官术网_书友最值得收藏!

Granting permissions to the System container

The ConfigMgr server, after extending the Active Directory schema, is able to save core configuration data in the Active Directory database inside the System Management container. Thanks to these pieces of information, clients are able to find the assigned ConfigMgr server and establish connection with it. Any changes made to the management point role are also saved and stored in the Active Directory database.

There are two ways of the System Management container creation:

  • The container can be created manually and grant permissions to the ConfigMgr computer account
  • ConfigMgr creates it by itself thanks to the granted permissions
The presence of this container is not obligatory to go through the ConfigMgr installation process. The container, as well as permissions, might be created later after the server is installed.

To manually create the System Management container using the Active Directory Users and Computers console, follow these steps:

  1. Run the console, highlight the System container, right-click on it, and choose Properties:
System container in Active Directory Users and Computers console
  1. On the Security tab, click on Add... to add a computer account for the ConfigMgr server:
Properties of System container
  1. By default, the system does not show computer accounts when adding permissions. To see them, we need to check Computers in the Object Types... section and click on OK:
Adding computer accounts to searchable objects in Active Directory
  1. We fill in the computer name, and to ensure that we typed it correctly, we click on Check Names and then we click on OK:
Pointing ConfigMgr computer account
  1. The next step is to add permissions to the computer AD account. Highlight the computer account visible on the Security tab and click on Advanced:
Choosing a computer account for granting permissions
  1. Windows Advanced Security Settings for System appears. Highlight the ConfigMgr computer account and choose Edit:
Editing of permissions for the System container
  1. On the Permission Entry for System tab, check Full control and change the Applies to section to This object and all descendant objects:
Configuring permissions for a computer account
  1. After granting permissions, click on OK thrice. At this point, the environment is prepared for ConfigMgr to create the System Management container on its own and save the configuration data in there.
主站蜘蛛池模板: 黑山县| 淮南市| 五大连池市| 京山县| 乌鲁木齐市| 德兴市| 合作市| 锦州市| 黄骅市| 华容县| 沙坪坝区| 荆门市| 麻栗坡县| 南宁市| 句容市| 康平县| 外汇| 金塔县| 错那县| 揭阳市| 淅川县| 呼和浩特市| 定州市| 昆明市| 贺兰县| 临湘市| 财经| 攀枝花市| 英山县| 丽水市| 吉林省| 金溪县| 安阳市| 平乡县| 云和县| 张家港市| 资兴市| 白沙| 乾安县| 兰州市| 陇南市|