The server farm account should not be used for other services

I have created a new SharePoint Foundation 2013 Farm. I only used the Farm Configuration Wizard to create the Search Service Application, all other aspects of the Farm was created using PowerShell.
The SharePoint Health Analyzer is reporting the following error:
Title: The server farm account should not be used for other services.
Severity: 1 - Error
Category: Security
Explanation: DOMAIN\FARM_ACCOUNT, the account used for the SharePoint timer service and the central administration site, is highly privileged and should not be used for any other services on any machines in the server farm.  The following services were
found to use this account: Distributed Cache Service(Windows Service)
Remedy: Browse to
http://centraladminsite:port/_admin/FarmCredentialManagement.aspx and change the account used for the services listed in the explanation. For more information about this rule, see "http://go.microsoft.com/fwlink/?LinkID=142685".
Now I understand how to change the account used to run the Distributed Cache Service, but my query is what account should I use in the least privelage model? I have setup the following 6 accounts as per TechNet guidelines (Link)
and am not sure if one of these accounts should be used or if another account is required:
SQL Server service account
Setup user account
Server farm account
SharePoint Server Search service account
Default content access account
Application pool identity
After reviewing the TechNet article again, I don't fully understand the section titled "Service application accounts". Is the article advising me to create a seperate account for each row in the table? e.g. 1 account for Business Data Connectivity
Service, a different account for "Application Discovery and Load Balancer Service", another account for "App management" and another account for "Distributed Cache", so 4 extra accounts if I choose to install all of these services
within the Farm?
Also, what does the article mean when it says "Plan one set of an application pool and proxy group for each service application that you plan to implement."? How do I go about doing this?
Kevin Evans

After reviewing the TechNet article again, I don't fully understand the section titled "Service application accounts". Is the article advising me to create a seperate account for each row in the table? e.g. 1 account for Business Data Connectivity Service,
a different account for "Application Discovery and Load Balancer Service", another account for "App management" and another account for "Distributed Cache", so 4 extra accounts if I choose to install all of these services within the Farm?
Inder: Yes, It is suggested to have multiple service account for each service application. This increases security and dependencyof 1 account on multiple Service applications. Like below
SQL Server service
Local System account (default)
Setup user
Member of the Administrators group on the local computer
Server farm
Network Service (default)
No manual configuration is necessary.
SharePoint Server Search Service
By default, this account runs as the Local System account.
If you want to crawl remote content by changing the default content access account or by using crawl rules, change this to a domain user account. If you do not change this account to a domain user account, you cannot change the default content access account
to a domain user account or add crawl rules to crawl this content. This restriction is designed to prevent elevation of privilege for any other process running as the Local System account.
Default Content Access
No manual configuration is necessary if this account is only crawling local farm content. If you want to crawl remote content by using crawl rules, change this to a domain user account, and apply the requirements listed for a server farm.
Content Access
Same requirement as the default content access account.
Profile import Default Access
Same requirements as server farm.
Excel Services Unattended Service
Must be a domain user account.
http://technet.microsoft.com/en-us/library/cc263445%28v=office.15%29.aspx
Also, what does the article mean when it says "Plan one set of an application pool and proxy group for each service application that you plan to implement."? How do I go about doing this?
Inder: Each service account has a application pool and you can plan to use same application pool for multiple
service accounts if required. These application pool are then consumed by proxy connection
of each service application. On service application pool, you can see all the service applications and its proxy connection.
If this helped you resolve your issue, please mark it Answered

Similar Messages

  • How do I make it so that the one computer that has the main itunes account on it be used on other computers, when it comes to backing up phones and not deleting data off of phone that isnt on that computer itunes becasse its all on the one main computer

    how do I make it so that the one computer that has the main itunes account on it be used on other computers, when it comes to backing up phones and not deleting data off of phone that isnt on that computer itunes becasse its all on the one main computer. Baiscally the problem is that one comuter and one account has always been sued for eey persons itunes. Now if we want to be able to backup and use itunes on our own computers fro our iphones and such, how will all he data that is on our phones not be deleted once its plugged into a new computer? Also, is theere a way to get all the stuff on thw current itunes onto each computer, via differtn account name?

    option discovered in preferences. Really this and any feature that moves deletes or edits a users data should as far as possible be OFF BY DEFAULT. It shouldn't by default and without the users specific say do this dangerous and unnecessary thing without even letting the user know what it's doing!!! And then cause me a few hours (as i'm new to mac) searching for the option so as to switch it off. If i hadn't noticed the status cage declaring that it was copying files then i might never have twigged that this insane thing was occurring. And if i hadn't of noticed i would have been left maintaining the contents of the folder i copied the files to, the folder which as far as i was informed and so believed was also the location of the music files i was playing. How does Apple justify this 'genius' piece of software non-design? Surely it will hurt no one if this was off by default for new users - overall at least i dare say it would cause a lot less distress in the future for the unsuspecting public at large. Thanks for the support.

