Verify Registry Permissions

The account the Tableau Server service runs under needs permission to modify the registry on the local machine.

In a multi-node cluster, the registry permissions are only granted on the tsm node in the cluster.

When you update the Run As service account, TSM will configure the registry permissions on the Tableau computer for the account you specify. It's unlikely that you will need to apply these permissions manually.

Verify that the Run As service account has been granted permissions to the HKEY_LOCAL_MACHINE\Software\Tableau registry branch. If the account that you have specified as the Run As service account is a member of the local administrative group or a member of the Domain Admins security group, then the account will not be displayed on the Permissions page.

Permissions

TSM will grant Read permission and the following Special permissions to these branches:

  • Query Value
  • Set Value
  • Create Subkey
  • Enumerate Subkeys
  • Notify
  • Write DAC
  • Write Owner
  • Read Control

To view or edit permissions on registry directories:

  1. Open the Registry Editor by entering regedit in Windows Run, and then clicking OK.
  2. In Registry Editor, navigate to the directory where you want to view or edit permissions. Right-click the directory, and then click Permissions....
  3. In Permissions, on the Security tab, select the Run As service account, and then click Advanced.
    If you are adding your Run As service account, then click Add and follow the Windows process for adding a user account to the Security tab. After you have added the account, then select the Run As service account, and then click Advanced
  4. In Advanced Security Settings. on the Permissions tab, select the Run As service account, and then click Edit.
  5. On the Permission Entry, under Basic permissions, verify that Read and Special permissions are selected. Verify that Only apply these permissions to objects and/or containers within this container is not selected.
  6. To view or edit Special permissions, click Show advanced permissions.
  7. Under Advanced permissions, verify that the permissions enumerated at the beginning of this topic are selected. Verify that Only apply these permissions to objects and/or containers within this container is not selected.
  8. If you have set new permissions, then click OKthrough the multiple windows to finish. If you have viewed permissions and not edited anything, then click Cancel to close all windows.
Thanks for your feedback!Your feedback has been successfully submitted. Thank you!