In my environment ,we're runing luall.exe to update Definition in SEPM.
usually we run the luall.exe as an administrator.now our AD team going to disable all admin rights to our user.
So they requested us what kind of permission or rights for our user to perform daily SEPM tasks such as manual def update(also to upgrade SEPM).so they can create a restricted user,allowed to perform only the required task
I want to know is there any way to run/upgrade without full admin rights
I read the article about file permission https://support.symantec.com/en_US/article.TECH91181.html
which leads me to another question .whether A user without full admin rights ,can able to perform manual live update (luall.exe)\upgrade SEPM ,if that user with full access control (read,write and execute) only to all the Endpoint Protection Manager and its sub folders?