Run as account and profile associate

Dears,
Sorry I am new to Managing Linux in SCOM, so I have a 2 questions.
In below link:
http://technet.microsoft.com/en-us/library/hh212926.aspx
it is mentioned that we have to create 2 type of Run as accounts:
A monitoring account
An agent maintenance account
It is mentioned that we have to associate the Run as accounts with profile as below:
UNIX/Linux Action Account:
 Add a monitoring Run As account that has unprivileged credentials, to this profile.
UNIX/Linux Privileged Account:
 Add a monitoring Run As account that has privileged credentials or credentials to be elevated, to this profile.
UNIX/Linux Agent Maintenance Account:
 Add a monitoring Run As account that has privileged credentials or credentials to be elevated, to this profile.
Questions are:
Why we have to associate "Monitor Run as account" with "UNIX/Linux Agent Maintenance Account" ?
What if we associate "Agent maintenance account" with "UNIX/Linux Agent Maintenance Account" ?
When we will use the "Agent maintenance account"?
Thank you

Hello,
The "Agent Maintenance" account type is for use with the ssh protocol. It allows for the use of ssh key authentication and su elevation (as an alternative to sudo elevation).  Therefore, it is not compatible with any Run As Profile other than the Agent
Maintenance profile.  The Action & Privileged account profiles are used for "monitoring" operations with the WS-Man protocol, and don't support the ssh-specific options for the Agent Maintenance account.  A "Monitoring" account type can be used
in all three profiles, but the "Agent maintenance" account type can only be used in the Agent Maintenance Account profile.
To address your questions directly:
Why we have to associate "Monitor Run as account" with "UNIX/Linux Agent Maintenance Account" ?
The documentation here looks like it could be improved. An account type of Monitoring or Agent Maintenance can be used in this profile.
What if we associate "Agent maintenance account" with "UNIX/Linux Agent Maintenance Account" ?
This is completely OK.
When we will use the "Agent maintenance account"?
The agent maintenance account is only used in two cases: 1) when you upgrade existing agents and 2) when you uninstall existing agents.  Ultimately, it is an optional profile. 
I hope this helps,
Kris
www.operatingquadrant.com

Similar Messages

  • I have moved to uk from ireland and bought new iphone, set up using my existing Apple ID account and profile but won't let me buy install or update apps??

    I have moved to uk from ireland and bought new iphone, set up using my existing Apple ID account and profile but won't let me buy install or update apps??
    Can anyone advise me on what I need to do?
    My existing account is linked to ireland as my bank account details are there, does this make a difference?
    Please help!

    Until you get a UK bank account and credit card, buy and redeem UK iTunes gift cards for use in the iTunes and Mac App Stores. But you need to switch your region/country to the UK store in your account information, as you can't use UK iTunes gift cards in the Irish stores, the gift cards are country specific.

  • Can I run sage accounts and payrol on an apple imac?

    Hi looking at buying an iMac can I run my sage accounts and sage payrol on it?

    I have used Sage in a VM, I used Fusion (I never use Parallels) I also have heard (not seen) that it will run in Virtual Box.
    It runs slowly in Fusion, but it runs.

  • RUN LOGIC:Accounts and entities do not match data in application Ownership (BPC10.0 NW)

    Hello Experts,
    During execution of the legal consolidation package we get the following error: "Accounts and entities do not match data in application OWNERSHIP"
    We have entered the ownership and transaction data.
    Could you, please, help us to solve the problem?
    Thanks.

