HomeLOGbinder for SP KBGetting Started GuideAppendix A: Assigning Permissions

2.4. Appendix A: Assigning Permissions

SharePoint Farm Administrator

Site Collection Administrator

WSS_ADMIN_WPG group

On SharePoint 2013, the service account has to be member of the WSS_ADMIN_WPG Windows security group.

  1. Open the Computer Management administrative tool.
  2. Under System Tools, expand Local Users and Groups, and select Groups.
  3. In the properties of WSS_ADMIN_WPG, add the service account.

Local Security Policy Changes

The following chart summarizes the changes to be made in the Local Security Policy. More detailed explanations are found after the chart.

Local Security Policy (secpol.msc) settings summary

Windows Server 2008/2012

 

Security Settings

Local Policies

User Rights Assignment

Log on as a service

add service account

This always needs to be set

Generate security audits

add service account

These need to be set if outputting to Windows Security log

Security Options

Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings

set Enabled

Advanced Audit Policy Configuration

Object Access

Audit Application Generated

set Success

Log On as a Service

  1. Open the "Local Security Policy" (secpol.msc) Microsoft Management Console (MMC) snap-in.
  2. Select Security Settings\Local Policies\User Rights Assignment
  3. Open "Log on as a service" and add user
  4. NOTE: You can also configure this via a group policy object in Active Directory. If you try to modify this setting in Local Security Policy and the dialog is read-only, it means it is already being configured via Group Policy and you'll need to configure it from there.

Generate Security Audits (SeAuditPrivilege)

  1. Open the "Local Security Policy" (secpol.msc) Microsoft Management Console (MMC) snap-in.
  2. Select Security Settings\Local Policies\User Rights Assignment
  3. Open "Generate security audits" and add user
    NOTE: You can also configure this via a group policy object in Active Directory. If you try to modify this setting in Local Security Policy and the dialog is read-only, it means it is already being configured via Group Policy and you'll need to configure it from there.

Audit Policy

Windows Server 2008/2012

Audit policy can be configured with the original top level categories as described above for Windows 2003 but most environments have migrated to the new more granular audit sub-categories available in Windows 2008 aka (Advanced Audit Policy).

Using Advanced Audit Policy Configuration allows for more granular control of the number and types of events that are audited on the server. (NOTE: The steps described here are for Windows Server 2008 R2; see TechNet for information on earlier releases.)

  1. Select Security Settings\Advanced Audit Policy Configuration\Object Access
  2. Edit “Audit Application Generated,” ensuring that “Success” is enabled. (LOGbinder for SharePoint does not require that the “Failure” option be enabled.)
    NOTE: You can also configure this via a group policy object in Active Directory.

This page was: Helpful | Not Helpful