Service Account Active Directory

Hello Community,

Please i have a question regarding the permissions required for the Service Account configured in the “Domain” configuration of the source.

Since IQService is the component that performs the provisioning operations on the Domain Controller, I am a bit confused about which account actually needs the write permissions in Active Directory.

Should the IQService service account be the one with the necessary write permissions in AD, while the account configured in the Domain configuration only requires read permissions?

Or should both accounts have read and write permissions in the domain?

Also, could you please clarify what the basic permissions are that should be granted to the service account used in the Domain configuration?

Thank you in advance for your clarification

@DivyaL_7
Aggregation tasks uses domain configuration.
Provisioning activity uses IQService setup - Write permission.
1.Domain configuration: For aggregations used by Domain Configuration Account (in IIQ Application)
Configured in the Active Directory Application → Domain Settings
Used by IIQ for aggregation (read operations)

  1. IQService Account (Windows Service)
    Runs on the Windows server where IQService is installed
    Executes provisioning operations (create, update, enable/disable accounts)

1.Domain configuration: For aggregations used by Domain Configuration Account (in IIQ Application)
Configured in the Active Directory Application → Domain Settings
Used by IIQ for aggregation (read operations)

  1. IQService Account (Windows Service)
    Runs on the Windows server where IQService is installed
    Executes provisioning operations (create, update, enable/disable accounts)

Extra permissions(domain setting account, are acceptable to have, including both read and write access.

Hi @DivyaL_7 ,

As mentioned by @narayanag , Though service account used by IQService required both Read and Write permission. Please refer below screenshot.

Hello,

Thank you for your answers,

@narayanag the answers you provided apply to IdentityIQ is it the same for ISC please?

Thank you,