    Hi
    The Ownership has accounts like Percentage consolidation etc. Please check if you have selected the correct ones, marked as use in consolidation process and loaded Ownership data aganst those .
    Regards
    Surabhi

  • Account and profile settings

    There is a mistake in my account, I was charge $10.dl's for a subscription that I did not ask for. All I wanted to do was to change my payment method to renew auto charge of $2.99dl's p/month with a new credit card, I can't find a way to cancel this $10.dl's charge and replace the current credit card for the new one, the c/card on record is not valid, I cancelled with the bank, that is the reason why I need to replace the card, how do I go about doing this.
    Thank you.

    for clarifications regarding those charges and for further assistance, you may need to contact customer service. Just click the link below for instructions on how to contact the support them. You can also request for a refund if preferred/applicable;
    http://community.skype.com/t5/General-Discussion/How-to-Contact-Skype-Customer-Service/m-p/431911
    IF YOU FOUND OUR POST USEFUL THEN PLEASE GIVE "KUDOS". IF IT HELPED TO FIX YOUR ISSUE PLEASE MARK IT AS A "SOLUTION" TO HELP OTHERS. THANKS!
    ALTERNATIVE SKYPE DOWNLOAD LINKS | HOW TO RECORD SKYPE VIDEO CALLS | HOW TO HANDLE SUSPICIOS CALLS AND MESSAGES

  • Re: Account and profile settings

    i need help anyone at all that can help me please!!! I tried this and they took 20 dollars and now i cant get ahold of anyone

    for clarifications regarding those charges, you may need to contact customer service. Just click the link below for instructions on how to contact the support team. 
    http://community.skype.com/t5/General-Discussion/How-to-Contact-Skype-Customer-Service/m-p/431911
    IF YOU FOUND OUR POST USEFUL THEN PLEASE GIVE "KUDOS". IF IT HELPED TO FIX YOUR ISSUE PLEASE MARK IT AS A "SOLUTION" TO HELP OTHERS. THANKS!
    ALTERNATIVE SKYPE DOWNLOAD LINKS | HOW TO RECORD SKYPE VIDEO CALLS | HOW TO HANDLE SUSPICIOS CALLS AND MESSAGES

  • 2012 R2 Need help understanding profiles/run as accounts

    I'm new to SCOM, just installed 2012 R2, everything is set up.  Basically only 2 servers.
    I've installed management packs for base OS, IIS, AD, Lync 2013, SQL.
    The first thing after that I set up a run as account for email notifications.  In doing so I used an AD account but chose less secure.
    I then created a notification channel, subscribers, and subscriptions.  It worked and I was getting emails because I bound by Notification action account to the notification account profile.  The problem in doing so is that now I got alerts on all
    my DCs that the run as account does not exist on the target machine.  So in choosing "less secure" or "all targeted objects" on the run as account, it is trying to use that account for my notifications instead of the default.
    So I started messing around with things, such as the run as accounts used for the notification account profile but things are just not working as expected.
    Also for some reason the 3 Microsoft Lync Server Profiles have the network server windows account bound to them which I can't remove.
    So in the end here is what I did for email alerts.  We have a seperate anonymous SMTP relay set up.  I created a new run as account called "notification action account" and chose an newly created AD account which is just a domain
    user.  Inside of the distribution tab, I selected more secure but added the SCOM server itself because I don't have the agent installed on our open SMTP relay and it allows internal anonymous email. Under the Profiles, Notification Account I set the run
    as account to the "Notification action account" I created, but still selected all targeted objects.  That seems to be working and I'm not getting alerts from my DCs about the account doesn't exist on the target. 
    I'm just not understanding why if you don't specify more secure and put in specific servers, it trys to use that account to connect to everything instead of using the default.

    Hi,
    If you choose to distribute the Run as account to all the agents, all the workflows on the agents associates with this profile will use this account.
    http://technet.microsoft.com/en-us/library/hh431855.aspx
    http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx
    Juke Chou
    TechNet Community Support

  • Run As Account does not exist on the target system or does not have enough permissions

