What minimum permissions are required for the Synchronization Service or Quick Connect Service account?
LOCAL PERMISSIONS
In order for the product to function properly, the Service Account must have Administrator rights on the computer running the Synchronization Service or Quick Connect service. For example, the Service Account can be a member of the local Administrators group.
SQL PERMISSIONS
The product can be configured to use either Windows Authentication or SQL Server authentication for the connection to SQL Server. If you choose Windows Authentication, the connection is established using the Sync Service/Quick Connect Service account. In this case, the service account must be a member of the sysadmin role on the SQL Server.
If you choose SQL Server authentication, the connection is established with the override account you are prompted to specify when installing the product. This account must be a member of the sysadmin role on the SQL Server.
The minimum permissions required to create and update the Sync Service/Quick Connect databases are:
ACTIVE DIRECTORY PERMISSIONS
In order to post a Service Connection point to Active Directory, the Service Account requires the following minimum permissions, added via ADSIEdit:
1. The permission to create container objects in the System container
2. The permission to create serviceConnectionPoint objects in the System container
3. The permission to delete serviceConnectionPoint objects in the System container
4. The Read permission for the attributes of the container and serviceConnectionPoint objects in Group Policy containers
5. The Write permission for the serviceBindingInformation and displayName attributes of the serviceConnectionPoint objects in Group Policy containers
6/ The Write permission for the keywords attribute of the serviceConnectionPoint objects in the System container
NOTE: The Active Roles Synchronization Service and Quick Connect Sync Engines use the Service Account when accessing managed resources, such as SQL Server or the Active Roles Administration Service unless an override account is specified. This may require the addition of more permissions within the managed resource, as dictated by the desired access.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. 이용 약관 개인정보 보호정책 Cookie Preference Center