Skip to Main Content
Integration


This is an IBM Automation portal for Integration products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.


Status Submitted
Created by Guest
Created on Aug 28, 2026

BigFix / ILMT Upgrade Case Summary and Pre-Upgrade Recommendation

Why is this useful?

This enhancement would prevent a common and difficult-to-identify failure during BigFix and ILMT upgrades in environments using a remote SQL Server with Windows Authentication.

In this case, the pre-upgrade Fixlet failed because some BigFix-related services were running under a local system/user account while others were running under the approved service account. The logs showed only a SQL login failure for the machine account and did not clearly indicate that inconsistent service logon accounts were the underlying cause.

By detecting this before the upgrade starts, the enhancement would reduce failed Fixlet executions, avoid unnecessary troubleshooting, minimize upgrade delays, and improve confidence in the upgrade process.

Who will benefit?

This will benefit:

BigFix and ILMT administrators performing version upgrades.

Windows and SQL Server administrators supporting BigFix environments.

IBM Support teams handling upgrade and authentication-related cases.

Customers using remote SQL Server databases with Windows Authentication.

Implementation partners and managed-service teams responsible for upgrade readiness.

How should it work?

The BigFix pre-upgrade Fixlet should include an automated Service Account and Remote SQL Authentication Pre-Check.

Before allowing the upgrade to proceed, the Fixlet should:

Detect and display the logon account configured for all relevant BigFix services, including BES Server components and BES Client.

Identify inconsistent configurations, such as services running under Local System/local user while other required services use a domain service account.

Clearly show the Windows identity that will be presented to the remote SQL Server during the Fixlet execution.

Warn the administrator when Local System will cause the BigFix server machine account to be used for database authentication.

Validate that the account used for the upgrade has the required permissions on the BFEnterprise and BESReporting databases.

Explain that credentials entered in the Fixlet may not override Windows Authentication when the Fixlet runs under the BES Client service context.

Provide clear pre-upgrade guidance to correct the service-account configuration and record the original configuration.

Remind administrators to restore any temporarily changed service account after the upgrade, where required by the standard BigFix configuration.

This capability would provide clear direction before the Fixlet runs, instead of relying on unclear SQL authentication errors after failure.

Idea priority Urgent