Installation
Prerequisites
Service Accounts and Groups
4 min
this document covers the service accounts and directory groups that activate requires to function to ensure activate is installed and operates reliably within your environment, several active directory (ad) service accounts and a dedicated ad group must be configured with specific permissions these accounts enable activate to interact with the systems it manages—such as active directory, exchange, file servers, and other infrastructure components—on behalf of users and administrators this article outlines the purpose of each required account and group, their recommended permission levels, and considerations for environments that cannot grant domain admin rights it also highlights the operational risks of using delegated permissions instead of domain admin access, to help you make informed decisions during setup activate orchestrator service account purpose runs the activate provisioning server and performs actions across target systems recommendation account should be a member of the domain admins group if not domain admin add to local administrators on all activate servers grant delegated permissions across active directory exchange file servers sccm / mecm office 365 azure other managed infrastructure general permissions required sql database dbo rights active directory full permissions for creating, updating, deleting users, groups, computers, distribution lists exchange manage mailboxes and distribution lists, archiving access file servers power user rights for share creation sccm / mecm as required by provisioning tasks folder manager module power user access to file servers activate web service account purpose runs the activate web portal and handles web based notifications account setup 'send as' rights on the orchestrator service account smtp relay rights local administrator on the activate web server sql server connection rights; added to the activate administrator sql database role iis membership member of iis wpg or iis iusrs local group (depending on os version) tip add activate web portal urls to group policy for client machines to classify the portals as local intranet activate installation account recommendation use the activate orchestrator service account to install activate if using a different account, it must have local administrator on the activate server sql connection rights with dbo on the activate database or rights to create databases membership in the activate administrators ad group activate administrators group purpose defines the ad group for users who administer activate setup must contain direct members only — nested groups are not supported include the following members activate orchestrator service account activate web service account (if separate) users administering activate the installation account (if required) best practice create and maintain a dedicated activate administrators group distinct from other admin groups