To create a dedicated Federated Authentication domain service account and configure its domain and local group memberships, follow the steps.

To configure the domain service account for Federated Authentication

  1. Create a dedicated Federated Authentication domain service account, for example: _arfed.

  2. Ensure that the domain service account has a password that does not expire and set the following:

    1. To configure domain group membership, add the domain service account to the Domain Users group.

    2. To configure local group membership on the Active Roles server with the Active Roles Web Interface, add the domain service account to both Distributed COM Users and IIS_USRS groups.