<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/discussions/f/administration/17667/new-service-account-added-to-security-group-not-included-when-group-is-deployed-to-higher-environment</link><description>Created a new Service Account in the Admin Console and generated API Key. Added the new Service Account to a security group that has access to an application. Added the updated security group to a patch and deployed it to the next higher environment </description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69590?ContentTypeID=1</link><pubDate>Thu, 26 Sep 2019 12:11:48 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:7bc8ebe0-39af-444d-8b34-d961f1e71b41</guid><dc:creator>judym598</dc:creator><description>&lt;p&gt;Thank you!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69585?ContentTypeID=1</link><pubDate>Wed, 25 Sep 2019 23:03:37 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:e15f539f-508f-47e3-857f-b7c2376a596f</guid><dc:creator>Robert Shankin</dc:creator><description>&lt;p&gt;You&amp;#39;re right, Judy: Service Accounts are still basically user accounts first.&amp;nbsp; &lt;br /&gt;When a user is added to the Service Accounts user role (group), it becomes a service account.&lt;br /&gt;According to current product functionality, user accounts must be created in each environment where they are to be used.&amp;nbsp;&amp;nbsp;&lt;br /&gt;They cannot be moved from one environment to another like other Appian objects.&lt;br /&gt;When a group object is&amp;nbsp;exported from a system, member users are not also exported.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69564?ContentTypeID=1</link><pubDate>Wed, 25 Sep 2019 14:44:19 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:f6c8d30e-db35-4f3c-a83b-40124c63f142</guid><dc:creator>judym598</dc:creator><description>&lt;p&gt;You may be right - If I had included the Service Account&amp;nbsp;&lt;em&gt;group&amp;nbsp;&lt;/em&gt;and promoted it that way- It would have included the user but because this new Service Account is a &amp;#39;user account&amp;#39;, it is likely that it needs to be added manually. I didn&amp;#39;t really think of the Service Account as being like a user account but I suspect that&amp;#39;s the case.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69562?ContentTypeID=1</link><pubDate>Wed, 25 Sep 2019 14:33:33 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:94712d5b-5623-484e-8868-bb7f0c5c1305</guid><dc:creator>Mike Schmitt</dc:creator><description>[quote userid="2799" url="~/discussions/f/administration/17667/new-service-account-added-to-security-group-not-included-when-group-is-deployed-to-higher-environment/69559"]that group can be promoted to higher environments.[/quote]
&lt;p&gt;My reading of it was that the group / &amp;quot;permission&amp;quot; is promoted, not actually the account, though I do see where you&amp;#39;re coming from.&amp;nbsp; I don&amp;#39;t have much experience yet with this new service account construct, all I know is that traditional user accounts are never transferred between environments.&amp;nbsp; Hopefully someone with more detailed technical knowledge about this new functionality can weigh in as well.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69559?ContentTypeID=1</link><pubDate>Wed, 25 Sep 2019 14:22:18 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c818c005-ef78-4db1-ac0d-87daddaa2c51</guid><dc:creator>judym598</dc:creator><description>&lt;p&gt;But the next sentence implies that once the it is in the same group - that group can be promoted to higher environments.&lt;/p&gt;
&lt;p&gt;&amp;quot;&lt;span&gt;so that permissions can be promoted to higher environments&amp;quot;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;To me it seems as though If I create ABC.Service (as a new Service Account) in each environment and add it to GroupXYZ in DEV, when I create a patch in DEV with this updated group and import it into TEST (where ABC.Service already exists) - GroupXYZ in TEST should include ABC.Service. I shouldn&amp;#39;t have to manually add it to the group.&amp;nbsp;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="https://docs.appian.com/suite/help/19.3/Web_API_Authentication.html"&gt;https://docs.appian.com/suite/help/19.3/Web_API_Authentication.html#&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: New Service Account added to Security Group not included when group is deployed to higher environment</title><link>https://community.appian.com/thread/69558?ContentTypeID=1</link><pubDate>Wed, 25 Sep 2019 14:15:33 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:a0eadf13-dc88-4572-9eaf-48f5d2cab382</guid><dc:creator>Mike Schmitt</dc:creator><description>[quote userid="2799" url="~/discussions/f/administration/17667/new-service-account-added-to-security-group-not-included-when-group-is-deployed-to-higher-environment"]&lt;span&gt;Service accounts should be created in each environment with the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;same username&lt;/strong&gt;&lt;span&gt;&amp;nbsp;and placed in the&amp;nbsp;&lt;/span&gt;&lt;strong&gt;same groups&lt;/strong&gt;[/quote]
&lt;p&gt;Actually, this implies to me (without further clarification at least) that the service account *does* need to be manually placed into the appropriate group in each environment.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>