Unconfiguring a service account deactivates the policy group in the mangement console and disables console access to the policy file and keystroke logs on the primary policy server.
To unconfigure service account
- Log in as supervisor or an Active Directory account with rights to change System Settings; that is, an account in the Console Administration role.
 - From the top-level Settings menu, navigate to System settings | Privilege Manager.
 - Click Unconfigure service account next to the primary policy server listed.
 - On the Unconfigure Service Account dialog, enter credentials to log onto the primary policy server and click OK. 
Note: This task requires elevated credentials.
 - Verify that the Active box is not checked.
 
Note: When you unconfigure a service account, the mangement console,
- leaves the "questusr" and the corresponding "questgrp" account on the host.
 - removes questusr from the pmpolicy and pmlog groups.
 - leaves questusr as an implicit member of questgrp.
 - removes the policy group SSH key from questusr's authorized_keys, /var/opt/quest/home/questusr/.ssh/authorized_keys.