In order to manage shared folders in EmpowerID or execute other system management tasks on a local Windows server, you need to create a service account identity and link that identity to the Windows Server Management Web Service. By default, this service is turned on for the following server roles:
As this is the case, the local Windows server must have one of these roles assigned to it. For information on assigning server roles to Windows servers, see Configuring Server Roles. Additionally, as the Windows Server Management Web Service is hosted in IIS, the service account needs to be a member of the domain administrator's group with a password that is vaulted in EmpowerID. Vaulting the password allows the service to access the private key that was used to encrypt the password, decrypting it to gain the necessary privileges on the server.
To configure the Windows Server Agent account, you will need to do the following:
From the General tab, select Service from the Account Type drop-down.
Notice that the fields on the form change to reflect the options you have for creating a service account. Specifically, EmpowerID removes the First Name, Last Name, and Display Name fields. This keeps EmpowerID from automatically provisioning an EmpowerID Person from the account during the next inventory event. |
Select Allow me to enter a password and then type a password in the Password and Confirm Password fields.
The account must have a password before it can be vaulted in EmpowerID. |
Now that the service account has been created and added to the domain admins group, the next step is to vault the account password. This is discussed in the next section.
Now that the service account password is vaulted, the next step is to add the account to the agent. This is discussed in the next section.
From the Windows Server Agent Service Account page, search for the appropriate Windows server and then click the Name link for that server.
|