6.2 Which SharePoint 2019 Service Accounts do I need?
Service Applications [18] provide additional functionality for your sites and require a lot of different accounts. Sometimes one Service Application requires more than one account so you may want to group accounts by Service Application.
However, a better way is to group Service Applications by account.
Note:
A Service Application is a concept based on a service. You can create one or more instances of the service. In order to communicate with the instance there is an endpoint (which is an IIS Virtual Application) using an Application Pool. Therefore, you need to provide an Application Pool account if you create a Service Application in SharePoint.
Application Pool Account for Service Applications:
This table shows the required SharePoint Server 2019 Service Accounts.
Service Application |
Account name (example) |
Requirement |
Access Services
Access Services 2013
App Management Service
Business Data Connectivity service
Machine Translation service
Managed Metadata Service
PerformancePoint Service
PowerPoint Conversion Service*
Search Service
Secure Store Service
Usage and Health Data Collection Service*
User Profile Service
Visio Graphics Service
Word Automation services
|
domain\spService |
Must be a domain user account. |
* Only available using PowerShell, aren't displayed in Central Administration
Note:
"A single account should be used for all Service Applications, named Service Application Pool account. This allows the administrator to use a single IIS Application Pool for all Service Applications. In addition, this account should run the following Windows Services: SharePoint Search Host Controller, SharePoint Server Search, and Distributed Cache (AppFabric Caching Service)." [19]
Unattended Service Accounts (Accounts for accessing External Data):
PerformancePoint Services or Visio Graphics Service can access and display data from external sources. You may need an unattended service account in certain cases [20]. This kind of account is stored inside the Secure Store Service Application in SharePoint.
This table shows the required SharePoint Server 2019 Service Accounts for Accessing External Data.
Service Application |
Account name (example) |
Requirement |
PerformancePoint Service Visio Graphics Service |
domain\spUnattended |
Must be a domain user account. |
Search Accounts:
This table shows the required SharePoint Server 2019 Service Accounts for Search.
Service Application |
Account name (example) |
Requirement |
Search Service (The default content access account is used by the indexer to access content) |
domain\spSearchDCA |
Must have Read Access to the content being crawled. |
Search Service (Optional separate content access account used with a custom crawl rule) |
domain\spSearchCA |
Must have Read Access to the content being crawled. |
Synchronization Connection Account:
This table shows the required SharePoint Server 2019 Service Accounts for User Profiles.
Service Application |
Account name (example) |
Requirement |
User Profile Service (Inside the User Profile Service Application, you can create connections to directories where your company’s user profile information is stored. Each connection needs an account to access the directory.) |
domain\spUPSync |
Must be a domain user account. Replicating Directory Changes permissions on the domains being synchronized. |
SharePoint 2019 Service Account Permissions
"The SharePoint Products Configuration Wizard (Psconfig) and the Farm Configuration Wizard, both of which are run during a complete installation, configure many of the SharePoint baseline account permissions and security settings." [16]
So there's nothing to prepare right now.
SharePoint 2019 Service Account Best Practice
Please have a look at Service account recommendations if you want to know more.
Back to top