    We are getting below alerts,
    Run As Account does not exist on the target system or does not have enough permissions.
    I know we can create a Run As account with low Privilege can fix this issue ,
    http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx
    My question here is there is any other way to fix it. I tried giving below permission for scom_act account (we used for agent installation and has local admin rights) but still same issue and
    also i tried with sysadmin access for scom_act as well but no luck still having same issue , any solution would be welcome
    The min. Privilege for monitor SQL server
    DB Server Level
    a.  VIEW ANY DEFINITION
    b. VIEW SERVER STATE
    c.     VIEW ANY DATABASE
    Each DB
    a.  SQLAgentReaderRole database role.
    b.  PolicyAdministratorRole database role

    Check below link
    http://blog.coretech.dk/msk/run-as-account-does-not-exist-on-the-target-system-or-does-not-have-enough-permissions/
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Mai Ali | My blog: Technical | Twitter:
    Mai Ali

  • Query on Run as accounts

    Hi,
    We are Have SCOM 2012 R2 environment and default agent action account used is local system. I would like to clarify below points on Run as accounts.
    1) Permissions and rights required for SQL run as account.
    2) Permissions and rights required for the Cluster Run as account.
    3) Permissions and rights required for the Exchange 2013 run as account.
    4) Permission and rights required for the AD run as account.
    All the agents in our environment is running with Local system.

    Hi 
    in addition, it is good practice to install agent with Local Account and configure application specific account as run as account.
    refer below link on run as account :
    http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx
    Regards
    sridhar v

  • Accidentally deleted APM Run As Account

    Hey
    While deleting some test Run As accounts, I accidentally deleted the APM Run As Account that gets automatically created. Is there a way to restore this account? I was going to try and re-create it, but I never entered any credentials for it.
    In my test environment, I installed APM and noticed that the account gets created once you start monitoring an application. The credentials for the account are a Binary Account File type with encrypted binary data.
    Any suggestions with how I should proceed?
    Thanks!

    Fixed the issue. Here's what I had to do:
    1. Delete the Run As PROFILE (entitled 'APM CSM Encryption Profile') that was looking for the deleted Run As "APM Account" (pictured above). Once I deleted it that action propagated to all the clients to stop looking for that account to authenticate
    as. I believe this is due to the nature of the account (See: Distribution tab: Less Secure - distributes to ALL managed computers).
    2. Once that profile was deleted, all the alerts entitled: "System Center Management Health Service Credentials Not Found Alert Message" were closed. 
    3. To get the account & profile back, all I had to do was the following: I noticed in my test lab that the APM account and APM CSM Encryption profile get created NOT when you import the APM management back, but once you SETUP your first .NET Application
    to monitor. After the setup of an application to monitor, those accounts get created and linked together. Since I already had a production APM monitor set up, all I had to do was open the properties of the .NET application from the Management Pack Templates
    view, and click Apply again. It sat there for a few moments processing the completion (one of the tasks obviously is creating those accounts if they do not exist), and then the wizard closed. Once closed, I verified the account and profile were created and
    watched the OpsMgr Event log populate as it propagated this account to all managed computers.
    Hope this helps someone if they encounter this in the future!

  • Can't change Run as account in the Host Access tab for a clustered host

    Gentlemen, we have a bunch of Hyper-V clusters added to hyper-V and most of them have a run as account assigned to them, which we don't want to keep (they were added with a domain admin user).
    However, I'm not able to change it on the clustered host nodes. I can change it on non clustered hosts, no issue.
    I've tried and, of course, removing and re-adding the clusters with another account also fixes the issue, but there is a good number of clusters and it is all production.
    Any other ideas?
    I could also rename the run as account and make sure it has local admin right for all nodes. Is it safe? Any gotchas?
    I've tried powershell, but I couldn't find a command to change the run as account for a clustered host (read-only).
    Thank you,
    JF
    MCITP, MCSE, MCTS

    you're right. once the hosts are clustered, this option is greyed out.
    the only option is to remove the cluster from VMM, and add it again with the right run as account.
    I have not tested to rename the run as account.
    -kn
    Kristian (Virtualization and some coffee: http://kristiannese.blogspot.com )

  • Display color profile bug when using the fast account switch from a guest account to an admin account (and vice versa)

