Help! Configuring SSO

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: vamsi (vamsi_at_discussions.microsoft.com)
Date: 11/24/04


Date: Wed, 24 Nov 2004 10:39:02 -0800

All,
I am having trouble configuring SSO on a medium server farm.
I checked for all the preconfiguration steps to assign required permissions
for the accounts used.

I used AD Domain Admin account for service account.
This account is local admin on front1, front2, index servers.
and is system administrator on SQL, and has public role access to SPS config
db. This account is in STS_WPG, SPS_WPG groups on all three servers.

I get this error:User <domain>\<admin> failed to configure the single
sign-on server. The
error returned was 0x80004005.

I used another domain admin account and given all these permissions, I get'
you do not have enough permissions to perform this action' error.

Please help if I miss any configuration step. Also, pls. list all needed
requirements for SSO configuration on medium server farm.



Relevant Pages

  • Re: IUSR_myserver and deny write
    ... your configuration is the default from Microsoft. ... ran your ASP page... ... All run IIS under the NT AUTHORITY\Network account. ... IUSER_on the wwwroot directory has no read permissions. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Win2k - Account Operator not working properly
    ... You very likely have other ACL issues other than what was mentioned and I can point them out here for you for free or you can pay someone $200-500 an hour to come check it out. ... In order for that to result in inheritence protection it means the schema had to be modified. ... set the account in the GUI to inherit from its parents. ... Used the delegation wizard, on the top level OU, to assign the desired permissions. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Incoming E-Mail - cant create contact in OU
    ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
    (microsoft.public.sharepoint.windowsservices)