  • GL Account Should not be used

    Dear Friends,
    For PO-4111127913, GL account 726234 was used in the PO - item details, invoice tab.
    The user now says that the GL Account should not be used untill 2010.
    What is the most simple way of blocking the GL? If any user tried to select the GL in the PO, he must not able to use it or the system should issue a warning or error message  " you cannot use this GL Account".
    Already Some POs with this GL Account 726234 has been posted. IR and FI Documents were posted. How to reverse everything from po,IR and FI Documents.
    Please suggest?
    Regards
    Sridhar
    Edited by: Sridhar M on Dec 8, 2009 1:24 AM
    Edited by: Sridhar M on Dec 8, 2009 1:25 AM

    Hi,
    Blocking an account is usually done for closing and reconciliation purposes so that no further activity can be posted to that account. The account can be unblocked when activity can resume.
    Menu Path
    From the SAP R/3 screen, select the path:
    Accounting >> Financial accounting >> General ledger >>
    (new menu) Master records >> G/L Accounts >> Individual Processing >> Centrally
    Fast Path
    At the Command Line, enter:
    /NFS00
    Block G/L Acct: Request Screen
    Key Fields (Complete or Review)
    Account number
    Enter the G/L account number to be blocked / unblocked.
    (F4) to access a matchcode.
    Company code
    Enter CUR for MIT.
    Next Step...
    (ENTER) to access the Block G/L Account Screen.
    Block G/L Account Screen
    Use this screen to block / unblock the account for different postings.
    Key Fields (Complete or Review)
    Posting block
    All company codes
    To block the account from being posted to CUR, the MIT company code, click in the box beside this field.
    Planning block
    All company codes
    To block the account from planning, click in the box beside this field. Note: To unblock the account, click in the box to deselect.
    Next Step...
    (F11) to save the blocking / unblocking changes made to the G/L account. The Block G/L Acct: Request Screen reappears with a message that the changes were made.
    Thanks,
    Rajesh.

  • HT204053 in my iphone settings, my phone has not allowed me to change the apple id account i want to use for icloud

    in my iphone settings, my phone has not allowed me to change the apple id account i want to use for icloud
    im using another id for my purchases, which was the same one set for icloud, but i wasnt using icloud, now i made a new id, and want to set it for icloud, but its not offering me the chance to change it in icloud settings

    Welcome to the Apple Community Rozie.
    In order to change your Apple ID or password for your iCloud account on your iOS device, you need to delete the account from your iOS device first, then add it back using your updated details. (Settings > iCloud, scroll down and hit "Delete Account")

  • The visual Studio Test controller service on local computer started and then stopped. Some services stop automatically if they are not in use by other services or programs

    We are using VS2013 Premium. i have installed vs2013 Test controller in my dev environment. While i am configuring (https://msdn.microsoft.com/en-us/library/hh546459.aspx) getting error message in
    the Configuration summary dialog box displaying following error's : 1. Failed to Configure TFS Team Project Collection, 2. Could not complete operation as the time out expired. ''
    I have checked the "visual Studio Test controller " in the
    Services --> Administrative. Its automatically stopped the service. When i started the manually its showing message like as 'The visual Studio Test controller
    service on local computer started and then stopped. Some services stop automatically if they are not in use by other services or programs'
    Please guide me how to resolve this problem. 
    Thanks in Advance...

    Hi Divakar,
    What’s the version of your TFS?
    How do you configure the test control?
    Please make sure you are specify the team collection instead of team project.
    On the other hand, you may enable test controller logs. (You could share the log file on the OneDrive)
    # How to enable test controller logs
    http://blogs.msdn.com/b/aseemb/archive/2009/11/28/how-to-enable-test-controller-logs.aspx
    Regards
    Starain
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • When starting the AMDS it just says "the apple mobile device service on local computer started then stopped. Some services stop automatically if they are not in use by other services or programs."... help?

    when trying to fix the ipod syncing/recognition by starting the AMD (apple mobile device) in admin tools section on my computer it came up with the message in the question aboce (the apple mobile device service on local computer started then stopped. Some services stop automatically if they are not in use by other services or programs.)
    i have restarted my comp etc and reinstalled itunes... recurrent issue.
    note - i wiped my ipod before this issue occurred, does this affect the problem?

