Be sure to review our Idea Submission Guidelines for more information!
Submission GuidelinesWe have configured the service account for Alteryx services on workers, controllers and Gallery. Kindly go through the below problem statement and current scenario and help to provide solution.
I will appreciate if we can setup a 30 minutes call and discuss on it.
Purpose/Current Design :
Problem Statement :
As we have added service LAN account in multiple AD groups [ global and local ] it has become member of 440+ groups which has resulted in the approx.. token size to 8421.
Active directory has a limit of having approx.. token size to 10000 (10k) for LAN accounts and after that it will fail to authenticate with AD ; which will result in failure of starting Alteryx services.
Please refer below link to know what exactly issue we are facing and looking solution from Product team[Alteryx].
https://www.jijitechnologies.com/blogs/active-directory-token-bloat
We are looking from the Alteryx team :
We already explored the option you suggested [https://help.alteryx.com/current/server/credentials] but as per our firm’s password policy we cannot save/use/withdraw privilege account passwords.
Because if we go with the suggested option we have to add the particular accounts in Windows server privilege group [ Log on as service, App_Security Logon locally and run batch job].
To meet compliant policy ; Any account which is privilege should be considered as app to app account and it should be integrated with Microsoft’s gMSA or CyberArk’s EPV-AIM solution to be on boarded account in vault. [ No human interaction with account ]
Feel free to reach out to me for any additional clarifications.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.