Page tree

When using the PATROL Console to configure or manage the PATROL KM for Microsoft Windows OS, verify that the console connection account, the account that you use to connect to the agent, meets the following requirements:

  • Is a member of the local Administrators group on the agent computer
  • Has the right Log on as a Batch Job assigned

If the console connection account does not meet these requirements, the features described in the following table are not available

Console features that require local admin rights

The following table lists the features that are require local admin rights:

KMFunctionalityMenu commandBehavior
PATROL KM for Microsoft Active DirectoryRunning the AD Operations reportAD Operations ReportSystem Output details the need for a sufficient connection account. One can grant read/write permission to the connection account to %PATROL_HOME%\Patrol\tmp for this to work or add the connecting user to the Server Operators group on the agent computer.
PATROL KM for Microsoft Cluster ServerDeleting account informationDelete Access InformationMessage is displayed with failure to remove account information.
PATROL KM for Windows Domain ServicesRunning an availability report with the Remote Servers KMAvailability ReportA blank report is displayed. This report uses Agent history data. Give the connecting account full access to the %PATROL_HOME%\tmp directory structure
Running a Server Information report with the Remote Servers KMServer Information ReportA blank report is displayed. Give full access to the %PATROL_HOME%\tmp directory structure to the connecting account.
Displaying information about a user using the Users KMDisplay User InformationA blank report is displayed. Give the connecting account full access to the %PATROL_HOME%\tmp directory structure
Stopping or Starting the WINS serviceStart/Stop WINS ServiceA message is displayed detailing the inability to access the resource. Add the connecting account to the built-in Administrators group on the Agent computer.
Starting or stopping the DFS serviceStart/Stop DFS ServiceMessage is displayed indicating inability to access service. Add the connecting account to the built-in Administrators group on the Agent computer.
Running the DFS Operations reportDFS Operations ReportReport is blank. Give the connecting account full access to the %PATROL_HOME%\tmp directory structure, or add the account to the Server Operators group on the Agent computer.
PATROL KM for Windows Domain Services, continuedStarting or stopping the DFS Replica serviceStart/Stop Replica DFS ServiceMessage is displayed indicating inability to access service. Add the connecting account to the built-in Administrators group on the Agent computer.
Disconnecting DFS usersView/Disc. Connected UsersUsers are not disconnected. Add the PATROL Agent default account to the Account Operators, Print Operators or Server Operators built-in group.
Compressing the DHCP databaseCompress DHCP DatabaseMessage is displayed indicating inability to access database. Add the connecting account to the built-in Administrators group on the Agent computer.
Starting or stopping the DHCP serviceStart/Stop DHCP ServiceMessage is displayed indicating inability to access service. Add the connecting account to the built-in Administrators group on the Agent computer.
Stopping or Starting the DNS serviceStart/Stop DNS Server ServiceA message is displayed detailing the inability to access the resource. Add the connecting account to the built-in Administrators group.
PATROL KM for COM+Starting or Stopping the DTCStart/Stop DTC ServiceAccess Denied message is displayed. Add the connecting account to the built-in Administrators group on the Agent computer.
Viewing application propertiesView application propertiesAn unable to view message is displayed. Add the connecting account to the built-in Administrators group.
PATROL KM for MSMQStarting or stopping the MSMQ serviceStart/Stop MSMQ ServiceAccess Denied message is displayed. Add the connecting account to the built-in Administrators group on the Agent computer.
PATROL KM for Microsoft Windows OSConfiguring Blue Screen KM (NT_BSK) system recovery actionsSet System Recovery ActionsA pop-up window displays a message stating that the connecting user must have administrator privileges.
Configuring Blue Screen monitoring (NT_BSK)Configure BlueScreen MonitoringYou can use the three options provided to configure the KM. The KM looks for the crash dump file as well as the event (ID 6008).
Configuring Windows operating system quotasConfigure Operating System QuotasThe KM prompts you to supply an administrative account that includes the user right Log on as batch job on the PATROL Agent computer. For more information, see Supplying an impersonation account.
Managing Windows services, such as starting and stopping services or changing service startup propertiesManage Windows Operating System ServicesThe KM prompts you to supply an administrative account that includes the user right Log on as batch job on the PATROL Agent computer. For more information, see Supplying an impersonation account.
Viewing the Windows security event logWindows Event ViewerYou can view event logs, other than the security event log, but you cannot change properties. Add the right Manage Auditing And Security Log to the agent account and the console connection account.
Managing Windows event logsWindows Event ViewerThe KM prompts you to supply an administrative account that includes the user right Log on as batch job on the PATROL Agent computer. For more information, see Supplying an impersonation account

Supplying an impersonation account

On Windows 2000, the user right, Act as part of the operating system is also required by the PATROL Agent when it impersonates an account. That is, when it uses an account that you enter to perform the requested action. If the agent default account has this right and it has the user right Log on as batch job, but PATROL still cannot perform the request, you may need to also assign the user right Bypass traverse checking to the PATROL Agent default account.

  • No labels