Installation of the Symantec Endpoint Protection Manager (SEPM) fails with the error "Failed to set Symantec Endpoint Protection Manager service account ACLs."
The following error is shown in a popup window while attempting to install the SEPM:
Failed to set Symantec Endpoint Protection Manager service account ACLs.
The following error is logged in the following file. Default location:
STDERR: com.sygate.scm.server.util.acl.ACLException: Failed to set ACL on object : HKLM\System\CurrentControlSet\services\semsrv
The following error is logged in the following file. Default location:
2014-07-22 12:23:29.093 THREAD 31 WARNING: SEPMACLManager>>applyAllACLs:
Begin...serverHome=D:\Program Files (x86)\Symantec\Symantec Endpoint Protection
Manager\tomcat,dataRoot=D:\Program Files (x86)\Symantec\Symantec Endpoint
Protection Manager\data,luClientPath=C:\Program Files (x86)\Symantec\LiveUpdate
2014-07-22 12:23:29.343 THREAD 31 WARNING: ACLUtil> executeSetACLExe>> Process
output:
INFORMATION: Processing ACL of:
<machine\System\CurrentControlSet\services\semsrv>
ERROR: Enabling the privilege SeSecurityPrivilege failed with: Not all
privileges or groups referenced are assigned to the caller.
ERROR: Reading the SD from <machine\System\CurrentControlSet\services\semsrv>
failed with: Not all privileges or groups referenced are assigned to the caller.
SetACL finished with error(s):
SetACL error message: A privilege could not be enabled
This error is caused because the user account which is attempting to install the SEPM is lacking the privilege SeSecurityPrivilege, or another application such as the splunk forwarder is accessing files in SEPM.
To resolve this issue, ensure that the installation is being performed by an Administrator level Windows Account. If the installation still fails, verify whether or not the SeSecurityPrivilege is present. This privilege is needed for the installation to complete successfully.
How to check whether the logged in account has the SeSecurityPrivilege:
If the privilege exist, Stop the splunkforwarder service.