SharePoint 2013 Best Practices: Service Accounts

SharePoint 2013 Best Practices: Service Accounts



For a SharePoint installation, this page recommends the following best practices and naming conventions for service accounts:

Remember: 
Managed Service accounts are limited to a total of 20 characters - including the Domain Name (for example Domain\SP_Name  - total characters should be less than 20)

Service Account Overview

  • SQL_Service, for the SQL Server service.
  • SQL_Admin, for the SQL Server administrator.
  • SP_Admin, for the SharePoint administrator and setup user.
  • SP_Farm, for the SharePoint farm service.
  • SP_WebApps, for the user-facing web application app pool.
  • SP_ServiceApps, for the service application app pool.
  • SP_Crawl, default content access account.
  • SP_UserSync, user profile synchronization account.
  • SP_EnterpriseAdmin, powerful account for handling all kinds of high privilge operations.
  • Farm administrators, normal admin user accounts are used as SharePoint Farm Administrators.


You can also add a "ga" after each Administrator Account to make explicit that this is a "Global Administrator" Account! An example can be "SP_Farmga". So we know that this account is the Global Administrator of the SharePoint Farm.

SQL_Service

​​This account should be used for running SQL Server engine and SQL Server Agent. Create inside Service Manage Accounts Container inside AD to keep it controlled. Have the following characteristics:​

  • Belongs to the Users Domain Group.
  • ​​Use only for these two SQL services, if installed more (what you should do) keep the service accounts suggested by the installation program..

SP_EnterpriseAdmin

This account is needed for performing high privilege jobs and (such as installing fixes, upgrades, etc.). It needs to have the following permissions:

  • Either SQL Administrator or db_owner of all SharePoint databases.
  • Local administrator of each SharePoint server.
  • Member of Farm Administrators group.

See http://social.technet.microsoft.com/wiki/contents/articles/12438.sharepoint-2013-best-practices.aspx for more information.

Please Note This page is a community driven effort and is open for update. Originally, it was based on the work of Dan Holme (http://www.sharepointpromag.com/author/5052626/DanHolme).

Leave a Comment
  • Please add 3 and 8 and type the answer here:
  • Post
Wiki - Revision Comment List(Revision Comment)
Sort by: Published Date | Most Recent | Most Useful
Comments
  • Richard Mueller edited Revision 20. Comment: Remove blank heading in HTML

  • Refresh98370 edited Revision 19. Comment: fixed grammatical error

  • Gokan Ozcifci edited Revision 18. Comment: ga  

  • Richard Mueller edited Revision 14. Comment: Removed (en-US) from title, added headings to TOC, added tags

  • Margriet Bruggeman edited Revision 8. Comment: add

  • Margriet Bruggeman edited Revision 7. Comment: add

  • Margriet Bruggeman edited Revision 5. Comment: add

  • Margriet Bruggeman edited Revision 4. Comment: add

  • Margriet Bruggeman edited Revision 3. Comment: add

  • Margriet Bruggeman edited Revision 2. Comment: add

Page 1 of 2 (12 items) 12
Wikis - Comment List
Sort by: Published Date | Most Recent | Most Useful
Posting comments is temporarily disabled until 10:00am PST on Saturday, December 14th. Thank you for your patience.
Comments
  • Margriet Bruggeman edited Original. Comment: add

  • Margriet Bruggeman edited Revision 1. Comment: add

  • Margriet Bruggeman edited Revision 2. Comment: add

  • Margriet Bruggeman edited Revision 3. Comment: add

  • Margriet Bruggeman edited Revision 4. Comment: add

  • Margriet Bruggeman edited Revision 5. Comment: add

  • Thanks.

  • Margriet Bruggeman edited Revision 7. Comment: add

  • Margriet Bruggeman edited Revision 8. Comment: add

  • Hi Serhad,

    What a fast response, I just started creating the thing!

  • I think a srvsvc account also should be added

    all win services should be run with it like search, doc convert and so on.

  • Thanks

  • What about Search service?

  • Hi,

    I did an article about this on Nothing but sharepoint.   I am posting the link not to make publicity for it, but to get opinions from the community and make the article better.

    www.nothingbutsharepoint.com/.../SharePoint-2013-Service-Accounts-Best-Practices-Explained.aspx

  • Hi,

    I did an article about this on Nothing but sharepoint.   I am posting the link not to make publicity for it, but to get opinions from the community and make the article better.

    www.nothingbutsharepoint.com/.../SharePoint-2013-Service-Accounts-Best-Practices-Explained.aspx

Page 1 of 2 (19 items) 12