<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.grooper.com/index.php?action=history&amp;feed=atom&amp;title=Template%3ALeastPrivilegeAppPoolAccounts</id>
	<title>Template:LeastPrivilegeAppPoolAccounts - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.grooper.com/index.php?action=history&amp;feed=atom&amp;title=Template%3ALeastPrivilegeAppPoolAccounts"/>
	<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Template:LeastPrivilegeAppPoolAccounts&amp;action=history"/>
	<updated>2026-06-13T05:47:47Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.42.3</generator>
	<entry>
		<id>https://wiki.grooper.com/index.php?title=Template:LeastPrivilegeAppPoolAccounts&amp;diff=33148&amp;oldid=prev</id>
		<title>Dgreenwood: Created page with &quot;When installing the Grooper web client, you will need to assign an application pool identity — a Windows account under which Grooper runs. This account must be granted specific permissions to launch and operate the Grooper website.  From a security standpoint, this account should be granted the minimum permissions required to function. It is unadvisable to grant full local administrator privileges to the Grooper app pool identity.  &#039;&#039;&#039;Note:&#039;&#039;&#039; The user performing the i...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.grooper.com/index.php?title=Template:LeastPrivilegeAppPoolAccounts&amp;diff=33148&amp;oldid=prev"/>
		<updated>2026-06-11T13:51:04Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;When installing the Grooper web client, you will need to assign an application pool identity — a Windows account under which Grooper runs. This account must be granted specific permissions to launch and operate the Grooper website.  From a security standpoint, this account should be granted the minimum permissions required to function. It is unadvisable to grant full local administrator privileges to the Grooper app pool identity.  &amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The user performing the i...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;When installing the Grooper web client, you will need to assign an application pool identity — a Windows account under which Grooper runs. This account must be granted specific permissions to launch and operate the Grooper website.&lt;br /&gt;
&lt;br /&gt;
From a security standpoint, this account should be granted the minimum permissions required to function. It is unadvisable to grant full local administrator privileges to the Grooper app pool identity.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The user performing the installation must also have the ability to query the domain in order to enter credentials for the app pool identity during setup.&lt;br /&gt;
&lt;br /&gt;
{|class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Permission&lt;br /&gt;
! Type&lt;br /&gt;
! Where to Configure&lt;br /&gt;
! Reason&lt;br /&gt;
|-&lt;br /&gt;
|colspan=4|&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Always Required&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
| Read Member Of&lt;br /&gt;
| Active Directory&lt;br /&gt;
| Active Directory Users and Computers (or via Group Policy)&lt;br /&gt;
| Required to check the authenticated user&amp;#039;s group membership at login&lt;br /&gt;
|-&lt;br /&gt;
| Local Users Group&lt;br /&gt;
| Local&lt;br /&gt;
| Computer Management → Local Users and Groups → Groups → Users&lt;br /&gt;
| Grants rights to run installed applications, including Grooper&lt;br /&gt;
|-&lt;br /&gt;
| File Store Access&lt;br /&gt;
| NTFS / Share&lt;br /&gt;
| Windows Explorer → Folder Properties → Security (NTFS) and/or Share Permissions&lt;br /&gt;
| Read and write access to the Grooper file store location&lt;br /&gt;
|-&lt;br /&gt;
| Database Access&lt;br /&gt;
| SQL Server&lt;br /&gt;
| SQL Server Management Studio → Security → Logins → [account] → User Mapping → [GrooperDB]&lt;br /&gt;
| Read and write access to the Grooper database. Grant &amp;#039;&amp;#039;&amp;#039;db_datareader&amp;#039;&amp;#039;&amp;#039; and &amp;#039;&amp;#039;&amp;#039;db_datawriter&amp;#039;&amp;#039;&amp;#039; on the Grooper database.&lt;br /&gt;
|-&lt;br /&gt;
|colspan=4|&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Conditionally Required&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
|-&lt;br /&gt;
| C:\Release&lt;br /&gt;
| Local / NTFS&lt;br /&gt;
| Windows Explorer → Folder Properties → Security&lt;br /&gt;
| Required when implementing Object Libraries or custom scripts — grants rights to run MSBuild for compilation&lt;br /&gt;
|-&lt;br /&gt;
| Logon As Service&lt;br /&gt;
| Local Security Policy&lt;br /&gt;
| Local Security Policy → Local Policies → User Rights Assignment → Log on as a service&lt;br /&gt;
| Required only if the app pool identity is also being used as a Grooper service account&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; The permissions above cover normal application operation. Elevated database rights — such as the ability to create or alter tables — are only required during initial installation or upgrades if alterations to the Grooper database tables are required or new tables are added. Furthermore, only the user running [[Grooper Command Console]] (GCC) will need these rights.&lt;/div&gt;</summary>
		<author><name>Dgreenwood</name></author>
	</entry>
</feed>