RE: SMS Administrator Accounts



Have you tried to make something like a trust just to get your account into a
group in the other domain?

"Michael Day" wrote:

> Our company merged with another. We had SMS they didn't. My Domain's SMS
> account does not have privs on the new domain and I cannot add my SMS Admin
> acount to the new domain. Neither can I add the new Domain - Domain Admins
> account to our old domain. All computers are on separate domains (some in
> our location are on the new company's domain).
>
> What account can I use to deploy packages to all servers in all domains?
> The only way I've been told how I can have administrator privs on all
> computers is to put my ID in the local administrators group on all of the
> computers either manually or with a script.
>
> Is this the only way for me to successfully deploy packages to all
> computers? I know soon I will be called upon to build site servers at the
> other locations, push out clients to all computers and will also have to
> deploy security patches to all servers in all locations eventually.
>
> I encountered this the other day when I was deploying the security patches.
> My package failed on a couple of local servers that happen to be in the new
> company's domain. My
>
> Mike Day - SMS Administrator
> mike.day@xxxxxxxxxx
.



Relevant Pages

  • Re: MP stopped working on Windows 2003 DC after MS04-037 patch
    ... As for the DC recommendation, we're a mid-size company with 16 ... With our Enterprise Agreement and licensing changes in SMS ... > The IWAM_computer account is a local account when on a member server, ... > member servers for all SMS roles. ...
    (microsoft.public.sms.misc)
  • Re: Disabling Local user accounts on member servers and workstations
    ... identify those computers. ... winnt:// Provider to disable this account. ... disabling. ... connecting to the servers I want to disable the account on. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Disable Distribution or advertisements to selected clients
    ... Above is a way to create a collection of computers based on user names of ad groups. ... The issue we have is more an internal one where an IT staff member logs into a system with there standard user account and ends up having applications deployed to systems that are not supposed to get those applications, ... My solution to the problem would be to restrict who can logon to servers via GPO, but in any case, if the IT staff members admin account is put into an group that SMS advertisements apply then they'll have apps pushed onto servers. ...
    (microsoft.public.sms.swdist)
  • Re: Agent on servers
    ... account on the servers and even enabled the guest accounts on both ... sides.Lately I am trying to install more servers but the installation is ... I HIGHLY recommend you migrating to SMS 2003... ...
    (microsoft.public.sms.admin)
  • Re: Using local accounts for installation and other things
    ... Kim Oppalfens ... Would be nice if SMS behaved like Harris' STAT Guardian VMS Vulnerability ... have some computers that are not on the Domain, ... account on those. ...
    (microsoft.public.sms.setup)

Loading