Hello,
could there be any reason for the TM1 AD-user to have Domain-Administrator rights? The documentation says that to use the Integrated Login you need a AD-user with sufficient rights like specific file system permission on the sever and directory listing permissions for checking the users.[0] Is there any other use case where you would need an AD-user with more privileges?
Thanks in advance,
Cedric
[0] https://www.ibm.com/docs/en/planning-an ... __title__5
Domain-Administrator for TM1?
-
- MVP
- Posts: 3654
- Joined: Fri Mar 13, 2009 11:14 am
- OLAP Product: TableManager1
- Version: PA 2.0.x
- Excel Version: Office 365
- Location: Switzerland
Re: Domain-Administrator for TM1?
The main issue is access to network resources. The account running the TM1 service doesn't need to be domain admin, but the account needs to have sufficient rights to do what it needs to do, e.g. read from and write to network shared folders which are located on another machine on the network, use the command line to create/delete diretories and files, use the command line to launch another executable, connect to an ODBC database on the network with WIA to run a query to load data.
(The above is just some examples of common tasks the TM1 service account would need to perform, it isn't an exhaustive list.)
(The above is just some examples of common tasks the TM1 service account would need to perform, it isn't an exhaustive list.)
Please place all requests for help in a public thread. I will not answer PMs requesting assistance.