Avatar of Dan
Dan
Flag for United States of America asked on

Accounts used by application pools or service identities are in the local machine Administrators group.

I am using sharepoint foundations 2010, and I'm getting this error message:

"Accounts used by application pools or service identities are in the local machine Administrators group."

I changed the user acount from local to a domain account for sharepoint, but after reanalyzing, it's still coming up with that error message.

Any ideas?
Microsoft SharePoint

Avatar of undefined
Last Comment
Justin Smith

8/22/2022 - Mon
ASKER CERTIFIED SOLUTION
jessc7

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
I changed the account it used and it's still giving me that error, I guess I will wait until tomorrow to see what happens.
jessc7

The Health Analyzer rules run on scheduled timer jobs. Some of them are daily, weekly, etc.

Open the error, click Reanalyze Now, click Close, wait a few minutes, and then refresh the Health Analyzer page. See if it disappears.
2011-10-10-2013.png
Dan

ASKER
after making those changes yesterday, when I came in today, everyone in the organization CAN'T log in to the intranet.  It prompts for a username and password, and when you enter that, it doesn't except it.  I tried to restore from the backup I made yesterday before I made the changes, but it doesn't see or recognize the backup.   What do I do now?  This is insane, why doesn't it see the backup?????
The default location is:  C:\sharepointbackups
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
Dan

ASKER
I set back all the accounts with the local service, which was the default before I made the change.
I even restarted the server and restarted the services, and it's still not working.  
How do I get sharepoint to run it's internal job for using the new accounts, as I can't wait until tonight..
SOLUTION
Justin Smith

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
yes, the sites are working fine. How can I tell what account is running each web app pool?
I believe I set them back to the original accounts, yes, but I have been reiving this error since it's been installed like 3 months ago.
Justin Smith

Either look in IIS under Application Pools (right click on the app pool, Properties, then the Identity tab), or in Central Admin - Security - Service Accounts.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
ok, here's what i found:
application pool (sharepoint central admin v4), uses domain\sharepoint account ( a local account I created on the sharepoint server)

application pool (sharepoint-80), uses Networkservice account

I think that's the problem, so instead of using networkservice, what should I be using?
Justin Smith

Best practice is to use Active Directory accounts for everything.  
Dan

ASKER
sorry, domain\sharepoint is not a local account, it's a domain account.
So you're saying just change the other application pool to that as well?
Your help has saved me hundreds of hours of internet surfing.
fblack61
Dan

ASKER
actually, perhaps what it's saying is that the domain\sharepoint account was part of the local administrators group, and it didn't like that.  So I removed that user from the local administrators group and we'll see what happens.
Justin Smith

Best practice is to have seperate domains accounts for Farm, Web App, and Svc App.  You could at a min, have three domain accounts:  domain\spfarm, domain\spwebapp, domain\spsvcapp.  All web apps use the web app pool account, all service applications use the svc app account,
Dan

ASKER
So if I create 3 different accounts, how do I know what access to give them, like domain administrator, domain user, etc....?

Also, how do I run the sharepoint health analyzer manually, as I believe it runs once at night, but I would like to run it again now.  I clicked on the "reanalyze now" button it's then says it's disabled, so that didnt' work.  Is there a service to restart or a manual command to run, as I just restarted the server, but that didnt' do anything.
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Dan

ASKER
Also, do you know if there's a way to schedule a complete farm backup?  I now do it manually every few days, but it would be nice to schedule it somehow?
SOLUTION
RHADMIN

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
Justin Smith

Research my friend ;)  Or have a SP professional do your deployment.

Dan

ASKER
By removing the domain\sharepoint account from the local administrators account on the server where sharepoint is installed, that cleared the error message.

So is there a way to schedule a complete farm backup of sharepoint automatically?
Experts Exchange is like having an extremely knowledgeable team sitting and waiting for your call. Couldn't do my job half as well as I do without it!
James Murphy
Dan

ASKER
Justin Smith

Backups must be scripted if you want to automate.  But you would need to start another question on that.