Skip to Main Content
AVEVA Product Feedback


Status No status
Categories Installation
Created by Guest
Created on Oct 5, 2026

Allow managed service accounts to be specified for each service during installation

There are KB articles that talk about how to switch the services of the PI Server install kit to use managed service accounts and grant them the appropriate permissions:

This takes a while to set up, especially for the PI Data Archive, and it is easy to make a mistake (e.g. forget to grant certain permissions or accidentally grant excessive permissions).

To make this easier and less error-prone, especially when you consider that the use of managed service accounts for services is a best practice, please allow managed service accounts to be specified, during installation, for each service that will be installed. The install kit should automatically grant all of the required permissions for each managed service account. After installation, the install kit should also allow you to modify the installation to change the managed service accounts.

The install kit for the PI SQL Data Access Server (RTQP Engine) is a good example of an install kit that allows you to specify any type of account, including managed service accounts, during installation for the services. However, unlike what I am proposing for the PI Server install kit, it does not allow the service accounts to be changed when you modify the installation.

To be clear, when I say "managed service accounts", I am talking about both standalone managed service accounts (sMSAs) and group managed service accounts (gMSAs). As a general comment, for PI in general, it seems that managed service accounts are an afterthought with workarounds, and most PI programs and install kits still expect you to use a regular user account as the service account. This should change so that managed service accounts are at least as easy to use as regular user accounts for PI services.

  • Attach files