cancel
Showing results for 
Search instead for 
Did you mean: 

Discovery Accelarator security hardening

ggeorgi
Level 5
Partner Accredited

Hi to all EVguys.....

I got a request to remove every permissions from EVDA for all users (including EV service account and other administrators) except a specific one. I removed the admin roles from all users, except the one I was asked to keep, and for all "normal" domain accounts it was successful and I wasn't even able to login. For EV service account, despite the fact that I removed the roles, I was able to login to the EVDA console and make several changes. Am I missing something or is this the default behavior?

 

Thanks in advance,

GeorgeG

2 REPLIES 2

AndrewB
Moderator
Moderator
Partner    VIP    Accredited

the service account can be configured not to have access to cases and such but it will always have the right to assign itself access since it is the service account after all. does that make sense? (like how in AD/NTFS the administrator role doesn't necessarily have access to every file or resource but it can take ownership, grant full control, etc.)

JimmyNeutron
Level 6
Partner Accredited

Default behavior no further action required.