This article clarifies the required Windows user rights for service accounts used to execute jobs via the Autosys Windows Agent.
It explains why a broad set of permissions is typically documented and how to determine the minimum permissions required for specific job types.
Customers often require a "least privilege" security model for service accounts.
The standard documentation provides a comprehensive list of permissions to cover all possible job types (interactive, file transfer, command, etc.), which may include sensitive rights that trigger security audits.
The permissions documented in the List of Required Permissions to Run a Job on Windows present a combined set of rights. Not every permission is required for every job.
SeTcbPrivilege (Act as part of the operating system), are more sensitive than standard local administrator rights. Windows requires these to be explicitly granted.To determine the minimum required permissions for your specific environment and job types, follow these steps:
The user name or password is incorrect or Access Denied), review the Agent logs.To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.