Documentation PI Nexus+ Documentation

PI Nexus+ / Installation Guide

Prepare the Service Account

This chapter prepares the Windows account that runs PI Nexus+, so that the installer can assign it and scans can read the PI System.

Overview

This chapter prepares the Windows account that runs PI Nexus+, so that the installer can assign it and scans can read the PI System.

One account runs the PINexusAppPool app pool and the PI Nexus+ Scanner service. Use a dedicated domain account, for example DOMAIN\svc-pinexus, or a group managed service account (gMSA). On a split deployment each server can use its own account.

Name the account in full

Enter the account as DOMAIN\svc-pinexus, .\svc-pinexus or svc-pinexus@domain.example. The installer does not assign a bare name such as svc-pinexus; it falls back to a built-in identity. Enter a gMSA as DOMAIN\svc-pinexus$, without a password; the PI Nexus+ servers must be allowed to retrieve its password.

Check that the account resolves on the PI Nexus+ server; this PowerShell command must return a SID:

([System.Security.Principal.NTAccount]'DOMAIN\svc-pinexus').Translate([System.Security.Principal.SecurityIdentifier])

Grant the local Windows rights

On each PI Nexus+ server, under Local Security Policy > Local Policies > User Rights Assignment, or in the Group Policy that sets these rights:

  1. Add the account to Log on as a batch job (app pool, web server).
  2. Add the account to Log on as a service (scanner service, scanner server).
  3. Make sure the account is not in Deny log on as a batch job or Deny log on as a service.

If a domain Group Policy sets these rights, change it there; a local change is overwritten at the next policy refresh.

Grant read access to the PI System

PI Nexus+ needs read access only. Give the account:

  • A PI identity mapping with read access to the PI Points on each PI Data Archive.
  • Read access to the %OSI\Interfaces Module Database hierarchy, only for Interface Tracking.
  • Read access to each AF Server and AF database to scan, including the PI Adapter health database, if used.
  • db_datareader on each PI Vision database, if PI Vision is inventoried.

To test, sign in as the account and browse the PI Data Archive and AF database in PI System Explorer. Write rights for optional features, such as compression changes, are described with those features in the Administration Guide.

Note: Host monitoring later reads servers as the account that runs the PI Nexus+ Scanner service. Each monitored host then needs a few non-administrator rights, granted with a script PI Nexus+ provides; see Host Monitoring in the Administration Guide.

Reference: Service Account Rights