ESP dSeries Workload Automation

 View Only
  • 1.  Issue with Service Account having permission to allow login

    Posted Mar 15, 2022 10:02 AM
    Hello,

    We have been tasked with creating "service accounts" to replace a DOMAIN account used to execute CAWA-DE jobs. Initially we encountered a "allow logon" error on the server because the CAWA-DE agent uses an account named SYSTEM, then switches user to the service account.

    Is there a workaround/setting within CAWA-DE that can help with this challenge? The issue can be handled by creating a Group Policy, but we have many servers and that doesn't seem to be the most efficient way of handling this. So we thought we'd ask to see if you have a best practice, or suggestion.

    Here is my WINDOWS Admin's spin on the issue in case I misquoted him:

    The issue that we are trying to resolve is taking a standard domain user account and allowing it to login to the machine and run the defined job in espresso / app. In order to do this we have found that editing the Security Policy in Group Policy allows the jobs to run as expected. We have multiple machines and multiple user accounts and we want to dedicate specific accounts to specific machines. They only way I can find is that we create multiple Group Policies and filter those policies to the specific machine and add the user account to the allow logon locally.

    Possibly there are some advance options using Registry and File System settings in Group Policy? That's what I can think of right now without having to use multiple Group Policy objects for machines.

    Thanks,
    Ken Ski



    ------------------------------
    DARDEN Corporation
    Orlando, FL
    ------------------------------


  • 2.  RE: Issue with Service Account having permission to allow login

    Broadcom Employee
    Posted Mar 22, 2022 06:10 AM
    Hi,

    Can you please let me know if you are looking to run jobs under GMSA account or normal Service Accounts.

    -Ravi Kiran


  • 3.  RE: Issue with Service Account having permission to allow login

    Posted Mar 22, 2022 09:05 AM

    Hi Ravi,

     

    These are just accounts they are not part of any group.

     

    Ken

     






  • 4.  RE: Issue with Service Account having permission to allow login

    Posted Mar 22, 2022 03:14 PM

    Hello Ravi,

     

    These accounts like Ken said are just regular accounts. Do these jobs support using GMSA accounts?

     

    Do you have any articles that support this?

     

    Thank you and have a great day!

    Chad Hammond