Setting up and managing device configurations using Intune
NDES Service Account Installation Failure – Interactive Logon Policy Conflict
We are encountering an installation failure while deploying the NDES role using a dedicated service account. The configuration fails with the error: "Logon Failure: the user has not been granted the requested logon type at this computer"
Our security standards mandate that service accounts belong to PG-Deny logon locally SVC, which blocks interactive logon. We verified that removing the service account from this deny group allows the setup to succeed. However, our security team cannot approve permanent interactive logon permissions for service accounts due to compliance risks.
Could you please clarify:
- The exact logon rights required by the NDES service account both during installation and at runtime ?
- Supported hardening workarounds or procedural steps to install NDES without granting permanent interactive logon rights to the service account?