A.2 Windows LSA User Rights

Windows Local Security Authority (LSA) rights and privileges are assigned to accounts or groups, and they determine how those accounts or group members may access the system. The User Rights are modified through the Local Security Policy from:

Start > Administrative Tools > Local Security Policy

  1. In Local Security Policy, go to the following:

    Security Settings > Local Policies > User Rights Assignments

  2. Verify that the File Reporter proxy rights group has the following assignments:

    • Access this computer from the network

    • Back up files and directories

    • Bypass traverse checking

    • Create a token object

    • Create symbolic links

    • Impersonate a client after authentication

    • Log on as a batch job

    • Manage auditing and security log

IMPORTANT:Absence or removal of these privileges may prevent the Engine and Agent components from functioning properly.

In some cases, Group Policy Object (GPO) settings may remove or override the necessary Local Security Policy settings and revoke the membership of the File Reporter proxy object from one or more required LSA privileges.

If GPO conflicts are detected, set up an additional GPO with just the privileges listed above and assign it to the proxy rights group for the appropriate servers.