i want to ask about MacAfee epos best practice for service accounts minimum privilege’s “hardening” for deployment and operation

Local administration
Log on locally
Log on remote desktop
Log on through Network
Log on as a batch job
Log on as a service

i want to what to allow and what to deny from the above list for both SQL service account and McAfee deploy account to function properly and with lest privilege’s required. if any one has best practice just tell me

Thanks in advance

2 Spice ups