官术网_书友最值得收藏!

Granting permissions to the System container

The ConfigMgr server, after extending the Active Directory schema, is able to save core configuration data in the Active Directory database inside the System Management container. Thanks to these pieces of information, clients are able to find the assigned ConfigMgr server and establish connection with it. Any changes made to the management point role are also saved and stored in the Active Directory database.

There are two ways of the System Management container creation:

  • The container can be created manually and grant permissions to the ConfigMgr computer account
  • ConfigMgr creates it by itself thanks to the granted permissions
The presence of this container is not obligatory to go through the ConfigMgr installation process. The container, as well as permissions, might be created later after the server is installed.

To manually create the System Management container using the Active Directory Users and Computers console, follow these steps:

  1. Run the console, highlight the System container, right-click on it, and choose Properties:
System container in Active Directory Users and Computers console
  1. On the Security tab, click on Add... to add a computer account for the ConfigMgr server:
Properties of System container
  1. By default, the system does not show computer accounts when adding permissions. To see them, we need to check Computers in the Object Types... section and click on OK:
Adding computer accounts to searchable objects in Active Directory
  1. We fill in the computer name, and to ensure that we typed it correctly, we click on Check Names and then we click on OK:
Pointing ConfigMgr computer account
  1. The next step is to add permissions to the computer AD account. Highlight the computer account visible on the Security tab and click on Advanced:
Choosing a computer account for granting permissions
  1. Windows Advanced Security Settings for System appears. Highlight the ConfigMgr computer account and choose Edit:
Editing of permissions for the System container
  1. On the Permission Entry for System tab, check Full control and change the Applies to section to This object and all descendant objects:
Configuring permissions for a computer account
  1. After granting permissions, click on OK thrice. At this point, the environment is prepared for ConfigMgr to create the System Management container on its own and save the configuration data in there.
主站蜘蛛池模板: 宁阳县| 高邮市| 黄大仙区| 定边县| 昂仁县| 上犹县| 莆田市| 伊宁市| 昌吉市| 乐业县| 敦化市| 连南| 行唐县| 得荣县| 徐州市| 潞城市| 陆丰市| 习水县| 浪卡子县| 岐山县| 柯坪县| 钦州市| 东乌珠穆沁旗| 祁门县| 佛教| 洛浦县| 琼结县| 常宁市| 绥芬河市| 望奎县| 蚌埠市| 远安县| 轮台县| 青龙| 冷水江市| 澎湖县| 富阳市| 潢川县| 武强县| 西宁市| 广灵县|