How To: Run the SecureAuth RADIUS Service Under an Active Directory Account

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: SecureAuth IdP 9.1, 9.2 (tested on RADIUS Agent v2.4 and v2.5)

     

    Overview

    This article explains how to configure the SecureAuth RADIUS Service to run under an Active Directory (AD) account instead of the Local System account. Running the service under an AD account without the correct permissions causes Windows to fail to start the service, showing the error "Windows could not start the SecureAuth RADIUS on Local Computer... service-specific error code 1."

     

    Run the SecureAuth RADIUS Service Under an AD Account

    1. Create, or identify, the AD account you want to use to run the SecureAuth RADIUS Service.
    2. On the RADIUS server, open Local Security Policy (or run secpol.msc), expand Local Policies, and click User Rights Assignment.
    3. In the right pane, right-click Log on as a service and select Properties.
    4. Click Add User or Group, add the AD account, then click OK on each dialog to save.

    Log on as a service Properties dialog with the AD account added to the list of accounts allowed to log on as a service.

    1. Grant the AD account Full Control on the SecureAuth RADIUS installation folder — for example, C:\Program Files (x86)\SecureAuth Corporation or C:\idpRADIUS, depending on how RADIUS was installed. Right-click the folder, go to Properties > Security > Edit, add the account, and check Full Control.

    SecureAuth Corporation Properties Security tab with Full Control and other permissions checked (Allow) for the AD account.

    1. If RADIUS configuration or log files are stored in a separate folder, repeat Step 5 for that folder as well.
    2. Open Services, right-click SecureAuth RADIUS, select Properties, go to the Log On tab, select This account, enter the AD account and its password, then click OK.

    SecureAuth RADIUS Properties Log On tab with This account selected and the AD account entered.

    1. Start the RADIUS service.


     

    Special Considerations

    Back up the RADIUS configuration before changing the service's logon account. Changing the Log On account clears realm-specific RADIUS server settings such as the Shared Secret, API Application ID, and API Application Key.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.