Back

Can we use a Managed Service Account (MSA) for eOne SmartConnect Service or API Service in SmartConnect 21?

Published: Mar 21, 2025
Post Author Written by Amit Chaudhari

Yes, we can use a Managed Service Account (MSA) for the eOne Window Service Scheduler or eOne SmartConnect API Service. The only consideration is that the password is automatically managed by the Windows Service Control Manager (SCM) on the machine where the service is running. As a result, it will not cause any interruptions when starting, stopping, or pausing the service

An MSA account must have at least local administrator permissions on the machine, so add the account into local machines administrator group.

Here’s a key distinction between Managed Service Accounts (MSA) and Domain Service/User Accounts Accounts:

FeatureManaged Service Accounts (MSA)Domain Service/User Accounts
Password ManagementAutomatically managed by Active Directory, including regular rotationRequires manual password management with no automatic rotation
Password ExpirationNo manual intervention is needed; AD handles expiration and updatesNo built-in expiration policy; must be managed manually
Service AssociationTied to a single machine (Standalone MSA) or multiple machines (Group MSA)Can be used across multiple machines
SecurityMore secure due to automatic password rotation and elimination of hardcoded credentialsLess secure if passwords are not regularly changed manually
Configuration ComplexityEasier to manage since AD automates password changesRequires administrative effort to maintain password policies
UsageIdeal for services running on a specific machine or group of machinesCommonly used for applications and services that need access across multiple servers

In SmartConnect 21, MSA does not have a password, the SmartConnect Configuration screen will show the following message during installation.

For: eOne Windows Service:

Managed service account

For: eOne API Service:

Managed service account


To proceed, use a different account (either a domain user or a domain service user) with at least local administrator permissions on the machine to install the service.

For Example: As outlined in Step 7 below.
https://www.eonesolutions.com/help-article/how-to-reinstall-the-smartconnect-21-scheduler-service/

we need to change the account later after the installation.

Once SmartConnect Window Service Installed >>
  1. Open the Start menu, select ‘Run’ and type services.msc, then press ‘Enter’.
  2. In the Services window, locate eOne SmartConnect Service.
  3. Right-click the service and select ‘Properties‘. Navigate to the Log On tab, enter your MSA service account ID (or browse if needed), and leave the password field blank.
  4. Then, go to the General tab and start the service.
Once SmartConnect API Service Installed >>
  1. Open the Start menu, select Run, type inetmgr, and press ‘Enter‘.
  2. In Application Pools, locate SmartConnectWcf.
  3. Right-click and select ‘Advanced Settings’. Under the Process Model section, find Identity, then select ‘Custom Account > Set‘. Enter your MSA service account ID and leave the password field blank.
  4. Right-click and select ‘Recycling’ to restart the service. Ensure you can browse the SmartConnectWcf website under the Sites section. If needed, restart IIS to ensure the services function as expected.

    According to Microsoft, this is a warning (not an error) and “can typically be ignored.”
    https://techcommunity.microsoft.com/blog/iis-support-blog/iis-manager-shows-authorization-warning-when-testing-a-physical-path/287861


Have a question? Please reach out to us at support@eonesolutions.com

Feeling stuck? Get the support and guidance you need to help you power through any data challenge

We're on your integration team. Connect with our people and let us know how we can help you.