    Hey,
    I'm sometimes using a guest account on my MBP (unibody late 2008 2,4 GHz Core2Duo, 4GB DDR3 running OSX 10.9.4 on an OCZ 128GB SSD) for a more distraction-free working space and I noticed right away a disturbing bug:
    Using the fast account switch (upper right hand corner of the screen) in Mavericks from an admin account to log into a guest account (or vice versa) produces, after the fancy rotating cube animation, some strange distortion of the desktop background happens (lasting approx. 2 sec.). After that the color profile of the display is changed into an usable but ugly one, which is disturbing while working with pictures. When checking the color profile in the pref pane, the standard "display" profile is said to be active (it's the one I use) but still the colors aren't the same. Selecting another profile and re-selcting the desired one doesn't fix the problem. Switching back to the other account with the fast switching leaves the colors altered. Logging out and deleting the guest account seems to the problem for the remaining admin account. Rebooting  and logging in to either of the accounts (admin or guest) from the standard account selecting page at booting shows the normal color profile.
    Is it a general bug or is their anything a can do to prevent this problem (other than never using the fast switching)?
    Thanks for your advice.
    Mael

    I cannot agree more with your comments! What a way to frustrate your customers!
    I have been having an issue with iCloud on Mac where it kept asking me for my password and sometimes would, sometimes would not continue to access my iCloud mail. Today it just refused to connect to iCloud mail.
    I looked in the Mail, Contacts and Calendars in my MacBook Pro settings and discovered that 2 iCloud accounts were present. One with my original Apple ID (a gmail address) and a second with my new iCloud email ( an @me.com address). Having deleted the second account, using the new @me.com address everything is working fine.
    So from my viewpoint when I moved over to iCloud I was asked to sign in with my Apple ID (the gmail address) then to create an @me.com address. However, as far as I can see all sign ins to the new @me.com account on Macbook, iPhone and iPad need to be done through the old Apple ID (the gmail address). Is that confusing and just plain crazy???
    Further, after creating the new @me.com address I soon found out that this is apparently now forever bound to my old Apple ID and cannot be changed. I mean why can't I delete the iCloud account and start anew with a different @me.com address??? Also, as everybody using iCloud must create an @me.com address why on earth can I not get rid of my old gmail address and have my entire Apple ID accessed through the new @me.com address? Creating a whole new Apple ID will not solve this as we are unable to transfer purchases between accounts.
    Apple products are great IMHO, but they do seem to not think things through in a very big way sometimes......

  • Alert summary MP run as account profile in multiple domains

    Hi,
    I have a general question about run as account profiles and targeting of objects.    We have an Alert Summary MP account that uses the scom action account.   The target is all objects.   the Runas account used is a domain
    account in domain XYZ.  When targeting all objects, it tries to run on domain ABC and caused an alert.
    How can I specifically configure the profile to use account  XYZ\accountname for objects in XYZ domain and then ABC\accountname in the ABC account.
    Thanks Lance

    1) Create Group XYZ contains all objects in domain XYZ
    2) Create Group ABC contains all objects in domain ABC 
    3) Create two runas account, ones in domain XYZ(XYZSCOMActioAccount) and the others in domain ABC(ABCSCOMActioAccount)
    4) In the account profiles, add two runas as account, ones with account XYZSCOMActioAccount and target group XYZ and the others with account ABCSCOMActioAccount and target group ABC
    Roger

  • Firefox crashes when run. Reinstalling, safe mode, and profile all bring up "Firefox has stopped working" before it ever opens a window

