To grant the Federated Authentication domain service account the Act as part of the operating system User Rights Assignment on the local Active Roles server with the Local Group Policy Editor and the Active Roles Web Interface, follow the steps.

To add the Federated Authentication domain service account to the Act as part of the operating system policy

  1. Right-click the Windows Start button and select Run.

  2. Enter gpedit.msc and click OK.

  3. Navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > and select User Rights Assignment.

  4. In the right pane, double-click Act as part of the operating system.

  5. Click Add User or Group.

  6. Enter the name of the Federated Authentication domain service account and click OK.

  7. Click OK.

  8. Close the Local Group Policy Editor. The account is now present for the Act as part of the operating system policy.

    Figure 9: Local Group Policy Editor

  9. Open the Command Prompt with Administrator privileges and run gpupdate /force to refresh the local policy with the changes.

  10. Close the Command Prompt.