Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- From: "Cathy Moya [MS]" <camoya@xxxxxxxxxxxxxxxxxxxx>
- Date: Mon, 23 May 2005 09:42:44 -0700
Domain controllers DO have local groups, they just work a little differently
on DCs than they do on member servers and workstations. Administrators is a
local group, but it is "local" to all domain controllers. Yes, this opens up
the security a bit. That's why in a high security environment we don't
recommend installing site servers (primary or secondary) on domain
controllers. But if you have to do it, you have to accept the risks for SMS
accounts that require admin rights.
For security procedures, see Appendix E: SMS Security Procedures in
Scenarios and Procedures for Microsoft Systems Management Server 2003:
Security
http://www.microsoft.com/technet/prodtechnol/sms/sms2003/security/spsecsms03/spsec_10.mspx
There is a section of procedures for SMS Account Management near the end.
You want the procedure: Adding Computer Accounts to Groups.
We tried breaking the Concepts, Planning and Depoyment Guide (CPDG) into
something that is more procedural. We've had mixed reaction so far. We're
trying some different approaches in the next version. If you have feedback,
please write to us at smsdocs@xxxxxxxxxxxxxxx We welcome your feedback!
--
Cathy Moya, CISSP, MCSE: Security
Technical Writer, Windows Enterprise Management Division User Assistance
Check out the SMS Technical FAQ:
http://www.microsoft.com/technet/prodtechnol/sms/sms2003/techfaq/default.mspx
This posting is provided AS IS with no warranties and confers no rights.
"John Noble" <john.exists@xxxxxxxxx> wrote in message
news:1116669083.877889.118390@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Kim, Sylvain,
>
> I'm running 2003 SP1 on both machines, yes. The machine I'm trying to
> connect to is a DC - no, I haven't added the computer account of the
> Primary server to any groups. As it's a DC, and therefore has no local
> groups, where do I need to add permissions?
>
> Is it just me, or is the Microsoft document (the 700 page deployment
> guide) very heavy on ideas and theories and very light on actually "do
> this, click this, add this"? It doesn't seem all that useful to the
> poor techie having to do the work. :-/
>
> My "browsing" account is a domain admin account.
>
.
- Follow-Ups:
- Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- From: John Noble
- Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- References:
- SMS 2003 - adding Secondary site... driving me -mental- :-/
- From: John Noble
- Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- From: Kim Oppalfens
- Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- From: John Noble
- SMS 2003 - adding Secondary site... driving me -mental- :-/
- Prev by Date: Dead Primary Site Server
- Next by Date: Can't add login for moved SMS database
- Previous by thread: Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- Next by thread: Re: SMS 2003 - adding Secondary site... driving me -mental- :-/
- Index(es):
Relevant Pages
|