Re: Domain Admins Permissions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



"Robin Hearne" <RobinHearne@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:797D302C-54FD-401D-A86E-EEAA0DA1CA4A@xxxxxxxxxxxxxxxx
> We have an SMS 2.0 installation in an Active Directory 2003 domain.
> Currently there are several SMS service accounts in the Domain Admins
group
> and loads of them in the Administrators group for the domain.
>
> Is it absolutely necessary for these accounts to be there or is there
> another way to give them the permissions that they need but without having
> them in either the Domain Admins or the Administrators group?

There was a Microsoft SMS 2.0 Security whitepaper that covered this... while
it's easier to use and deploy SMS with an account with domain admin rights,
it is possible to make it work without being a Domain Admin. However, on
each server/client you would need to allow the SMS 2.0 service account to
have local administrator rights.

Here you go:
http://support.microsoft.com/default.aspx?scid=kb;en-us;294786

Steve


.



Relevant Pages

  • Secondary site creation
    ... OK I'm very new to SMS administration and am just starting to deploy SMS in ... I've setup the primary site server at our HQ location and am ... I've added the primary site server's computer account to our domain admins ...
    (microsoft.public.sms.setup)
  • Re: SMS Service Account Question
    ... You should be able to remove from the Domain admins without implications. ... Just make sure that account is a local admin on all SMS site systems. ...
    (microsoft.public.sms.admin)
  • SMS 2.0 not installing on XP SP2 RC2 system ?
    ... So I got a problem where SMS 2.0 does ... a Network Discovery of clients, so in the Log it sees the machine ... Machine has the Firewall turned OFF, on the domain, so domain admins ...
    (microsoft.public.sms.admin)
  • Logon Points
    ... I have several secondary sites within one domain which have all been working ... correctly.I then exported all the data from SMS using Site Properties Manager ... When i checked on my sites a few days later,all my service accounts for the ...
    (microsoft.public.sms.admin)
  • Re: fix it or trash it & start over
    ... Can you launch the SMS Admin Console? ... new accounts if needed and apply security. ... you don't need service accounts and passwords. ...
    (microsoft.public.sms.admin)