{"id":3401,"date":"2015-02-05T11:26:53","date_gmt":"2015-02-05T19:26:53","guid":{"rendered":"http:\/\/www.atumvirt.com\/?p=3401"},"modified":"2015-02-05T11:26:53","modified_gmt":"2015-02-05T19:26:53","slug":"service-account-spn-registration-tip","status":"publish","type":"post","link":"https:\/\/avtempwp.azurewebsites.net\/2015\/02\/service-account-spn-registration-tip\/","title":{"rendered":"Service Account SPN Registration Tip"},"content":{"rendered":"

For a variety of software, such as SQL Server or Provisioning Services SOAP service, the services will attempt to self-register their Service Principal Name (SPN).  When they are running as Network Service, they\u2019ll be operating as the computer, which by default will have permission to set its own SPN.  However when you are using named user service accounts, you either have to register the SPN manually or grant the permission for the service to modify its own.  You can use the handy command below to grant the permission for the service to register it\u2019s own SPN when running as a user rather than a computer account.<\/p>\n

\n

dsacls <DistinguishedName_of_Service_Account> \/G SELF:RPWP;”servicePrincipalName”<\/p>\n<\/blockquote>\n

For example<\/p>\n

<\/p>\n

\n

dsacls cn=svcPVS,ou=MyUsers,dc=citrix,dc=local \/G SELF:RPWP;”servicePrincipalName”<\/p>\n<\/blockquote>\n

The distinguished name can be found by going to AD Users and Computers.  Select View, Advanced Features.  Open the user object, click \u201cAdvanced\u201d then scroll to \u201cDistinguished Name\u201d.  If you double click to edit it, you\u2019ll be able to copy and paste from the text field.<\/p>\n","protected":false},"excerpt":{"rendered":"

For a variety of software, such as SQL Server or Provisioning Services SOAP service, the services will attempt to self-register their Service Principal Name (SPN).  When they are running as Network Service, they\u2019ll be operating as the computer, which by default will have permission to set its own SPN.  However when you are using named […]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[33,43],"tags":[],"_links":{"self":[{"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/posts\/3401"}],"collection":[{"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/comments?post=3401"}],"version-history":[{"count":0,"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/posts\/3401\/revisions"}],"wp:attachment":[{"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/media?parent=3401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/categories?post=3401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/avtempwp.azurewebsites.net\/wp-json\/wp\/v2\/tags?post=3401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}