running ELA as a non-admin account

running ELA as a non-admin account

Hi,

has anyone managed to run ELA as a non-admin account? The support Guys - who had been very helpful so far - are trying to tell that it's impossible. I'm nearly certain that's not right. Most of the apps can be run as limited user.

I must not run applications under admin account for security reasons - to minimize affect of a potential compromise of ELA.

I did the following:

- create local user account
- gave it full control permission to AdventNet folder on all subfolders.
- gave all rights on the WMI namespaces
- set this account as a logon account fro ELA service

the service starts I get access to web console but it is not collecting logs.
I'm now running FileMon to find out what it's accessing beside obvious things.

ELA is a great product but the fact that it by default runs under system account and has a blank database password is very bad, especially for application that is to be used as a security/policy enforcement tool.

Any help is appriciated.

Regards



















                New to ADSelfService Plus?