Howdy, Stranger!

It looks like you're new here. Sign in or register to get started.

SSO agent with Domain Admin privs

StintovStintov Newbie ✭
edited October 21 in Mid Range Firewalls

Does anyone know if there is a way to install and configure SSO agent on DCs without giving the service login user Domain Admins privs please?



Category: Mid Range Firewalls
Reply
Tagged:

Answers

  • TKWITSTKWITS All-Knowing Sage ✭✭✭✭

    Make a dedicated account a member of Distributed COM Users, Performance Monitor Users, and Event Log Readers groups.

    Give the account logon as a service privileges on the servers.

    Give the account 'Execute Methods', 'Enable Account', 'Remote Enabled' and 'Read Security' privileges in WMI for the Root namespace and subnamespaces on the servers.

  • StintovStintov Newbie ✭

    Thanks for responding so quickly.

    I have since found this:

    Is this what your instructions where pertaining to please?

  • TKWITSTKWITS All-Knowing Sage ✭✭✭✭

    Yes that is correct. I just couldn't find the KB.

  • StintovStintov Newbie ✭

    Some feed back for everyone, the Domain Controllers are connected but the connection to Exchange server is disconnected now. Making the Server Account users a Domain Admin makes this work. I have given the SA the correct DCOM and WMI permissions the same as the DCs so not sure what going on.

Sign In or Register to comment.