Grant Service Account Rights
When the Royal Server service runs as a Windows account other than LOCAL SYSTEM, that account needs two user rights to run Dynamic Folder and Dynamic Credential scripts as the requesting user:
- Replace a process level token (
SeAssignPrimaryTokenPrivilege) - Adjust memory quotas for a process (
SeIncreaseQuotaPrivilege, administrators hold it by default)
Royal Server starts the script interpreter of a Dynamic Folder or Dynamic Credential script - including PowerShell, when it is the configured interpreter - as a separate process running as the requesting user, and Windows requires both rights for that.
Note
The rights are needed only for Dynamic Folder and Dynamic Credential scripts. All other Royal Server features, including PowerShell execution through the Script module, work without them: that PowerShell runs inside the Royal Server service or on the target machine via WinRM, and no process is started as another user. If you do not use Dynamic Folders or Dynamic Credentials with Royal Server, you do not need this script.
The Services console does not grant these rights when you configure the service account. The script grant_service_account_rights.ps1, shipped with Royal Server 5.04.50928 and newer, grants them. You can find it in <royal-server-installation-directory>\Scripts\grant_service_account_rights.ps1.
Usage
- Open the script in an editor and set the variable
$Accountat the top to the account the Royal Server service runs as (Services console > Royal Server > Log On). Accepted forms:DOMAIN\user,[email protected],COMPUTERNAME\user,.\userfor a local account, or a SID. - Optionally set
$WhatIf = $trueto only show which rights are already granted and which are missing, without changing anything. - Run the script from an elevated PowerShell.
# --- configuration ---
$Account = 'DOMAIN\svc-royalserver'
$ServiceName = 'RoyalServer'
$RestartService = $true
$WhatIf = $false
The script exports the current user rights assignment with secedit, adds the account to both rights - keeping all existing members - and applies only these two rights. Afterwards it restarts the Royal Server service, because the rights only apply to a new logon of the account. Set $RestartService = $false to restart it yourself.
Note
If a domain Group Policy defines one of these user rights, it overwrites the local assignment on the next policy refresh. In that case, add the service account to that Group Policy instead. gpresult /h report.html shows which policy applies.
Royal Server 5.04.50928 and newer log a warning at startup as long as one of the rights is missing, and reject Dynamic Folder and Dynamic Credential scripts with a clear error message. Everything else keeps working.