11-29-2010 03:54 PM - edited 03-19-2019 02:00 AM
Hi
Unity 5.X in UM mode - Which unity accts can I take off "domain admin" group after install (ie unityinstall, unityadmin, UnityMsgStoreSvc, UnityDirSVC etc..)
and if I do so, what is the impact or if I want to upgrade in the future?
Thanks
11-29-2010 07:57 PM
You're allowed to downgrade the UnityInstall account if you wish post install. Personally I just disable it until I need it again.
Everything else should stick with whatever permissions the documentation/permissions wizard assigned.
11-30-2010 09:32 AM
UnityInstall should be the most powerful account and is the only account that should be added to the Domain Admins group by the Permissions Wizard. This is definitely true for Exchange 200, 2003, and 2007. I've not dealt with a lot of customers on 2010 yet so this could have changed; however, I doubt it. You can verify what I'm telling you here:
This link will tell you what permissions and group memberships are set at a high level for all the Unity service accounts.
To clarify what Jonathan said, by "downgrade" the UnityInstall account - the rule of thumb is this:
Cisco supports that you DISABLE the UnityInstall account, if desired, after an installation. This account should only be used during installation activities. However, DO NOT DELETE the account in AD. So, again - disabling the account is OK.
Hailey
Please rate helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide