Tuesday, 10 May 2016

Create Management Container and give Permissions

Configure Active Directory Permissions:
1) Logon to DC server, Open ADSI Edit mmc snap-in console , right-click ADSI Edit and click Connect to … :


2) Display Connection Settings :


 3) Click OK , Expand Domain <computer fully qualified domain name>, expand <distinguished name>, click CN=System :


 4) Right-click CN=System, click New, and then click Object… :


 5) In the Create Object dialog box, select container :


6) Then click Next , iIn the Value box, type System Management :


7) Click Next , display finish phase :


8) Click Finish , you can see created new container :


 9) Close ADSI Edit mmc snap-in console .

10) Open Active Directory Users and Computers mmc snap-in console . Point to View and choose Advanced Features item :
 

 11) Expand the System container, right-click System Management, and then click Properties:



12) System Properties is display , click Security page :


13) Click Add…,Display Select Users , Computers ,Service Accounts , or Groups box:



14) Click Object Types…item,just choose Computers in Object Types box :


15) Click OK and fill SC2012 ConfigMgr site server NetBIOS name :


16) Click Check Names to confirm , and click OK,return to System Properties box , and point just added computer name and choose all Allow items :




17) Click Advanced will display Advanced Security Settings for System box:


18) Double-click SC2012 ConfigMgr site server name , will display Permission Entry for System :


19) You need to choose This object and all descendant objects In Apply to , and confirm all Allow items was choose :


20) Click OK and back to Advanced Security Settings for System box :



21) Two consecutive hits OK will finish setting AD permission , close ADUC mmc snap-in console.

NOTE: Do the Same Thing for All the users you Created.

No comments:

Post a Comment