Deploying a Distributed Engine correctly helps improve performance and reliability. Using least-privilege service accounts and planning for auto-upgrades ensures smoother operations and fewer surprises down the road.
This post provides a quick walk-through of the steps and best practices for deploying a Distributed Engine in Delinea Secret Server.
Key highlights:
- Install via Admin → Distributed Engine → Add Engine, use the “Default” site, download, unzip, then run setup.
- Run the engine as a service account with minimal privileges. Once set up, activate the engine via the Delinea UI so the Connection & Activation status shows green.
- To support auto-upgrades, ensure that your service account is a member of the local Administrators group and has full rights to the installation directory. After changing the logon identity, restart the service, then deactivate the old engine and activate the new one.
- Download engine. Select 64-bit or 32-bit architecture and the preconfigured site.

2. Extract the downloaded file Thycotic.DistributedEngine.Service.Default.x64 and start the setup.

3. Deline Distributed Engine setup will start the Service Engine Installation.

4. You can check that the installation is completed in the Windows Services.

5. Go back to the Delinea Platform and check the Distributed Engine. Now you will see a new entry representing your Active Directory Server. Go to the right and click Activate.

6. Once Activated, you will see the Activation Status moving from pending to a green check mark. At this point, the AD distributed engine was added successfully.

