Privilege Levels for Archer Services

It is strongly recommended that you set Archer services to run with Domain User account privileges.

In general, Archer services should run with the lowest privilege level that allows them to work.

Local System privileges give Archer services unrestricted access to local system resources. While this level of privilege allows the services to access all system resources easily, giving unrestricted access to many services and accounts increases the security vulnerability of a system. Organizations concerned with system security should avoid giving Local System privileges to services and accounts without serious justification.

To improve system security, set services and accounts to run with Domain User account privileges that limit their access to only the system resources they need for normal business operations. This approach to setting privilege levels keeps the number of services and accounts with unrestricted system access to a minimum, which reduces the number of entities that can unintentionally or intentionally violate system security.