Documentation PI Nexus+ Documentation

PI Nexus+ / Installation Guide

Verify Runtime Identities

This chapter confirms that Windows runs PI Nexus+ as the service account, because a fallback identity opens the app but fails at SQL Server and the PI System.

Overview

This chapter confirms that Windows runs PI Nexus+ as the service account, because a fallback identity opens the app but fails at SQL Server and the PI System.

Quick check

In an elevated Windows PowerShell on each PI Nexus+ server:

Import-Module WebAdministration
(Get-ItemProperty 'IIS:\AppPools\PINexusAppPool' -Name processModel).userName
Get-CimInstance Win32_Service -Filter "Name='PI Nexus+ Scanner'" | Select-Object StartName, State, StartMode

Both must name the service account. An empty user name means the app pool runs as ApplicationPoolIdentity; LocalSystem means the service runs as the computer account. Correct either one as described below.

App pool

The app pool identity serves the browser, the Admin pages, the connection tests and discovery.

  1. Open IIS Manager > Application Pools and select PINexusAppPool.
  2. Open Advanced Settings and set Identity to the service account with its password.
  3. Check that .NET CLR Version is No Managed Code, Managed Pipeline Mode is Integrated and Load User Profile is True.
  4. Start or recycle the app pool.

Scanner service

The scanner service identity runs scans, health refreshes, runtime polls, host monitoring and emails.

  1. Open Services and open PI Nexus+ Scanner.
  2. On the Log On tab, choose This account and enter the service account and its password.
  3. Start the service and check that it stays Running.

If the app pool stops or the service does not start, see Installation Troubleshooting.

Note: When SQL Server or PI logs show the computer account DOMAIN\SERVER$, the scanner service is running as Local System.

Reference: Service Account Rights