    I would start with
    Removing and reinstalling iTunes, QuickTime, and other software components for Windows Vista or Windows 7
    or
    Removing and Reinstalling iTunes, QuickTime, and other software components for Windows XP
    Next see the the other actions of the following concerning the AMD
    iOS: Device not recognized in iTunes for Windows

  • SOME SERVICES STOP AUTOMATICALLY IF THEY ARE NOT IN USE BY OTHER SERVICES OR PROGRAMS

    I currently install a software that needs to have a services run in order to for the license to be detected.When i run the services manually i got this error message
    'THE UBSLAN_LDR SERVICE ON LOCAL COMPUTER STARTED AND THEN STOPPED.SOME SERVICES STOP AUTOMATICALLY IF THEY ARE NOT IN USE BY OTHER SERVICES OR PROGRAMS'
    What can cause this and solution please

    Hi kuados  ,
    Thanks for posting here.
    After reading your posting I understand that when you establish USBLAN_LDR service on windows server 2008, system prompt an error message.
    According the information what you provided right now, it’s hard to determine what cause this issue, you may like to post more information about your environment
    (Event log ,Other  System prompting etc… ).
    Please check if it worked with assign a  Local System account instead of Local Service account to run this service.
    Open service MMC snap-in.
    Right UBSLAN_LDR service , and click “properties”.
    Click “Log on” tab , and assign a local account for running this services.
    Seems this issue related to a third party software, I suggest to consult software vendor for future troubleshooting.
    Please understand that I don't mean to bounce you between different solution provider as I am fully aware how time consuming this can be. However, they really are
    in a better position to be able to assist you with this issue as they may have experienced similar issues.
    Thanks for your understanding.
    Tiger Li
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • Sales office not available and SHOULD not be used for determination

    Hi experts,
    I am encounting an issue with the organizational model.
    We do not want the sales office to be determined through the org model, we just want to be able to add it to the right sales areas in BPs or transactions.
    I have build ang enhanced org model where the sales offices and groups are assigned to more sales areas. I have not marked the determination on the office and groups, since I do not want to determine this automatically and since if I mark this, my pop-ups for the transactional data determination becomes impossible to overview.
    However, if I do not mark the determination in the sales offices and groups, they are not availeble in the drop downs for Bps and transactions.
    Can someone please advise how to solve this?
    Thanks

    Robert,
         As soon as an EntryProcessor or EntryAggregator get delivered to the server nodes, it will get executed regardless of the requestor's state.
         In regard to long-running operations the only thing you have to be conscious about is a number of worker threads allocated for such a processing. Since there is a single client thread issuing a request, it would suggests allocation as many worker threads (across the cache server tier) as there are client thread (across the presentation/application tier).
         Regards,
         Gene

  • FIOS CUSTOMER SERVICE IS THE WORST AND I AM NOT INSTALLED YET FOR NEW SERVICE!!

    So on May 20th I signed up for the triple play service for 59.99 with 2 year agreement with 4 tvs being installed with equipment, home phone service and internet/wifi. On May 25th I realized that I needed to change 3 of the boxes on my order to different ones so I called the 1800 verizon number and spoke with a woman agent who said she was able to make the changes and also wanted to verify on my order that I am getting everything that I am entitled to as a new customer to Fios so I told her okay. Never did this incompetent woman tell me that she was changing my ENTIRE ORDER. At the end of the call she said she made the changes to the equipment and gave me a confirmation number for the change.
    Today May 26th memorial day, I receive an email from Verizon confirming the changes that they said I made to my ENTIRE PLAN AT 2:46PM. She cancelled out my original order I placed online and switched it to another plan that was much higher at 79.99 with additional services I did not request and the EQUIPMENT WAS NEVER CHANGE, the whole reason for my call. After reading the email and going back to the original email I received after placing my order on May 20th I called Verizon customer service. The woman I spoke to, again incompetent and unsympathetic to the situation  couldn't tell me why my order was change. She couldn't tell me anything and was silent the most of the **bleep** time. (Don't these people work for the same company, she should have been able to see exactly what went on in her system.)
    When she did speak she said she was reviewing what was different from the last order. I said there is only ONE order that I placed and the only changes that I wanted was for the equipment. She didn't say anything after that. So after almost 10 minutes of silence, I said well at this point are you able to make the necessary changes to change me back to the original plan I signed up for with the correct equipment I needed. She told me NO, plain out.
    Are you kidding me! I never authorize the change of my package, only to the equipment and your telling me you can't do nothing about it. The woman showed no type of empathy for the situation, nor apologize on behalf of Verizon and the lady who screwed up my family order. It was like she didn't care and then said If I want to cancel the order she couldn't do that and that I would have to call back tomorrow May 27th and do so. (Shouldn't a customer service agent do whatever they could to KEEP YOU as a customer and not send you to cancel the order...big problem)  I haven't been with verizon for many many years and thought I should give you people a try. The way this initial contact with this company has been has truly set the tone of how these people/company will treat me and my family for the next 2 years. This transaction has not been smooth and not somehting that I would rave about to my friends/co workers/community, I will tell them to NOT choose this company. I see now that Verizon customer service agents will add what ever they want to your account that you didn't authorize, tell you lies and not correct anything that they are at fault of.

