« ConfigMgr SP2 RTM is available!ConfigMgr Service Pack 2 hits RTM »

Ouch...!

10/22/09 | by Jannes Alink [mail] | Categories: System Center, ConfigMgr

Sometimes I do a review of existing ConfigMgr environments. Most of the environments have extended the Active Directory schema which is always a good idea. It saves you lots of administrative tasks and configuration.

ConfigMgr needs access to the schema and one of the things I always check in those environments is to see how the rights in Active Directory are configured. Today I faced that all the ConfigMgr computeraccounts were a member of the Domain Admin group! Well...never seen that before!

Let me clarify; this is not required at all.

The schema extension allows ConfigMgr to publish data in a AD container named ‘System Management’ which is a sub-container of the Active Directory System container.

The System Management container is not created by default so this should be done by hand with the ADSIEDIT tool.
All the site server computer accounts must have Full Control rights on this 'System Management' sub-container and all childs, to publish their data. An important note; also Secondary Sites need those permissions.

So hopefully once and for all; All ConfigMgr Site Server computer accounts needs Full Control rights on only the 'System Management' container and all child objects.

Permalink

Search



Hi,

I'm Jannes Alink and welcome to my blog! I'm living in the Netherlands and working in the IT industry for more than 8 years. I work as freelance consultant at Alinja and deliver projects around the globe. Currently on a project in Abu Dhabi (UAE).

Posts are just my personal opinion.

February 2012
Mon Tue Wed Thu Fri Sat Sun
 << <   > >>
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29        

XML Feeds

powered by b2evolution free blog software