Skip to content
DataMiner DoJo

More results...

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Search in posts
Search in pages
Log in
Menu
  • Updates & Insights
  • Questions
  • Learning
    • E-learning Courses
    • Empower Replay: Limited Edition
    • Tutorials
    • Open Classroom Training
    • Certification
      • DataMiner Fundamentals
      • DataMiner Configurator
      • DataMiner Automation
      • Scripts & Connectors Developer: HTTP Basics
      • Scripts & Connectors Developer: SNMP Basics
      • Visual Overview – Level 1
      • Verify a certificate
    • Video Library
    • Books We Like
    • >> Go to DataMiner Docs
  • Expert Center
    • Solutions & Use Cases
      • Solutions
      • Use Case Library
    • Markets & Industries
      • Media production
      • Government & defense
      • Content distribution
      • Service providers
      • Partners
      • OSS/BSS
    • Agile
      • Agile Webspace
      • Everything Agile
        • The Agile Manifesto
        • Best Practices
        • Retro Recipes
      • Methodologies
        • The Scrum Framework
        • Kanban
        • Extreme Programming
      • Roles
        • The Product Owner
        • The Agile Coach
        • The Quality & UX Coach (QX)
    • DataMiner DevOps Professional Program
      • About the DevOps Program
      • DataMiner DevOps Support
  • Downloads
  • More
    • DataMiner Releases & Updates
    • Feature Suggestions
    • Climb the leaderboard!
    • Swag Shop
    • Contact
    • Global Feedback Survey
  • PARTNERS
    • All Partners
    • Technology Partners
    • Strategic Partner Program
    • Deal Registration
  • >> Go to dataminer.services

IT Security: is there a way to run the DMA server without users on admin right?

Solved822 views18th July 2023security
2
Christian Heidinger10 1st October 2021 0 Comments
  1. What options does skyline provide to reduce the privileges of the used system account?

We would like to run this account without users having admin rights.

It also would be helpful to have this as an feature in a newer release.

2. When DataMiner creates a user it is not part of any groups on the OS level. On the DataMiner level it will add the user to:

  • C:\Skyline DataMiner\Security.xml
  • C:\Skyline DataMiner\Files\SyncInfo\{DO_NOT_REMOVE_XYZ}.xml
  • C:\Skyline DataMiner\Files\SyncInfo\{DO_NOT_REMOVE_XYZ}.xml
    • This file is signed and cannot be altered, during startup this file is used to re-create/delete users that were added/removed from Security.xml

Can this files be altered?

What additional security measurements can be implanted here?

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 18th July 2023

1 Answer

  • Active
  • Voted
  • Newest
  • Oldest
2
Gellynck Jens [SLC]2.71K Posted 1st October 2021 0 Comments

A user with Administrator privileges is required to run the DataMiner installer. During installation, DataMiner will create a number of services in Windows that will run as SYSTEM. There is currently no way to run the DataMiner services under a different user. We are aware that all of our services running as SYSTEM is not recommended, and are working on removing this limitation in the future.

Do note that once the installation is finished, DataMiner operators no longer require Administrator permissions on the server where DataMiner is hosted. You can even disable the built-in Windows Administrator.

You can alter the Security.xml manually, but after the next DataMiner restart any changes will be overwritten by the information in the SyncInfo\* files. These files are signed, meaning they cannot be altered. This is a security measure to prevent tampering and is by design.

Some additional security tips can be found in this article about securing DataMiner (more tips will follow soon).

Other than this I recommend applying the principle of least privilege for your DataMiner users. Meaning if a user doesn’t require specific permissions, they should not be granted. Be especially careful when granting the DataMiner permissions regarding Security, Automation Script creation, and Protocol upload.
Please let me know if you have any further questions, I’m happy to assist where needed.

Marieke Goethals [SLC] [DevOps Catalyst] Selected answer as best 18th July 2023
Please login to be able to comment or post an answer.

My DevOps rank

DevOps Members get more insights on their profile page.

My user earnings

0 Dojo credits

Spend your credits in our swag shop.

0 Reputation points

Boost your reputation, climb the leaderboard.

Promo banner DataMiner DevOps Professiona Program
DataMiner Integration Studio (DIS)
Empower Katas
Privacy Policy • Terms & Conditions • Contact

© 2025 Skyline Communications. All rights reserved.

DOJO Q&A widget

Can't find what you need?

? Explore the Q&A DataMiner Docs