<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do SAS spawned server account (sassrv) and first user account (sasdemo) need to be local admins in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788407#M23599</link>
    <description>&lt;P&gt;This account should actually have quite restricted permissions, especially if you are allowing business users to create stored processes (eg, using EG).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is because - unless you configure the STP to run under the end user OS creds - you are granting those users the ability to run code under a different OS account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where you need to run SAS Apps with STPs with elevated OS credentials (such as in our product, Data Controller for SAS) then you are recommended to create a dedicated STP context and restrict the STPs that can run under that context.&amp;nbsp; More info:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.datacontroller.io/dci-stpinstance/" target="_blank"&gt;https://docs.datacontroller.io/dci-stpinstance/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jan 2022 07:27:06 GMT</pubDate>
    <dc:creator>AllanBowe</dc:creator>
    <dc:date>2022-01-05T07:27:06Z</dc:date>
    <item>
      <title>Do SAS spawned server account (sassrv) and first user account (sasdemo) need to be local admins ?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788329#M23596</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I apologize if this question is very trivial.&lt;BR /&gt;My question is do SAS Spawned Server Account (sassrv) and the first user account (sasdemo) need to be local administrators?&lt;BR /&gt;The context is of SAS 9.4 being installed on a Windows Server.&lt;BR /&gt;As I see in the documentation these are external accounts and the spawned server account account(sassrv) needs to be a member of the group of the sas installer account( typically sas). In addition it needs to have log in as batch privileges'.&lt;BR /&gt;I haven't seen any requirement that sassrv and sasdemo should have local admin rights (i.e. members of the local administrator group).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I request&amp;nbsp; experienced administrator and superusers for their guidance.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 18:25:31 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788329#M23596</guid>
      <dc:creator>thesasuser</dc:creator>
      <dc:date>2022-01-04T18:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Do SAS spawned server account (sassrv) and first user account (sasdemo) need to be local admins</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788330#M23597</link>
      <description>No, these users should not be local admins.</description>
      <pubDate>Tue, 04 Jan 2022 18:27:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788330#M23597</guid>
      <dc:creator>gwootton</dc:creator>
      <dc:date>2022-01-04T18:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Do SAS spawned server account (sassrv) and first user account (sasdemo) need to be local admins</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788407#M23599</link>
      <description>&lt;P&gt;This account should actually have quite restricted permissions, especially if you are allowing business users to create stored processes (eg, using EG).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is because - unless you configure the STP to run under the end user OS creds - you are granting those users the ability to run code under a different OS account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Where you need to run SAS Apps with STPs with elevated OS credentials (such as in our product, Data Controller for SAS) then you are recommended to create a dedicated STP context and restrict the STPs that can run under that context.&amp;nbsp; More info:&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.datacontroller.io/dci-stpinstance/" target="_blank"&gt;https://docs.datacontroller.io/dci-stpinstance/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 07:27:06 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Do-SAS-spawned-server-account-sassrv-and-first-user-account/m-p/788407#M23599</guid>
      <dc:creator>AllanBowe</dc:creator>
      <dc:date>2022-01-05T07:27:06Z</dc:date>
    </item>
  </channel>
</rss>

