissions needed for People Picker

    Greetz!
    The peoplepicker runs under the credentials of the application pool the site is running in.  However I am not able to retrieve users from Active Directory. What rights does this account need on AD, if any?
    Love them all...regardless. - Buddha

    I verified that the sAMAccountName matches what I'm entering. When I used your Peoplepicker Port Tester I ran it as an admin and when I clicked search I got an errot that said it had stopped working:
    Description:
      Stopped working
    Problem signature:
      Problem Event Name: CLR20r3
      Problem Signature 01: peoplepicker port tester.exe
      Problem Signature 02: 1.0.0.0
      Problem Signature 03: 54d84550
      Problem Signature 04: mscorlib
      Problem Signature 05: 2.0.0.0
      Problem Signature 06: 526717bd
      Problem Signature 07: 20ce
      Problem Signature 08: 100
      Problem Signature 09: N3CTRYE2KN3C34SGL4ZQYRBFTE4M13NB
      OS Version: 6.3.9600.2.0.0.272.7
      Locale ID: 1033
    I believe I got that error because I added a CN which perhaps wasn't correct. When I removed the CN and just used 2 OU identifiers the tool connected to the client forest. I have failures in UDP 88, 135, 137, 138, 389, 445 and 749. Some are because
    the response wasn't timely. Some because they were 'forcibly closed' by the remote host.
    I am in a 2 way trust between separate forests. My SA says there are not ports closed between my server and the AD. When I run the port test tool is there a requirement that I be on a specific service where a particular SharePoint service is running? I ran
    it on the app server and got the results above. When I run it on the web front en all ports just say 'connection failed'
    TCP/389 connection failed
    TCP/636 connection failed
    TCP/135 connection failed
    TCP/137 connection failed
    TCP/138 connection failed
    TCP/139 connection failed
    TCP/3268 connection failed
    TCP/3269 connection failed
    TCP/53 connection failed
    TCP/88 connection failed
    TCP/445 connection failed
    [Opt]TCP/749 connection failed
    [Opt]TCP/750 connection failed
    No such host is known
    Love them all...regardless. - Buddha

  • Permissions needed for user to define workflow variable

    Hi all
    im using a workflow on sharepoint designer 2007, running on list of customer orders. the workflow is trying to use data from customer list.
    In the workflow i used the "define workflow variable" step on customer order list. the users who are using the order list have Contribute permission so they can add items. on the customer list they have read permission.
    when an item is created, the workflow is suppose to generate the varieble by combining data from the two lists: selecting the customer from the current order item and suppose to combine it with data from the customer list for that specific customer
    and keeps it in the variable.
    for users with full control permission for the site, the workflow is completed ok. for the users with the contribute and read permissions it ends with an error and doesnt store the variable (i cheked it by storring the variables in the workflow history).
    what are the permission needed to manage to do the action of storring the variable?
    or any other ideas for the error?
    Thanks in advance

    Hello Cajuntank and welcome to the Palm forums.
    Palm Desktop needs to be installed with the local administrator priviledge during the install of Palm Desktop, the HotSync Manager, the first HotSyn sync, and the installation of any third-party conduits on the desktop.
    After that, the local admin rights can be revoked.
    Alan G

  • Need for an Account?

    Do I need to keep an account on Revel just to work on my own computer and not store off-site?  And is having an account the only way to get help with editing?  I have not yet gotten to really use my programs, but I don't want to share my stuff with the world.

    >way to get help with editing?
    Asking here is probably the best way... starting with a LOT of reading
    You did not specify a version, so I will post ALL links, not just for version 11
    Online User Guide http://help.adobe.com/en_US/premiereelements/using/index.html
    -Page to download current PDF http://helpx.adobe.com/premiere-elements.html
    -Previous versions http://helpx.adobe.com/premiere-elements/archive.html
    Importing Video http://forums.adobe.com/thread/1065281
    -and project settings http://forums.adobe.com/thread/1112086
    Saving & Sharing http://forums.adobe.com/thread/1137128
    -Sharing to DVD or BluRay http://forums.adobe.com/thread/1137645
    -Sharing for Movies http://forums.adobe.com/thread/1051093
    -Sharing for Computer http://forums.adobe.com/thread/1058237
    Steve's Basic Training Tutorials... steps are the same for several versions
    -start at http://forums.adobe.com/thread/537685
    -v11 http://www.amazon.com/Muvipix-Guide-Premiere-Elements-version/dp/1479311200/
    -v10 http://www.amazon.com/Muvipix-com-Guide-Premiere-Elements-Version/dp/1466286377/
    -v09 http://www.amazon.com/Muvipix-com-Guide-Premiere-Elements-version/dp/1453871209/
    -All http://www.amazon.com/Tricks-Adobe-Premiere-Elements-Muvipix-com/dp/1451529724/
    -and http://forums.adobe.com/thread/498626
    -and http://prodesigntools.com/four-hours-free-video-tutorials-new-photoshop-elements-9-pse9.ht ml
    -and http://prodesigntools.com/five-hours-free-tutorials-photoshop-and-premiere-elements-7-and- 8.html
    FAQ http://forums.adobe.com/community/premiere_elements/premiere_elements_faq
    TIPS http://forums.adobe.com/community/premiere_elements/premiere_elements_tips
    Another help site http://muvipix.com/ or http://muvipix.com/phpBB3/

  • Permissions needed for sql server job to execute stored procedure on linked server?

