On the computer running the Application Object Server (AOS), only members of the local Microsoft Windows Power User group or Administrators group can change configuration settings.

Restrict membership in these groups as much as is feasible, to reduce the potential for malicious mischief.

The log directory cannot be changed - the log is always installed to installationdirectory\log. Be sure to set the access control list for the directory so that only administrators and the AOS account (the domain account or Network Service account associated with an AOS instance) have write privileges to this directory.