Altiris services on the Notification Server will fail to start on a regular basis due to log on failure
search cancel

Altiris services on the Notification Server will fail to start on a regular basis due to log on failure

book

Article ID: 162906

calendar_today

Updated On:

Products

IT Management Suite

Issue/Introduction

You noticed that the Altiris Service account stopped working on the SMP (Symantec Management Platform) server, meaning the Altiris Services started to fail to run due to logging failures with your currently in-use service account.

After looking at the System Event logs, you noticed the following entry:

Log Name:      System
Source:        Service Control Manager
Event ID:      7041
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Description:
The AeXSvc service was unable to log on as Example\svc_smp with the currently configured password due to the following error:
Logon failure: the user has not been granted the requested logon type at this computer.
 
Service: AeXSvc
Domain and account: Example\svc_smp
 
This service account does not have the required user right "Log on as a service."
 
User Action
 
Assign "Log on as a service" to the service account on this computer. You can use Local Security Settings (Secpol.msc) to do this. If this computer is a node in a cluster, check that this user right is assigned to the Cluster service account on all nodes in the cluster.
 
If you have already assigned this user right to the service account, and the user right appears to be removed, check with your domain administrator to find out if a Group Policy object associated with this node might be removing the right.
 

Environment

ITMS 7.x, 8.x

Cause

The Service account (often the AppID account) is expected to be included in the "Log on as a service" security setting. This setting should also typically include:

  • Classic .NET AppPool
  • DefaultAppPool
  • The AppID Account or Service Account
  • Network Service
  • NT Services\All Services
  • SMP Server AppPool
  • Symantec Agent AppPool
  • Symantec Task Server AppPool

It's important to note that Group Policy Objects (GPOs) can sometimes inadvertently remove these permissions, and users may not be aware of such changes.

Resolution

If you encounter an issue where a service account lacks the "Log on as a service" user right, the System Event log will indicate this. This is a Windows requirement for service accounts.

To resolve this, grant the service account the "Log on as a service" security permission by following these steps:

  1. Open the Run command and type secpol.msc.
  2. In the Local Security Policy window, navigate to Security Settings > Local Policies > User Right Assignment.
  3. Double-click "Log on as a service" in the main frame.
  4. Under the Local Security Setting tab, add the desired service account.
  5. Save the changes.