Creating a Microsoft Active Directory account for the BEMS service account

Note: "Read Only Domain Controllers" are a feature of the Microsoft Active Directory software. Read Only Domain Controllers Microsoft Active Directory servers are not supported for BEMS. BEMS supports only writable domain controllers.

Set the following attributes for the BEMS service account:

  • The account for the Connect and Presence services must be in the same Active Directory domain as the BEMS server. For more information, see KB 63703.
  • This service account should be a member of local administrator group on the BEMS host machine.
  • The account name (UID, distinct from the account password) must be strictly alphanumeric; no special characters are allowed with the exception of underscore (_), hyphen (-), and period (.). For example, BEMSAdmin.
  • Account Password (distinct from the account name above) must not contain these characters: semicolon (;), at sign (@), slash mark (/), caret (^), and double quotes (").
  • Password Expires option must be set to Never for this account.