PI Nexus+ / Installation Guide
Verify Runtime Identities
This chapter confirms that Windows runs PI Nexus+ as the service account, because a fallback identity opens the app but fails at SQL Server and the PI System.
Overview
This chapter confirms that Windows runs PI Nexus+ as the service account, because a fallback identity opens the app but fails at SQL Server and the PI System.
Quick check
In an elevated Windows PowerShell on each PI Nexus+ server:
Import-Module WebAdministration
(Get-ItemProperty 'IIS:\AppPools\PINexusAppPool' -Name processModel).userName
Get-CimInstance Win32_Service -Filter "Name='PI Nexus+ Scanner'" | Select-Object StartName, State, StartMode
Both must name the service account. An empty user name means the app pool runs as ApplicationPoolIdentity; LocalSystem means the service runs as the computer account. Correct either one as described below.
App pool
The app pool identity serves the browser, the Admin pages, the connection tests and discovery.
- Open IIS Manager > Application Pools and select
PINexusAppPool. - Open Advanced Settings and set Identity to the service account with its password.
- Check that .NET CLR Version is No Managed Code, Managed Pipeline Mode is Integrated and Load User Profile is True.
- Start or recycle the app pool.
Scanner service
The scanner service identity runs scans, health refreshes, runtime polls, host monitoring and emails.
- Open Services and open
PI Nexus+ Scanner. - On the Log On tab, choose This account and enter the service account and its password.
- Start the service and check that it stays Running.
If the app pool stops or the service does not start, see Installation Troubleshooting.
Note: When SQL Server or PI logs show the computer account DOMAIN\SERVER$, the scanner service is running as Local System.
Reference: Service Account Rights