    I've tried every solution on other posts. I've uninstalled, including profile information, then deleted all Mozilla folders, restarted, then re-installed and I have the exact same issue.
    I'm running Vista 64, and the latest Firefox.
    I've run various virus scans, and tried uninstalling all Flash stuff.
    IE and Chrome both work, but Really slow compared to how fast Firefox ran (when it was working,) so I'd like to have it back.
    I get no real error information, but what I do is below...
    Problem signature:
    Problem Event Name: APPCRASH
    Application Name: firefox.exe
    Application Version: 24.0.0.5001
    Application Timestamp: 522fd29f
    Fault Module Name: ntdll.dll
    Fault Module Version: 6.0.6002.18881
    Fault Module Timestamp: 51da3e00
    Exception Code: c0000005
    Exception Offset: 0002abe4
    OS Version: 6.0.6002.2.2.0.256.6
    Locale ID: 2057
    Additional Information 1: 3f21
    Additional Information 2: b21eec1522c4859456611373b2bc31d4
    Additional Information 3: c437
    Additional Information 4: 4fcda050134e1df0038b45ec0bc068b3

    Hello Simonmmm, any luck if you boot the computer in [http://windows.microsoft.com/en-hk/windows/start-computer-safe-mode#start-computer-safe-mode=windows-vista Windows Safe mode with network support ](press F8 on the boot screen) and check firefox again.
    (If works in Windows Safe mode then probably you have problem with other software, like security software or maybe a system driver, that is running on your computer).
    thank you

  • How do I move all my files from one User Profile (account) into another? I needed to create a new account and want all of my files accessible in the new one.

    How do I move all my files from one User Profile (account) into another?
    I needed to create a new account and want all of my files accessible in the new one.

    ok, what you're learning right now is 101 unix, which is good. Unix is a good thing
    now: the way unix works, and macos (which uses unix underneath) the files and folders work like a hierarchy.
    the start of that tree is /
    so, if you were to do:
    cd /
    (cd means change directory)
    it will bring you at the highest branch of the file system.
    cd /Users
    will bring you to where all the users are.
    to see whats in /Users you can use your friend ls command
    ls means list files/directories
    so:
    cd /Users
    ls -la
    (the -la here means show all (even hidden) and long format (very verbose))  this flag is very optional.
    you will see
    fred
    user2
    for example.
    if you want to see the desktop of user2 you would change directory to it then list the files.
    for example:
    cd /Users/user2/Desktop
    Note that the files and directory are case sensitive, so, desktop is NOT the same as Desktop, or DESKTOP
    ls -la
    you should then be able to see everything in users2 desktop
    you could have done as well the same thing in smaller steps, for example:
    cd /
    cd Users
    cd user2
    cd Desktop
    this is the equivalent of cd /Users/user2/Desktop
    So, for your file, i don't know where it was, but know that if you log in as user2, it will directly put you in
    /Users/user2
    which most likely the file you had created from the other user was in /Users/user1
    if you copied all the files from /Users/original_user to /Users/secondUser
    most likely yes, all your mail, bookmarks etc would be copied over.
    so in your case.
    sudo chown -R seconduser:staff /Users/secondUser
    should work
    Remember that if you start a path with the character /  it means start from the root of the file system, at the highest top you can ever get.
    so
    cd /Users/fred
    is not the same as
    cd Users/fred
    unless you were in / already
    i know it may be confusing at first but it's actually very logical if you play with it.
    to simplify, think of it that / means C:\  on windows
    you can't go any higher than C:\  (in a way)
    if you're unsure which directory you're currently in, you can always type:
    pwd
    it will tell you where you are.
    for example:
    cd /
    pwd
    this shows  /
    cd Users
    pwd
    this now shows /Users
    cd /System/Library
    pwd will show /System/Library
    cd /
    cd /Users
    cd fred
    cd Library
    pwd will show /Users/fred/Library
    unix can look very scary but it's actually vital and very necessary to do tasks sometimes that would take for ever to do via the windows. This is good learning.
    so for the myfile you had created, i can't tell you where it is, at the time you created, if you can do a pwd command you'll know the path,
    ls -la  (this shows all the files where you are)
    if you see myfile in the list
    do a pwd
    whatever is return, the real location of the file would be:
    whatever pwd returned / myfile
    I hope that makes sense.

Maybe you are looking for