<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Configuring Run As Accounts and Profiles in OpsMgr – A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx</link><description>Update 11/29/2012: &amp;#160; This article is current as of the 6.3.173.1 version of the SQL MP. &amp;#160; Using RunAs accounts and profiles is an often poorly understood area of OpsMgr.&amp;#160; As I began to investigate setting this up for the SQL MP, I quickly</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Configuring Run As Accounts and Profiles in OpsMgr – A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3568003</link><pubDate>Fri, 19 Apr 2013 22:08:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3568003</guid><dc:creator>Keithk</dc:creator><description>&lt;p&gt;Kevin,&lt;/p&gt;
&lt;p&gt;Thanks for your work here. &amp;nbsp;I am having a problem recently where a SQL instance was recently encrypted and as a result the SCOM agent is not able to query the MSCluster namespace via WMI. &amp;nbsp;I am getting repeating event 5605 in the app log of the cluster node. &amp;nbsp;Here is an article that appears to describe the problem I am having.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/2590230?wa=wsignin1.0"&gt;support.microsoft.com/.../2590230&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;As a nice bonus for me, this seemed to cause all SQL and cluster monitors on that SQLcluster to thrash offline and online causing an impressive state storm filling up our Ops DB and taking the RMS offline. &amp;nbsp;Temporarily placing the SQL/cluster objects in maintenanace mode addressed the state storm and allowed me to free space and make sure the RMS was back online again. &amp;nbsp;However now I am not monitoring the SQL or clustered objects on that cluster so I need to find a way to address the root cause. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;I am not sure, but could perhaps you could confirm if setting up a Run as account with higher level permissions to execute the SCOM SQL/Cluster workloads on these encrypted instances would address this issue?&lt;/p&gt;
&lt;p&gt;I am concerned that it won&amp;#39;t because the eventid suggests that the resolution has to do with changing the authentication level to Pkt_Privacy. &amp;nbsp;&lt;/p&gt;
&lt;p&gt;Any thoughts?&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Keith&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3568003" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in OpsMgr – A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3553699</link><pubDate>Wed, 20 Feb 2013 01:45:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3553699</guid><dc:creator>Aaron</dc:creator><description>&lt;p&gt;Hi Kevin, thanks for this information. My concern is if you are using the Local System account for the “Default Agent Action Account”, what would stop someone from making the agent run scripts that could potentally do damage to the system?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3553699" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3488926</link><pubDate>Wed, 28 Mar 2012 08:47:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3488926</guid><dc:creator>Chris</dc:creator><description>&lt;p&gt;You wrote: &amp;quot;Our goal is to make the initial discoveries – which target the “Windows Server” class, run under the default agent action account. &amp;nbsp;THEN – ALL subsequent discoveries should run under the SQL Discovery Profile/Run As account. &amp;nbsp;Therefore – we should add the “SQL DB Engine” class.&amp;quot;&lt;/p&gt;
&lt;p&gt;Most of my sql servers can be monitored using the default action account (local system), but I have some sql servers that need to be monitored using another account (domain account). How do I target this runas account? I can not use the SQL DB Engine class because then all sql servers will use this run as account.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Chris&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3488926" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3470316</link><pubDate>Mon, 12 Dec 2011 13:49:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3470316</guid><dc:creator>JohnB</dc:creator><description>&lt;p&gt;And how do I distribute it?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3470316" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3470031</link><pubDate>Fri, 09 Dec 2011 16:36:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3470031</guid><dc:creator>Kevin Holman</dc:creator><description>&lt;p&gt;Cannot be resolved generally means you did not distribute the run-as account to that particular health service.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3470031" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3470030</link><pubDate>Fri, 09 Dec 2011 16:24:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3470030</guid><dc:creator>JohnB</dc:creator><description>&lt;p&gt;I went through your directions.. &amp;nbsp;Now I just got dozens of alerts saying &amp;quot;An account specified in the Run As profile &amp;quot;Microsoft.SQLServer.SQLDefaultAccount&amp;quot; cannot be resolved.&amp;quot;&lt;/p&gt;
&lt;p&gt;What is causing that?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3470030" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3428464</link><pubDate>Thu, 12 May 2011 14:25:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3428464</guid><dc:creator>Matthew Cater</dc:creator><description>&lt;p&gt;Hi Kevin - I have maybe a little bit different problem. &amp;nbsp;I would like to configure a custom RunAs profile for agent installation, and use a RunAs account associated with it. &amp;nbsp;The reason for this is I&amp;#39;m an admin for SCOM, but not domain admin, and our domain security policy has things pretty tightly locked down. &amp;nbsp;There is an installation account configured with Local Admin rights on the servers, and we are using a domain user service account for the agent action account. &amp;nbsp;All the documentation I&amp;#39;ve found says the agent installation is only able to be performed by the Managemnt Server action account, or an optional account that doesn&amp;#39;t save credentials. &amp;nbsp;Is there any way around this that you know of?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3428464" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3392284</link><pubDate>Mon, 07 Mar 2011 18:05:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3392284</guid><dc:creator>Kevin Holman</dc:creator><description>&lt;p&gt;Hi Graham - &lt;/p&gt;
&lt;p&gt;I didnt. &amp;nbsp;I started to... got some SDK code in C#, but what I really want is for this to be included in the product, or it to be portable to PS script.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3392284" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3390112</link><pubDate>Fri, 25 Feb 2011 10:23:19 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3390112</guid><dc:creator>Graham</dc:creator><description>&lt;p&gt;Hi Kevin&lt;/p&gt;
&lt;p&gt;Did you ever get a chance to look at this in more depth?&lt;/p&gt;
&lt;p&gt;&amp;quot;Yes - that will be a soon to come post - I am going to get some assistance and figure out a good way to handle dynamic run as account distribution using the SDK - since the UI leaves a lot to be desired. &amp;nbsp;Stay tuned. &amp;quot;&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Graham&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3390112" width="1" height="1"&gt;</description></item><item><title>re: Configuring Run As Accounts and Profiles in R2–A SQL Management Pack Example</title><link>http://blogs.technet.com/b/kevinholman/archive/2010/09/08/configuring-run-as-accounts-and-profiles-in-r2-a-sql-management-pack-example.aspx#3385510</link><pubDate>Mon, 07 Feb 2011 19:38:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3385510</guid><dc:creator>Kevin Holman</dc:creator><description>&lt;p&gt;@Vivak - &lt;/p&gt;
&lt;p&gt;Since your SQL server is ON the RMS.... this wont use Local System. &amp;nbsp;This will use the Management Server Action Account as the default action account for all monitoring workflows.&lt;/p&gt;
&lt;p&gt;Therefore - your MSAA needs the rights to SQL.... OR you need to set up the Run-As account and profile to be used by the SQL MP for the RMS. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3385510" width="1" height="1"&gt;</description></item></channel></rss>