It is Not supported to have the AA service account as a member of the Protected Users group. There are inherit restrictions placed on the Protected Users group and are intentionally not configurable. These restrictions can interfere with operation of AA and its agents. In addition, as per the following Microsoft document, service accounts should never be members of the Protected Users group:
https://docs.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/protected-users-security-group
Also, users running AA console are either Domain Admins, or highly permissioned users in the AD environment so that they may execute administrative operations, and we recommend that those users not be placed in the Protected Users group.
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center