Configure the Microsoft Single Sign-On Service

To use single sign-on, the Microsoft Single Sign-On Service service (SSO service) must be installed on all Microsoft Windows front-end servers in the farm. The SSO service must also be installed on all servers running Excel Services. If the Business Data Catalog search is used, the SSO service must also be installed on the index server.

The SSO service is configured by using the Services console. When configuring the service, a logon account is required. The logon account must be the following:

  • A domain user account. It cannot be a group account.

  • A SharePoint server farm account.

  • A member of the local Administrators group on the encryption-key server (the encryption-key server is the first server on which you start the SSO service).

  • A member of the Security Administrators group and DB creator group on the computer running Microsoft SQL Server.

  • Either the same as the single sign-on administrator account or a member of the group account that is the single sign-on administrator account.

Top of Page

Share Facebook Facebook Twitter Twitter Email Email

Was this information helpful?

Great! Any other feedback?

How can we improve it?

Thank you for your feedback!