Re: Sms2003 and extending AD
- From: zackangelo@xxxxxxxxx
- Date: 1 Dec 2006 09:19:31 -0800
Coincidentially, I'm also having problems with AD permissions. I
installed SMS without granting the proper permissions to
<domain>/System/System Management. I've done this, and about an hour
later, SMS created two more objects under that container. It then
threw an error message about security on the newly created objects. So,
I went in and manually assigned the necessary permissions and I'm
waiting for SMS to wake up and try and publish to AD again.
Is there a way to force SMS to publish to AD so I can get my clients
working?
Thanks,
Zack
Michel-Vincent wrote:
Hello
You probably have checked the option to publish server fqdn in SMS.
This can only work if you have extended AD with the SMS extensions FROM SP2
(allow me to insist on the SP2 as this is a common mistake).
Once you've extended the AD Schema, check that SMS service account (in your
case SMS computer account has the proper permissions in your AD and you
should be fine.
Of course, once everything is OK, you need to wait a couple of minutes for
SMS to actually publish the info in AD.
Hope it helps,
Cheers
MV
--
Michel-Vincent Leriche
http://mvleriche.spaces.live.com
"gdinescu@xxxxxxxxx" wrote:
Ok, i have found the answer:
"Although schema extension can be performed automatically during
installation, a manual procedure is required to grant SMS permissions
to successfully publish information to Active Directory. Failure to do
so causes SMS to generate error 4913 and prevents SMS clients from
accessing SMS information in Active Directory."
But another question rises: What do i have to setup in order for the
error to stop? (besides extending the schema - I'm using windows server
2000 and by default the schema is locked)
gdinescu@xxxxxxxxx wrote:
Hi,
I've installed SMS2003 sp2 in advanced security mode, without extending
AD. In the SMS console, under component status i can see errors under
SMS_SITE_COMPONENT, to be more specific the 4913 error (Systems
Management Server cannot create the object "cn=SMS-SLP-ROB-SMSSRV01" in
Active Directory)
I went in AD and gave full control to SMSSRV01 for the System
management container but i still get these errors. My question is can
SMS add these two objects (SLP, MP) to AD without the schema being
extended?
Thank you in advanced,
.
- Follow-Ups:
- Re: Sms2003 and extending AD
- From: zackangelo
- Re: Sms2003 and extending AD
- References:
- Re: Sms2003 and extending AD
- From: gdinescu
- Re: Sms2003 and extending AD
- Prev by Date: Re: Reporting Point hangs up in Loading...
- Next by Date: Re: Sms2003 and extending AD
- Previous by thread: Re: Sms2003 and extending AD
- Next by thread: Re: Sms2003 and extending AD
- Index(es):
Relevant Pages
|
Loading