Configure Active Directory Permissions:
1) Logon to DC server, Open ADSI Edit mmc snap-in console , right-click ADSI Edit and click Connect to … :

2) Display Connection Settings :
3) Click OK , Expand Domain <computer fully qualified domain name>, expand <distinguished name>, click CN=System :
4) Right-click CN=System, click New, and then click Object… :
5) In the Create Object dialog box, select container :

6) Then click Next , iIn the Value box, type System Management :
7) Click Next , display finish phase :

8) Click Finish , you can see created new container :
9) Close ADSI Edit mmc snap-in console .
10) Open Active Directory Users and Computers mmc snap-in console . Point to View and choose Advanced Features item :

11) Expand the System container, right-click System Management, and then click Properties:

12) System Properties is display , click Security page :
13) Click Add…,Display Select Users , Computers ,Service Accounts , or Groups box:

14) Click Object Types…item,just choose Computers in Object Types box :

15) Click OK and fill SC2012 ConfigMgr site server NetBIOS name :

16) Click Check Names to confirm , and click OK,return to System Properties box , and point just added computer name and choose all Allow items :

17) Click Advanced will display Advanced Security Settings for System box:

18) Double-click SC2012 ConfigMgr site server name , will display Permission Entry for System :

19) You need to choose This object and all descendant objects In Apply to , and confirm all Allow items was choose :

20) Click OK and back to Advanced Security Settings for System box :

21) Two consecutive hits OK will finish setting AD permission , close ADUC mmc snap-in console.
NOTE: Do the Same Thing for All the users you Created.
1) Logon to DC server, Open ADSI Edit mmc snap-in console , right-click ADSI Edit and click Connect to … :
2) Display Connection Settings :
3) Click OK , Expand Domain <computer fully qualified domain name>, expand <distinguished name>, click CN=System :
4) Right-click CN=System, click New, and then click Object… :
5) In the Create Object dialog box, select container :
6) Then click Next , iIn the Value box, type System Management :
7) Click Next , display finish phase :
8) Click Finish , you can see created new container :
9) Close ADSI Edit mmc snap-in console .
10) Open Active Directory Users and Computers mmc snap-in console . Point to View and choose Advanced Features item :
11) Expand the System container, right-click System Management, and then click Properties:
12) System Properties is display , click Security page :
13) Click Add…,Display Select Users , Computers ,Service Accounts , or Groups box:
14) Click Object Types…item,just choose Computers in Object Types box :
15) Click OK and fill SC2012 ConfigMgr site server NetBIOS name :
16) Click Check Names to confirm , and click OK,return to System Properties box , and point just added computer name and choose all Allow items :
17) Click Advanced will display Advanced Security Settings for System box:
18) Double-click SC2012 ConfigMgr site server name , will display Permission Entry for System :
19) You need to choose This object and all descendant objects In Apply to , and confirm all Allow items was choose :
20) Click OK and back to Advanced Security Settings for System box :
21) Two consecutive hits OK will finish setting AD permission , close ADUC mmc snap-in console.
NOTE: Do the Same Thing for All the users you Created.
No comments:
Post a Comment