Change the Microsoft Identity Integration Server 2003 service account
For this procedure, you can change the Microsoft Identity Integration Server 2003 service account used by Microsoft Identity Integration Server 2003. You can also add this account to several
local group policies, increasing security. To complete this procedure, you must be logged on as a member of the MIISAdmins security group.
To change the Microsoft Identity Integration Server 2003 service account
Back up the encryption key set by running Miiskmu.exe.
Click Start, point to Administrative Tools, and
then click Computer Management.
Double click Local Users and Computers, right click
Users, and then click New User.
Type the user information and password.
Clear the User must change password at next logon check
box, and then click Create.
Click Start, point to Programs, click
Administrative Tools, and then click Local Security
Policy.
Double click Local Policies, and then click User
Rights Assignment.
Double click Deny logon locally, and then click Add
user or group.
In Enter the object names to select, type the account
name created in step 4.
Repeat steps 8 and 9 by adding this account to Deny access
to this computer from the network, Deny logon as a batch
job, and Deny log on through Terminal Services.
Run Setup from the Microsoft Identity Integration Server 2003
installation CD in maintenance mode and change the Microsoft Identity Integration Server 2003 service account credentials from the old
account to the new one. During the setup process, you are prompted
for the encryption key set.
Back up the encryption key set by running Miiskmu.exe.
Click Start, point to Administrative Tools, and
then click Active Directory Users and Computers.
Under the root domain, right-click Users, point to
New, and then click User.
Type the user information, and then click Next.
Type the password, and then click Next.
Click Finish.
Click Start, point to Programs, click
Administrative Tools, and then click Local Security
Policy.
Double click Local Policies, and then click User
Rights Assignment.
Double click Deny access to this computer from the
network, and then click Add user or group.
In Enter the object names to select, type the account
name created in step 4.
Repeat steps 9 and 10 by adding this account to Deny logon
as a batch job, and Deny log on through Terminal
Services.
Run setup from the Microsoft Identity Integration Server 2003
installation CD in maintenance mode and change the Microsoft Identity Integration Server 2003 service account credentials from the old
account to the new one. During the setup process, you are prompted
for the encryption key set.
Important
To prevent attacks to the registry and system files by
malicious users, it is strongly recommended that you do not add the
Microsoft Identity Integration Server 2003 service account to the local
administrators group.
Note
No additional lock-down procedures are needed to secure the
Microsoft Identity Integration Server 2003 service account in a domain. By
default, you cannot log on locally with the Microsoft Identity Integration Server 2003 service account.