Failed to log on as user Install-AIPScanner

jpcapone 1,356 Reputation points
2021-04-21T00:51:51.677+00:00

How can you run this cmdlet Install-AIPScanner without the logon locally permission being given to the service account? Some environments do not allow for this permission to be given out and other steps in the installation process account for this but the -onbehalfof parament does not work for this cmdlet.

Azure Information Protection
Azure Information Protection
An Azure service that is used to control and help secure email, documents, and sensitive data that are shared outside the company.
523 questions
{count} votes

1 answer

Sort by: Most helpful
  1. jpcapone 1,356 Reputation points
    2021-04-23T19:24:45.68+00:00

    I worked around this issue by obtaining the logon locally right via the client. However, I have found this requirement listed at numerous sites which have been listed below:
    https://techcommunity.microsoft.com/t5/security-compliance-identity/installation-configuration-and-usage-of-the-aip-scanner/ba-p/221792

    Direct from Microsoft

    https://learn.microsoft.com/en-us/azure/information-protection/deploy-aip-scanner-prereqs

    Requirement Details
    Log on locally user right assignment Required to install and configure the scanner, but not required to run scans.

    Once you've confirmed that the scanner can discover, classify, and protect files, you can remove this right from the service account.

    If granting this right even for a short period of time is not possible because of your organization policies, see Deploying the scanner with alternative configurations.

    1 person found this answer helpful.