User accounts for running TM1 services on Windows
When you use IBM® Cognos® Configuration to start the TM1® Admin Server and IBM TM1 Server, they are registered to run as Windows services with the predefined Microsoft Windows Local System Account. You must manually change these services to run under a specific user account.
Run TM1 services under a specific Windows user account
By default, Cognos Configuration registers the following TM1 services to run under the Microsoft Windows Local System Account:
- IBM TM1 Server
- Cognos TM1 Admin Server
For more information, see Changing TM1 services to run as a specific user account on Windows.
After you make these changes, you will still be able to use Cognos Configuration to start and stop these services.
Required privileges for a specific Windows user account
The user account for running TM1 services on Windows must be included in the database owner group to access SQL tables and views.
The user account must have read and write privileges to the TM1 database and log directories.
The account must have the following privileges on the local computer:
- Act as part of the operating system
- Bypass traverse checking
- Increase quotas (Adjust memory quotas for a process)
- Replace a process level token
- Log on as a service
- Have read and write privileges on the Windows Registry item
You can use the Security Settings and Group Policy features in Microsoft Windows to configure these security privileges.
To set read and write privileges for the Windows Registry, use the Windows Registry editor.