    Your issue has been escalated to a Verizon agent. Before the agent can begin assisting you, they will need to collect further information from you.Please go to your profile page for the forum, and look in the middle, right at the top where you will find an area titled "My Support Cases". You can reach your profile page by clicking on your name beside your post, or at the top left of this page underneath the title of the board.
    Under “My Support Cases” you will find a link to the private board where you and the agent may exchange information. This should be checked on a frequent basis as the agent may be waiting for information from you before they can proceed with any actions. To ensure you know when they have responded to you, at the top of your support case there is a drop down menu for support case options. Open that and choose "subscribe".
    Please keep all correspondence regarding your issue in the private support portal.

  • HT1918 The credit on my account is not being used for purchases

    I have redeemed two cards and am not being given the option of using the credit on my account from the cards purchased. I do not want to use a credit card at all. Why is Itunes so inefficient? How can I use the credit?

    Use migration assistant.
    See http://pondini.org/OSX/MigrateLion.html
    Although this is only up to Mountain Lion it is still relevant to Mavericks.. only expect Mavericks to kick and buck a lot more.

  • I have 2 emai accounts which worked perfectly on iphone 4 but on iphone 5 my msn account wont let me reply to emails sent to that account, it leaves the message in my outbox saying recipient was rejected by the server because it does not allow relaying

    I have 2 email accounts which both worked perfectly well on my ipone 4 but since going over to iphone 5 my msn account will not allow me to reply to any emails. It places a message on my screen stating a copy has been placed in your Outbox. The recipient   @.com was rejected by the server because it does not allow relaying. Any ideas on how I can sort this. Would it be worth deleting my MSN account ant putting re-inputting the details again?

    Your email provider has blocked the standard mail port 25 for sending emails and is requiring a different port. This is to avoid mail relays that use mail clients to send spam. You need to find the port that is used by your provider for sending outgoing mail. Then change the settings in your email account on your phone to match the port. You will also have to provide some security credentials for the account.
    You can also try deleting the email account from your iphone, and the adding the email account back as this will many times set the correct port for sending emails.
    You could also do a Google search on the the settings for your device with your email provider. That will provide you with the proper settings.

  • Messaging Server 4.1: Received mail is not returned to the sender if the receiving local account does not exist.

    I have found that received mail is not returned to the sender if the receiving
    local account does not exist. This problem occurs even if I use Console to
    enable the Return message to sender option under the error handling methods.
    In addition, I have used the configutil
    to confirm that I have set the value
    for Unknown account action to "13," which corresponds to the settings "Return
    message to sender," "Notify the postmaster via email," and "Log the error in
    the log file." Yet, in this situation, an error message is being sent to
    postmaster, but not to the sender, and the error is not being recorded in the
    log file.
    <P>
    Do the following steps:<BR>
    <P>
    <OL>
    <LI>From Console, open the appropriate Messaging Server.
    <LI>Click the Configuration tab.
    <LI>Open the Services folder.
    <LI>Select SMTP.
    <LI>Click the System tab.
    </OL>
    <P>
    Check the "Domain handled by this server exclusively" field to make sure that
    your mail domain is listed. If your mail domain is not listed, then Messaging
    Server will assume that there is another mail server that is handling the
    domain listed and will forward requests to this server.
    <P>
    For more information, please see the document <I>Messaging Server
    Administrator's Guide</I>, Chapter 3, Configuring SMTP Services at <BR>
    http://docs.iplanet.com/docs/manuals/messaging/nms41/ag/smtp.htm#1010371

    On Thu, 12 Dec 2013 16:16:02 +0000, lpphiggp wrote:
    > I'm seeing this XTCOM error occur all over our /var/log/messages for one
    > server, running SLES11sp2 / OES11/sp1;
    >
    > I don't really know what this is even for. We don't use NetStorage or
    > iPrint even, this server only does basic NCP file serving, DHCP, and
    > hosts a GroupWise PO.
    > Is this anything to be concerned about?
    If this:
    http://www.linuxquestions.org/questi...entication-vs-
    edirectory-825043/
    is to be believed, it seems to indicate that your NAM configuration on
    this server is not valid. I'm not seeing this message here on the OES
    servers I looked at, and NAM is working correctly here.
    David Gersic dgersic_@_niu.edu
    Knowledge Partner http://forums.netiq.com
    Please post questions in the forums. No support provided via email.
    If you find this post helpful, please click on the star below.

