By default the Control-M/Agent Windows service is configured to start as "LOCAL SYSTEM", and cannot start other Windows Services. These other Windows Services can be started by an Administrator manually. |
Legacy ID:KA393357 - Create a Windows Administrator User and assign the following privileges/policies to this user. Alternately, use an existing Windows Administrator user. - When the agent service is defined as This Account, the user that the agent is running with must have List Folder Contents permissions for the agent drive. - Under the "Policy" column, find the following policy: - Double-click o open the properties of the policy and then add the user or group to this policy. Repeat for the 5 policy mentioned above. - Exit "Local Security Policy" management console - Open the "Service" management console by running "services.msc" Logon As User option.When this option is enabled the Agent submits the job under RunAs user. The RunAs user must have an additional privilege associated in the local security policy. "Log on as a Batch Job". Ensure as well that 'Deny log on as a batch job' is disabled for the "Run As" User.There maybe additional privileges that are required based on the job's requirement. BMC recommends that additional policies by applied as well however they are NOT a requirement for the Agent to launch the job. These additional policies are: i. Act as part of Operating System (review local security policy prior to enabling this option) ii. Increase Quotas (Adjust memory quotas for a process) iii. Replace a Process Level Token Related Products:
|