Skip to main content

where/How to give these permissions to k2 service account under active directory.

Domain Users group

Account Operators group
List contents and Read all properties permissions
Administrators group.

Hi, when you create an AD account, it is usually a Domain Users member by default.
Then this account should be a member of the local Administrators group on the server where K2 is to be installed.
It is usually not necessary to add that account to the Account Operators AD group unless you want to make any changes to AD, create users, groups, etc. from the K2 workflow.
And setting the "List contents and Read all properties permissions" permissions is usually not necessary either. And if it turns out to be necessary to set it, then you can delegate those permissions to that account in AD Users and Computers, using the wizard.
AD administrators should know what we're talking about.

Reply