    Hi all
    I have a job step which attempts to call a stored procedure on a linked server.
    This step is failing with a permission denied error. How can I debug or resolve this?
    The job owner is sysadmin on both servers so should have execute permission to the database/proc I'm calling, right?
    The error is:
    The EXECUTE permission was denied on the object 'myProc', database 'myDatabase', schema 'dbo'. [SQLSTATE 42000] (Error 229).  The step failed.
    My code is:
    EXEC [LinkedServer].myDatabase.dbo.myProc
    Also tried:
    SELECT * FROM OPENQUERY([LinkedServer], 'SET FMTONLY OFF EXEC myDatabase.dbo.myProc')
    With the same result.
    Any help appreciated.

    The job owner may be sysadmin on the remote server. The service account for SQL Server Agent may not. And it is the latter that counts, since the it the service accounts that logs in and impersonates the job owner. But the impersonation inside SQL Server
    does not count much in Windows, and it is through Windows connection is made to the other site.
    One way to resolve this is to set up a login mapping for the job owner. The login mapping must be for an SQL login on the remote server.
    You can verify the theory, but running this query from the job:
       SELECT * FROM OPENQUERY([LinkedServer], 'SELECT SYSTEM_USER')
    By the way, putting SET FMTONLY OFF in OPENQUERY is a terrible idea. This has the effect that the procedure is executed twice. (Unless both servers are SQL 2012 or higher in which case FMTONLY has no effect at all.)
    Erland Sommarskog, SQL Server MVP, [email protected]

  • Problem: Reversal (FB08) Needed for Clearing Account

    Dear Gurus,
    I have accidentally run the automatic clearing program (F110), which was not required, in the Production.
    263 documents have been generated.
    How to reverse the Clearing account in this case as FB08 doesn't allow reversing the clearing account.
    Please Help.

    Dear,
    Bhatia FB08 only for normal items
    but you used F110 means you cleared all open items
    so use T-code FBRA
    here select the clearing document numbers
    regards

  • CRM Table Names needed - For CRM Account, Contacts & Activity

    Hi,
    I liked to know "Table Names" for the following entities are stored in SAP CRM System
    (a.)  CRM Accounts
    (b.)  CRM Contacts
    (c.)  CRM Activity
    Thanks,
    Prembabu

    Check the list of CRM Tables;
    BUT000 : BP: General data - Contains Business Partner Number, Partner Category, Partner Type, First Name, Last Name etc.
    BUT020 BP: Addresses
    BUT050 BP relationships/role definitions: General data - Contains Relationship, Partner Number (PARTNER1), Relationship Category
    BUT051 BP Relationship: Contact Person Relationship Similar to
    BUT050 additionally contains Contact Person's Address data
    BUT0BK Business Partner: Bank Data & Details BP Number, Bank Key, Bank Country Key, Bank Account Number
    BNKA Bank Master Data
    BUT100 BP: Roles
    ADR2 Telephone Numbers (Business Address Services)
    ADR6 SMTP Numbers (Business Address Services) - Contains Email – Id of the BP.
    ADRC Addresses (Business Address Services) - BP's Complete Address Details- City, Country, Post Code, District,
    Street, Title No Etc
    TSAD3T Table containing the Title text against a Title No.
    COMM_PRODUCT Master Table for Product
    CRMM_BUAG Master table for Business Agreement
    CRMM_BUAG_H Header Data for Business Agreement such as Tax Category, Tax Characteristic, Form key, Business Agreement Class. Data in this table correspond to ISU
    CRMD_OPPORT_H OPPORTUNITY HEADER DATA
    CRMD_ORDERADM_H Contains the Header Information for a Business Transaction.
    Note:
    1. It doesn't store the Business Partner responsible for the transaction. To get the Partner No, link it with
    CRM_ORDER_INDEX.
    2. This table can be used for search based on the Object Id(Business Transaction No).
    CRMD_OPPORT_H OPPORTUNITY HEADER DATA
    CRMD_CUSTOMER_H Additional Site Details at the Header Level of a Business Transaction
    CRMC_PROC_TYPE Master table Business Transaction Type
    CRMC_PARTNER_FCT Definition of Partner Functions
    SCPRIOT Priorities for Activities with priority text.
    CRMC_PROC_TYPE_T Text for a transaction type
    CRMC_ACT_OBJ_T Objective Number and Text for Activities
    TJ30T All the status code and text
    CRMC_PR_ASSIGN : Transaction Type and its Transaction Type Object.
    IBIB : Installed Base/Ibase
    IBIN : Installed Base Components
    Activities:
    CRMD_ACTIVITY_H Activity Header table
    CRMD_ACTIVITY_I Activity Reporting: Activity Line Item Extension
    CRMD_TM_ACTIVITY Activity reference
    Lead:
    CRMD_LEAD_H Lead Header table
    Opportunity:
    CRMD_OPPORT_H Opportunity Header table
    Reward points if it helps.

