Running ActivID CMS as a Standard User

Prerequisites: Before changing permissions for the user account under which ActivID CMS runs, it is imperative that you first test and successfully issue a smart card. The ability to complete this important task is an assurance that ActivID CMS is correctly configured. If you are unable to successfully issue a smart card, then ActivID CMS is not configured correctly.

This section describes the process that explains how to configure the IIS server, Microsoft Windows, and ActivID CMS to run under a non-administrator user account, and it defines exactly what rights are required.

ActivID CMS is generally installed using a user account with Local Administrator rights to the system upon which it runs. While being the recommended method of installation, following the installation of ActivID CMS you must ensure that this user account is modified to only grant it the necessary rights required to perform ActivID CMS functions.

It is recommended that rights be assigned to a user group rather than to an individual user. This allows a more granular and manageable assignment of rights and provides the ability to run each ActivID CMS instance or process under different user accounts. For purposes of explanation in this documentation, the following Users and Groups are used in the following listed examples.

ActivID CMS Users and Groups Example

User or Group Name

Local Group Name    

Related Group Name

User

CMS_USR1

Adm-CMS-LDAPUpdate

Active Directory Group

Adm-CMS-LDAPUpdate

L-adm-CMS-User

Local Machine Group

L-adm-CMS-User