Local Machine Required Permissions¶
This section describes the local Windows permissions IMan needs to run normally.
If you change the account the services and the WebAPI application pool run as, the new user needs each of the privileges below. The IMan Permissions Function grants them all on the server.
File Permissions¶
IMan Shared Data¶
The IMan services and the WebAPI application pool must all have modify rights
to the IMan folder chosen during installation, C:\IMan by default.
IMan does not work at all without this privilege.
IMan Install Directory¶
The IMan services and the WebAPI application pool must all have read and
execute rights to the IMan program folder,
C:\Program Files (x86)\Realisable Software\IMan, and its subfolders. The
integration engine is in the IntManEng subfolder.
IMan does not work at all without this privilege.
HTTPS Certificate¶
The user IMan runs as must be able to read the private key of IMan's HTTPS certificate. Without it, the services cannot serve HTTPS.
Key Certificate¶
The user IMan runs as must be able to read the private key of IMan's key certificate, IMan KEK <database>. The key certificate opens the passwords, keys and tokens IMan stores. Without it, IMan cannot read them, and its services do not start. See Secrets.
IIS Worker Process Group¶
The user the WebAPI application pool runs as must be a member of the local IIS_IUSRS group.
Logon As a Service Privilege¶
A user must have Logon As A Service rights to run any service application. The user the IMan services run as must have this right, or the services cannot start.
Replace a Process Level Token Privilege¶
The Process task can start a program as another Windows user. To do so, the user IMan runs as needs the Replace a Process Level Token right.
Without this right the Process task fails.
DCOM Permissions¶
When the Sage 300 connector prints or exports forms such as an A/R Invoice or O/E Order Confirmation, it creates an out-of-process DCOM server to do the printing.
The user the IMan services run as needs Local Launch and Local Activation permissions on that DCOM application, whose AppID is {292D0CB8-6F03-42F0-8794-54830F6972FF}. The Permissions function grants both. Without them, Sage 300 printing fails with a DCOM permission error when the services run as a user other than LocalSystem.