Please ensure Javascript is enabled for purposes of website accessibility
Powered by Zoomin Software. For more details please contactZoomin

Data Archive Administration

Manage service principle names

  • Last UpdatedApr 15, 2025
  • 1 minute read

Service Principal Names (SPNs) are required for Kerberos authentication in Windows environments. When Data Archive is installed, SPNs are automatically registered for the account running PI Network Manager. However, there are scenarios where manual SPN management is necessary, such as when changing the service account or troubleshooting authentication issues.

SPN misconfigurations can lead to authentication failures, preventing clients from successfully connecting to Data Archive. This section provides instructions on how to view, register, update, and remove SPNs.

Key points for SPNs in Data Archive

Here are some key things to know about SPNs in Data Archive:

  • SPNs uniquely identify Data Archive services for Kerberos authentication.

  • SPNs are automatically created during installation and assigned to the computer account.

  • If the PI Network Manager account changes, SPNs must be manually reassigned.

  • Incorrect or missing SPNs can cause Windows authentication failures.

    Note: If you are running PI Network Manager using the default account (such as virtual service account), the SPN must be assigned to the computer account (for example, ‘domain\pidataarchivehostname$’).

TitleResults for “How to create a CRG?”Also Available in