Service Accounts
All Service Accounts (unless noted under Description) will be registered in SharePoint as Managed Accounts which will allow SharePoint to manage password changes automatically.
The following lists service accounts used for the SharePoint Farm:
| Description | Account Name | Roles | Permissions and notes |
|---|---|---|---|
| SQL Server Service Account | SP10_SQL | Runs services:
| * Requires sysadmin for SQL Server Agent |
| SharePoint Setup User Account | SP10_Setup |
| dbcreator, securityadmin server roles and db_owner for all SharePoint databases. |
| SP10_Farm |
| * |
| SharePoint Service Applications Service Account | SP10_Apps |
| * For least privileged user use a separate account for each service application. However, best practice is to limit the number of application pools. * If using Office Web Apps, this account must be dbo on all content databases. |
| SharePoint User Profile Synchronization Service Account (Unmanaged) | SP10_Sync |
| *Needs AD permissions: UPS Setup |
| SharePoint User Profile Application Service Account (Unmanaged) AD Connection Account | SP10_Profile |
| *Needs AD permissions: UPS Setup</td |
| SharePoint MySite AppPool Identity | SP10_MySite |
| * |
| SharePoint Web Analytics Service Account | SP10_Analyze |
| * |
| SharePoint Managed Metadata Service Account | SP10_Metadata |
| * |
| SP10_Search |
| * |
| SharePoint Content Access Account (Unmanaged) | SP10_Crawl |
| * |
| Search Administration App Pool Account | SP10_SearchAdmin |
| * |
| SharePoint Web Application Pool Account | SP10_Intranet |
| * |
| Objec Cache User Account (Unmanaged) | SP10_SuperUser |
| * |
| Object Cache Reader Account (Unmanaged) | SP10_SuperReader |
| * |
Additional Service Accounts for services:
| Description | Account Name | Roles | Permissions and notes |
|---|---|---|---|
| Office Web Apps Service Account | SP10_OfficeWeb |
| * Needs access to content databases. |
| Unattended Excel Services Service Account (Unmanaged) | SP10_Excel |
|
|
| Unattended Visio Graphics Services Service Account (Unmanaged) | SP10_Visio |
|
|
| Unattended PerformancePoint Services Service Account (Unmanaged) | SP10_PerfPoint |
|
|


