Torpedo Posted July 3, 2009 Report post Posted July 3, 2009 Hi, I am trying to configure "Computer Client Agent properties" as per this thread "http://www.windows-noob.com/forums/index.php?showtopic=491". And I am currently stopped at this step because I am seeing this note here: "for Network Access Account we need to enter an account to be used by Configuration Manager 2007 client computers to communicate with network resources. We can use the SMSread account we created earlier (in Step 3 of this guide)." But I don't think I did run this before as per "Step 3" because I could not find the related steps in the page :Step 3. And also I am not seeing SMSRead/SMSAdmin users in list. Could someone let me know if I am missing anything here. I don't remember missing any steps so far. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 3, 2009 Report post Posted July 3, 2009 read this part http://www.windows-noob.com/forums/index.p...post&p=1442 that's where those accounts were configured Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 3, 2009 Report post Posted July 3, 2009 Yes Anyweb. But I could not find how to steps fro creating those users? Could you let me know the steps. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 3, 2009 Report post Posted July 3, 2009 ok in a production environment where you should have SCCM and AD on different servers do it like this make a global security group in Active directory Users and Computers and call it SMS Admins now, make two (or more) new Domain Users called SMSadmin and SMSread once done, log on to the SCCM server and startup Server Manager, Configuration, Local Users and Groups and select Groups double click on Administrators and add the SMS Admins Global Security Group as a member. (this gives the SMSadmin user local admin rights on the sccm server) in your lab do as follows: *if you have both SCCM and AD on the same server* create the two Domain Users in Active Directory Users and Computers called SMSadmin and SMSread create the SMS Admins Global Security Group and add the SMS Admins group as a member of Domain Admins. Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 3, 2009 Report post Posted July 3, 2009 hmm.. Ok. But I don't know which wizard that I should use to create SMSadmin and SMSread. Do I just need to create them as regular Windows users and configure them as AD Users? Yes. I am installing everything on a single server. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 3, 2009 Report post Posted July 3, 2009 use Active Directory Users and Computers right click on Users, choose New etc Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 3, 2009 Report post Posted July 3, 2009 Thank you very much for confirming this. I tried the same before and thought it was not the right one because it is asking Firstname, Lastname and loginname@domainname etc. Now I ran the same wizard and created "SMSadmin & SMSread" users. Couple of questions here. 1. I completed all the remaining Part1 & 2 steps and reached to Part3: "Next we will configure the Computer Client Agent properties" step. Now I am not sure whether I can continue to configure "the Computer Client Agent Properties in Part3". Could you please let me know if I need to do anything before running this? 2. And a per your previous notes in this thread, you are saying that I need to create "SMSAdmins Global Security Group also and add the SMSAdmins group as a member of Domain Admins.". This group is actually available by default. How do I add this group as a member of Domain Admins. I am not finding this step in any of your guides. Sorry for asking many questions. I am basically lost now because I am at Part 3 now. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 4, 2009 Report post Posted July 4, 2009 bring up the properties of the Security group called SMS Admins, and click on the Member Of tab, Click Add and type Domain Admins thats it Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 5, 2009 Report post Posted July 5, 2009 Hi Anyweb, I tried the above step but I am seeing this message as seen in the screen shot. Could you please look at it. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 5, 2009 Report post Posted July 5, 2009 Domain Admins is present (it has to be) so you must be doing something wrong, try leaving it blank instead and click on check names and you need to do this as a user wit Domain Administrative permissions Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 5, 2009 Report post Posted July 5, 2009 Hi, I tried with empty value, but the "Check Names" button is not enabled for clicking ? I am seeing Domain Admins in the main list of "Active Directory Users and Comptuers window". Is it actually "Members" or "Members Of" tab on SMS Admins properties window? Checking Names with empty value on "Members Of" tab can not be done because the button is disabled. Also, I did not see this step anywhere in your guide. Please let me know if I miss anything? Actually this is the step as per your guide. Thanks for looking into this. Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 5, 2009 Report post Posted July 5, 2009 what type of user are you logged in as when attempting to do this ? Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 5, 2009 Report post Posted July 5, 2009 I logged in as XVMZAG\Administrator. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 6, 2009 Report post Posted July 6, 2009 after clicking on Member of, choose Object Types and make sure that Groups or Built-in security principals is selected, in your screenshot you've only selected Groups.... Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 6, 2009 Report post Posted July 6, 2009 Hi Anyweb, Please find here attached another screen shot showing that there is no other Object types other than Groups. Thanks Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 6, 2009 Report post Posted July 6, 2009 you must be doing Something wrong, and it must be related to how you are logging on to this server when i log on to my server i need to do so like this domain\user are you specifying domain\user ? Quote Share this post Link to post Share on other sites More sharing options...
anyweb Posted July 6, 2009 Report post Posted July 6, 2009 i dont get it, can you give me remote access to this machine ? i assume its a Domain Controller ????? Quote Share this post Link to post Share on other sites More sharing options...
Torpedo Posted July 6, 2009 Report post Posted July 6, 2009 Oh! I have sent PM and waiting. I did not realize that you posted a reply here. Yes, it is a Domain Controller. Thanks Quote Share this post Link to post Share on other sites More sharing options...