For each Symantec DLP Service, right-click the service name, and select properties.
Update the "Log On" tab with the new user account and password.
Note: The new account may have "Log on As A Service" right added upon saving the changes.
Update DLP Data Directory Permissions
Open the Symantec DLP Data directory. Default: \ProgramData\Symantec\DataLossPrevention\
For each application directory, locate the current DLP version subfolder. Example: \ProgramData\Symantec\DataLossPrevention\EnforceServer\<DLP_version>
Add special permissions for the new service account to access data directories and files.
Right-Click the DLP version subfolder and select Properties.
Open the Security tab.
Select Advanced.
Select Add.
Principal: click on Select a Principal and locate the new service account user.
Type: Allow.
Applies to: This folder, subfolders, and files
Basic Permissions: Full Control Note: The time it takes to cascade this change varies between servers.
By default, the group membership needed to access application files is Users. However, if the new account cannot be a member of Users, please contact DLP Technical Support.
If the DLP Services account is the same account being used to log into the database, then to avoid an account lock-out, run the DBPasswordChanger utility as soon as possible after the Oracle Data Loss Prevention account password is changed.