Service account and access
The NodeGraph service account needs to be a local admin on the server where NodeGraph is installed, and it must have read access to all the files and file shares used by any of the monitored systems. NodeGraph is by default set up to use the Local System account as the running account. This needs to be changed under Microsoft Services if the default does not have read access to your file environment.
Additional system access
In addition to the service account, the different connectors may require special rights to be able to extract all available metadata.
MS SQL
The account used to connect to the MS SQL server needs to be sysadmin. During the connector setup in NodeGraph, a connection string needs to be entered. This makes it possible for the NodeGraph admin to decide whether internal authentication with the NodeGraph service account should be used, or if a specific database user should be specified.
QlikView
No extra access is required.
Qlik Sense
An exported trust certificate from the QMC will be required by NodeGraph for API calls to be allowed. The service account also needs to be RootAdmin to ensure full rights during API calls. For this reason, it is best to run NodeGraph with the same service account as Qlik services use and adding it to the local admin group on the server.
Tableau
During the connector setup, a Tableau user is specified, either by using the credentials directly or by specifying a Personal Access Token. The Tableau user specified needs to be Site Administrator or have similar rights for content extraction.