On the Select components screen, define the account under which the services will run by specifying Logon account for the agent service. You can select one of the following:
Service User Accounts are Windows system accounts that are used to run services. The advantage of this setting is that the domain security policies do not affect these accounts' user rights. By default, the agent runs under the Local System account.
The account name will be Agent User for the agent.
If you install the agent on a domain controller, the system prompts you to specify existing accounts (or the same account) for the agent. For security reasons, the system does not automatically create new accounts on a domain controller.
If you chose the Create a new account or Use the following account option, ensure that the domain security policies do not affect the related accounts' rights. If an account is deprived of the user rights assigned during the installation, the component may work incorrectly or not work.
Privileges required for the logon account
A protection agent is run as a Managed Machine Service (MMS) on a Windows machine. The account under which the agent will run must have specific rights for the agent to work correctly. Thus, the MMS user should be assigned the following privileges:
How to assign the user rights
Follow the instructions below to assign the user rights (this example uses the Log on as service user right, the steps are the same for other user rights):
Important Ensure that the user which you have added to the Log on as service user right is not listed in the Deny log on as a service policy in Local Security Policy.
Note that it is not recommended to change logon accounts manually after the installation is completed.