Secondary Site on a DC

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Jeff Singer (JeffSinger_at_discussions.microsoft.com)
Date: 09/09/04


Date: Thu, 9 Sep 2004 14:39:03 -0700

It appears that making Domain Controllers a secondary site server is not an
uncommon idea... just one that is frowned on from a security perspective from
Microsoft.

I have my lab setup using SMS 2003 in Advanced Security mode. When creating
an address for the parent and child site to use would it be possible to use a
domain account instead of the computer account? Eventually, when this hits
the production environment each of our 28 or so Domain Controllers at remote
sites is going to be a Secondary site server. Instead of making each
computer account a Domain Admin would I be able to just use a single account
in the domain admin group to work as the "New Address to Parent Site" service
account?

Also, how are other people using domain controllers as site servers working
around this while keeping security in perspective?

-Jeff



Relevant Pages

  • Re: having problems creating packages - access denied..
    ... I've given a global group (which contains all of the site server computer ... full share permission and also full local security permission. ... SMS uses the site server computer account to connect to ...
    (microsoft.public.sms.admin)
  • Re: SMS Site Component Manager failed to reinstall SMS_SQL_Monitor
    ... Is the SQL the default instance or a named instance? ... Is this standard security? ... Also check to see if the account is not locked out. ... so it was the machine name of my Site server). ...
    (microsoft.public.sms.admin)
  • Re: SMS_MP_CONTROL_MANAGER
    ... In standard security the account used here is SMSServer_sitecode and is ... ACLd with needed rights on the site server. ... In advanced security the MP uses its machine account to communicate with the ... > connected to the network, ...
    (microsoft.public.sms.setup)
  • Re: Change SMS 2.0 Component Server Storage Object
    ... Your site server was not changed. ... Were they just logon points or were they ... The Storage Object for our domain controllers point to ...
    (microsoft.public.sms.admin)
  • [NT] Security considerations to keep in mind when using Site Server 3.0
    ... Site Server version 3.0 Commerce Edition ... LDAP_Anonymous user account, which is used by the included LDAP service. ... A valid NT user account is required to upload ...
    (Securiteam)