Disable interactive Logons for SCOM SQL service-accounts in SCOM 2012 R2

sreejeet nambiar 21 Reputation points
2020-09-03T10:45:26.843+00:00

Hi,

Can we disable interactive-logons for SCOM SQL service accounts.
Will this casue any issue in SCOM?

Thanks,
Sreejeet

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,419 questions
0 comments No comments
{count} votes

Accepted answer
  1. SChalakov 10,266 Reputation points MVP
    2020-09-10T14:29:47.583+00:00

    Hi @sreejeet nambiar ,

    that is correct and this is also clearly listed here:

    Enable Service Log on for run as accounts

    Earlier version of Operations Managers has Allow log on locally as the default log on type. Operations Manager 2019 uses Service Log on by default. This leads to the following changes:

    Health service uses log on type Service by default. Operations Manager 1807 and earlier versions, it was Interactive.
    Operations Manager action accounts and service accounts now have Log on as a Service permission.
    Action accounts and Run As accounts must have Log on as a Service permission to execute MonitoringHost.exe.

    23846-image.png


    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)
    Best regards,
    Stoyan


2 additional answers

Sort by: Most helpful
  1. SChalakov 10,266 Reputation points MVP
    2020-09-03T11:00:51.003+00:00

    Hi Sreejeet,

    it depends on the MP you are using. Can you please post the MP version you are using to monitor SQL? Is this the new, server agnostic MP? If this is the case, then the account needs "Allow Logon Locally" or otherwise monitoring will not work. Here is the information from the official MP guide:

    22320-image.png

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)
    Regards,
    Stoyan


  2. SChalakov 10,266 Reputation points MVP
    2020-09-03T19:30:53.367+00:00

    Hi Sreejeet,

    a couple of importand detials in addition to my previous reply.
    The SCOM Data Reader Account, as well as all SCOM Admin (in SCOM 2019) need thise same (Logon as a Service) right also. This is well described by Kevin Holman and there is also a Management Pack, which he created to make easier for Admins to set this permission. Here are the details:

    Security changes in SCOM 2019 – Log on as a Service

    and here is the article, presenting the MP:

    SCOM 2019 Log On As A Service Management Pack Helper

    Those details are nicely described also here:

    Enable Service Log on for run as accounts

    and particular they mention the changes in SCOM 2019, compared to the previous versions:

    System Center 2019 - Operations Manager supports hardening of service accounts and does not require granting the Allow log on locally user right for several accounts, required in support of Operations Manager.

    Earlier version of Operations Managers has Allow log on locally as the default log on type. Operations Manager 2019 uses Service Log on by default.

    This being said there is a great overview of all SCOM (not SQL though) account permissions needed and it again comes from Kevin Holman:

    SCOM 2019 Security Account Matrix

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)
    Regards,
    Stoyan