Minimum Security User Rights
The groups and accounts that BizTalk Server uses have the minimum user rights they need to perform most tasks. Therefore, there are some tasks where you may need more user rights than the ones BizTalk Server automatically has granted the group to which you belong. The following table describes the Minimum Security User fRights you need to perform tasks in BizTalk Server.
| Task | Groups or Roles | ||
|---|---|---|---|
|
Setup |
|
||
|
Installation |
|
||
|
Configuration |
|
||
|
Join a BizTalk Server group |
|
||
|
BizTalk Administration |
|
||
|
Create a MessageBox database |
|
||
|
Create or delete a BizTalk host |
|
||
|
Change the Host Tracking property for a host |
|
||
|
Create (install), delete, or change the credentials for a host instance |
|
||
|
Start or stop a host instance |
|
||
|
Add or remove Server |
|
||
|
Add or remove a receive handler |
|
||
|
Start or stop applications, orchestrations, send ports, and send port groups |
|
||
|
Enable or disable receive locations |
|
||
|
Search for artifacts |
|
||
|
Add an adapter |
|
||
|
Backup databases |
|
||
|
Configure BizTalk Groups with a certificate |
|
||
|
All other tasks (including WMI) |
|
||
|
Operations and Message and Service Instance Tracking |
|
||
|
View Group Hub page, perform queries, save and load queries |
|
||
|
View query results |
|
||
|
General configuration and tracking configuration |
|
||
|
Browse a health monitoring cube |
|
||
|
View message properties |
|
||
|
Save message bodies |
|
||
|
Use Find Message query |
|
||
|
Use Query Build |
|
||
|
Use the orchestration debugger |
|
||
|
View message flow, message events in the Group Hub page using the BizTalk Server Administration console. |
|
||
|
Suspend, terminate, or resume instances |
|
||
|
Archiving or purging messages from the Tracking database |
|
||
|
All other tasks |
|
||
|
Tracking Profile Editor |
|
||
|
Read or write to the BizTalk Management database |
|
||
|
Event Bus Monitoring MMC |
|
||
|
All tasks |
|
||
|
BizTalk WCF Service Publishing Wizard |
|
||
|
All tasks |
|
||
|
BizTalk Web Services Publishing Wizard |
|
||
|
All tasks |
|
||
|
Business Activity Monitoring |
|
||
|
Run BM.exe |
|
||
|
Run BM.exe, if there is an Analysis Services database |
|
||
|
Create account for BAM View |
|
||
|
Rule Engine (publishing rules) |
|
||
|
Deploy/undeploy policies, manipulate security-related artifacts |
|
User rights for performing administrative tasks
In order to perform administrative tasks, using either the BizTalk Server Administration Console or Windows Management Instrumentation (WMI), the account performing the administrative tasks requires different levels of user rights depending on the task to perform.
The following table describes the user rights the account needs to perform the tasks, from least user rights (level 1), to most user rights (level 4).
| Level of user rights | User rights granted | Tasks |
|---|---|---|
|
0 |
|
|
|
1 |
|
|
|
2 |
|
|
|
3 |
|
|
|
4 |
|
|
See Also
© 2010 Microsoft Corporation. All rights reserved.
Note