  • Hi, I forgot my user password mac 10.9.4 I don't need it to log in but i need it to make changes, etc. It says a password hasn't been set for this account but it still asks for one when i click on the lock icon. can anyone help me? thx!

    Hi, I forgot my user password mac 10.9.4 I don't need it to log in but i need it to make changes, etc. It says a password hasn't been set for this account but it still asks for one when i click on the lock icon. can anyone help me? thx!

    This is a little confusing since you say you have forgotten your password and then the system says you have not entered a password.  Even with an Admin account you must have a password to install software.
    If you are using Mac OS X 10.7 or above, you can change the admin password by restarting holding the Command and R keys, from the menu bar select Utilities, then Terminal.  When the Terminal window opens, at the cursor type exactly:
    resetpassword
    and press Enter.  When the Reset Password window opens, select the internal hard drive, and then the user account.  Type a new password twice, leave the Hint blank, and then Save.  Accept the next dialog that opens, and at the bottom of the Reset Password window agree to resetting the home directory permissions.
    Quit the Reset Password window, go to the apple left side of the menu bar, Restart.
    And you have a new password for your account.

  • I need to delete my Apple ID on my iPhone 4.  I forgot my psw for my account.  When I answer the security question, the system responds incorrect answer.  I created a new Apple iTunes account but I still unable to delete the old iTunes account.

    I need to delete my Apple ID on my iPhone 4.  I forgot my psw for my account.  When I answer the security question, the system responds incorrect answer.  I created a new Apple iTunes account but I still unable to delete the old iTunes account.

    AppleFAN7591 wrote:
    I need to delete my Apple ID on my iPhone 4.  I forgot my psw for my account.  When I answer the security question, the system responds incorrect answer.  I created a new Apple iTunes account but I still unable to delete the old iTunes account.
    How to reset your Apple ID password.
    Go to iforgot.apple.com and type in your Apple ID, then click 'Next'.
    Verify your date of birth, then click 'Next'.
    You'll be able to choose one of two methods to reset your password, either E-Mail Authentication or Answer Security Questions.
    If neither method works, then go to https://getsupport.apple.com
    (If you see a message that says 'There are no products registered to this Apple ID, simply click on 'See all products and services')
    Choose 'More Products & Services', then 'Apple ID'.
    A new page will open.
    Choose 'Other Apple ID Topics', then 'Lost or forgotten Apple ID password'.
    Click the blue 'Continue' button.
    Select the contact option that suits your needs best.
    How to reset your Apple ID security questions.
    Go to appleid.apple.com, click on the blue button that says 'Manage Your Apple ID'.
    Log in with your Apple ID and password. (If you have forgotten your Apple ID password, go to iforgot.apple.com first to reset your password with a password recovery email)
    Go to the Password & Security section on the left side, and click on the link underneath the security questions that says 'Forgot your answers? Send reset security info email to [email]'.  This will generate an automated e-mail that will allow you to reset your security questions.
    If that doesn't work, or  there is no rescue email link available, then click on 'Temporary Support PIN' that is in the bottom left side, and generate a 4-digit PIN for the Apple Account Security Advisor you will be contacting later.
    Next, go to https://getsupport.apple.com
    (If you see a message that says 'There are no products registered to this Apple ID, simply click on 'See all products and services')
    Choose 'More Products & Services', then 'Apple ID'.
    A new page will open.
    Choose 'Other Apple ID Topics', then 'Forgotten Apple ID Security Questions'.
    Click the blue 'Continue' button.
    Select the contact option that suits your needs best.

  • My children got Itunes cards for christmas.  There devices are all on my imac.  Do they each need a separate account or is there a way to keep them all separate under one account.

    My children got Itunes cards for christmas.  There devices are all on my imac.  Do they each need a separate account or is there a way to keep them all separate under one account.

    I need an answer to this too.

  • I need to reset the security questions for my account but it's sending an email to an email that no longer works. is there a way to change this email?

    the email it's sending it to is different than my sign in as well.

    You need to contact Apple. Click here, phone them, and ask for the Account Security team, or fill out and submit this form.
    (90544)

Maybe you are looking for