官术网_书友最值得收藏!

Granting permissions to the System container

The ConfigMgr server, after extending the Active Directory schema, is able to save core configuration data in the Active Directory database inside the System Management container. Thanks to these pieces of information, clients are able to find the assigned ConfigMgr server and establish connection with it. Any changes made to the management point role are also saved and stored in the Active Directory database.

There are two ways of the System Management container creation:

  • The container can be created manually and grant permissions to the ConfigMgr computer account
  • ConfigMgr creates it by itself thanks to the granted permissions
The presence of this container is not obligatory to go through the ConfigMgr installation process. The container, as well as permissions, might be created later after the server is installed.

To manually create the System Management container using the Active Directory Users and Computers console, follow these steps:

  1. Run the console, highlight the System container, right-click on it, and choose Properties:
System container in Active Directory Users and Computers console
  1. On the Security tab, click on Add... to add a computer account for the ConfigMgr server:
Properties of System container
  1. By default, the system does not show computer accounts when adding permissions. To see them, we need to check Computers in the Object Types... section and click on OK:
Adding computer accounts to searchable objects in Active Directory
  1. We fill in the computer name, and to ensure that we typed it correctly, we click on Check Names and then we click on OK:
Pointing ConfigMgr computer account
  1. The next step is to add permissions to the computer AD account. Highlight the computer account visible on the Security tab and click on Advanced:
Choosing a computer account for granting permissions
  1. Windows Advanced Security Settings for System appears. Highlight the ConfigMgr computer account and choose Edit:
Editing of permissions for the System container
  1. On the Permission Entry for System tab, check Full control and change the Applies to section to This object and all descendant objects:
Configuring permissions for a computer account
  1. After granting permissions, click on OK thrice. At this point, the environment is prepared for ConfigMgr to create the System Management container on its own and save the configuration data in there.
主站蜘蛛池模板: 红安县| 繁昌县| 霍邱县| 灵川县| 乐东| 丹东市| 翁牛特旗| 衡阳县| 全椒县| 通许县| 陵川县| 大兴区| 奉化市| 抚顺县| 缙云县| 玉山县| 会泽县| 田东县| 株洲县| 营口市| 正阳县| 永和县| 永平县| 洛南县| 广昌县| 湟中县| 富阳市| 九寨沟县| 桃江县| 卢龙县| 遂平县| 北海市| 汶川县| 南木林县| 辰溪县| 衡山县| 随州市| 嘉禾县| 伽师县| 长春市| 鄱阳县|