Answered by:
Central Administration errors "The server farm account should not be used for other services."

Question
-
Hello. Very new to sharepoint (but enjoying it). I configured a small farm (on a single server) for a small office (40 users). I used my DOMAIN\administrator account as my server farm account (in retrospect this isn't a good idea huh?). Now when I go into Central Administration I get an error saying "The server farm account should not be used for other services." because I'm assuming this same DOMAIN\administrator account is being used for all my other services.
The explanation is as follows:
DOMAIN\administrator, the account used for the SharePoint timer service and the central administration site, is highly privileged and should not be used for any other services on any machines in the server farm. The following services were found to use this account: Microsoft Project Server Events Service executes events triggered by changes to entities on the ProjectServer.(Windows Service) SharePoint - 80 (Application Pool) User Profile Synchronization Service(Windows Service) OSearch14(Windows Service) Microsoft Project Server Queuing Service executes project related jobs asynchronously. Example queue jobs: Save project, publish project, submit timesheet.(Windows Service) Web Analytics Data Processing Service(Windows Service)
Now I know I need to make a new managed account in the Register Managed Account window of Central Administration, but where does this account need to originate? From my Active Directory Service? I'm guessing (I want to be absolutely clear before moving forward) that I need to make two new accounts in my domain: a server farm account (something like domain\SharePointFarmAccount) and a services account (DOMAIN\SharePointServicesAccount). Then I can reference them as managed accounts in Central Administration? And then set my new SharePointFarmAccount to manage the Farm Account and my services account to manage those services? Am I right? If so, what rights (on the domain) do these accounts need?Thank you !
Monday, July 18, 2011 7:22 PM
Answers
-
Hello Kenny,
"The server farm account should not be used for other services" is one of the rule in SharePoint Health Analyzer. There is an article of how to resolev it step by step:
Please read the below article:
http://technet.microsoft.com/en-us/library/ff805056.aspxHope that helps.
Thanks,
Thanks, Amit Khare |EPM Consultant| Blog: http://amitkhare82.blogspot.com http://www.linkedin.com/in/amitkhare82- Marked as answer by Christophe FiessingerMicrosoft employee Saturday, September 10, 2011 7:24 AM
Tuesday, July 19, 2011 5:11 AM
All replies
-
Hi Kenny,
Glad to hear that you are enjoying SharePoint! Please see the TechNet article below that outlines the accounts / permissions needed for SharePoint Server 2010:
http://technet.microsoft.com/en-us/library/cc678863.aspx
Hope that helps
Paul
Paul Mather | Twitter | http://pwmather.wordpress.com- Proposed as answer by Alexander.Burton Monday, July 18, 2011 10:11 PM
Monday, July 18, 2011 7:53 PM -
Hello Kenny,
"The server farm account should not be used for other services" is one of the rule in SharePoint Health Analyzer. There is an article of how to resolev it step by step:
Please read the below article:
http://technet.microsoft.com/en-us/library/ff805056.aspxHope that helps.
Thanks,
Thanks, Amit Khare |EPM Consultant| Blog: http://amitkhare82.blogspot.com http://www.linkedin.com/in/amitkhare82- Marked as answer by Christophe FiessingerMicrosoft employee Saturday, September 10, 2011 7:24 AM
Tuesday, July 19, 2011 5:11 AM -
Thanks for the answer. I followed the instructions and created a separate managed account for the services in question. However how I'm having major issues with my User Profile Synchronization Service... it was one of the services that reported it needed to be on a separate managed account so I changed it. Now it won't start, and the original Synchronization Connection to AD is gone. So I went back into Central Admin -> Service Accounts and tried changing it back to the original managed account but I get the following error:
An object of the type Microsoft.SharePoint.Administration.SPWindowsServiceCredentialDeploymentJobDefinition named "windows-service-credentials-FIMSynchronizationService" already exists under the parent Microsoft.Office.Server.Administration.ProfileSynchronizationService named "FIMSynchronizationService". Rename your object or delete the existing object.
It's as if it already exists but won't let me modify or change it. Should I have changed this service account? I can't get this service started at all. :(
Tuesday, July 19, 2011 7:21 PM -
Hi Kenny,
Take a look at this thread over on the SharePoint forums http://social.technet.microsoft.com/Forums/en-US/sharepoint2010setup/thread/044e3c1a-6b24-4616-9121-2f353358b631/#2fb387b0-a408-4bc6-8c0f-04744c7666b9 the User Profile Sync is a bit of a beast to say the least :)
hope this helps,
Alex Burton
www.epmsource.com | Twitter
Project Server TechCenter | Project Developer Center | Project Server Help | Project Product PageWednesday, July 20, 2011 5:50 AM -
Hmmm I did exactly that (deleted USP App and created another) and I'm still getting the error, as well as not being able to start the servce.Wednesday, July 20, 2011 5:06 PM