  • Just got Prosoft drive genius 3 software, and it's telling me that the external hard drive that i am using for my time machine back up drive needs to be defragmented.  is it wise to do this or should i not??

    just got Prosoft drive genius 3 software, and it's telling me that the external hard drive that i am using for my time machine back up drive needs to be defragmented.  is it wise to do this or should i not??

    Let's hope a couple things: that you have bootable clones of your drives also; that the backup drive for TimeMachine has over 3x capacity of the data you plan and are storing. I would also switch TM backup drives so you have a 2nd.
    Fragmented free space affecting performance happens when the drive is too full which may mean there isn't enough free space for a full backup set.
    1.5TB for backing up 500GB, while WD Green 3TB is $140 and WD Black 1.5TB is, about the same price.
    I'd be worried about the integrity and directory, and whether you can afford to lose that drive. Defragging is also a very slow operation. the ideal: to just clone a drive, or start over with another drive and wait. cloning TM volumes has not been done or has it? SuperDuper hoped to but I don't think they or Bombich's CCC made it there.
    Trouble with highly fragged is when free space gets to 20% normally, 1/3 or so though for TM volumes, and finding where and a chunk of space for the file being written. Does TM use large spare image files of like 2GB?
    Best would be to ask in the TimeMachine section Snow Leopard
    https://discussions.apple.com/community/mac_os/mac_os_x_v10.6_snow_leopard?view= discussions#/?tagSet=1009
    where there are some good FAQ and tutorials, and people that know the ins-and-outs and shortcomings.

  • "The 'charCode' property of a keyup event should not be used. The value is meaningless." Is this possibly caused by a virus?

    I don't know what's wrong with my Mac Mozilla Firefox, version 3.6.8, but today, it started alerting me about an error message on the "Error Console". In every website I visit, it tells me: "The 'charCode' property of a keyup event should not be used. The value is meaningless." Is this possibly caused by a virus?
    I saw a pop-up which did not allow me to click it when I scatter the windows on my Mac. I was using Private Browsing, with pop-ups disabled, but one pop-up managed to get passed my settings, and open in another window. It would not allow me to select it, so all I did was to close Firefox, and start a new session. So far, everything has been normal, I also deleted the cookies it installed.
    But, I still keep seeing that "Error Console" notice under my "Tools" on the Menu Bar, and when I clicked on it, it listed errors (such as what I listed above).
    Would someone explain this to me?
    Thanks for your help!

    The messages you see in the Error Console are mostly to assist the web site's author in resolving compatibility problems. Some of them can assist you in determining why a web site doesn't work as intended. The one you mentioned doesn't sound that suspicious, except that it occurs on many sites. Perhaps one of your add-ons is trying to monitor what you type?
    To diagnose whether this is caused by an add-on or one of your settings, you could try the following:
    First, make a backup of your computer for safekeeping. To back up Firefox, see [https://support.mozilla.com/en-US/kb/Backing+up+your+information Backing up your information].
    Next, try starting Firefox in Firefox
    [http://support.mozilla.com/kb/Safe+Mode Safe Mode]. Be careful not to "reset" anything permanently if you didn't back up.
    Does that resolve the errors? If so, then an add-on usually is the culprit. If not, try creating a new (blank) profile: [http://support.mozilla.com/kb/Managing+profiles Managing profiles].
    If the new profile works correctly, you can choose between further research on your old profile or moving key settings like bookmarks from your old profile to the new one. [https://support.mozilla.com/en-US/kb/Recovering+important+data+from+an+old+profile Recovering important data from an old profile].
    Hope this helps.

  • I keep getting the message your account is not valid for use in the US Store. You must switch to the Canadian store before purchasing. I have selected the Canadian store, but I still keep getting the same message.

    I keep getting the message: Your account is not valid for use in the US Store. You must switch to the Canadian Store before purchasing. I have selected the Canadian store, but still keep getting the same message. Any suggestions?

    Hi hi-liter,
    Are you certain that you are signed onto iTunes & Apps in the Canadian store?
    Settings>iTunes & App Stores, click on your AppleID, and then click on View AppleID. Type in your password, then click on Country/Region. Once there, follow the prompts and then select the Canadian Flag.
    Hope that helps!
    Cheers,
    GB

Maybe you are looking for