DP Required rights for installation.
Hi I have installed a primary site and will have arround 150 DPs in my production environment, currently working in a test lab with around 100 clients, and 6 DPs, Everything working well with software distributions and software updates working as expected. I have however run into a bit of a snag. the servers that will be used as DPs are also file and print servers, they are configured with a c:\ O/S partition and a d:\ Data partition, the c:\ is quite small and not suitable for software distribution files. so D:\ it is. (currently the c:\ was being used didnt realise as I had configured the d:\ as the default software updates drive. Anyway the problem is that our d:\ NTFS rights are quite locked down, and even though the site servers computer account is a member of the local administrators group, local admins do not have access to the root of d:\ I have tried to pre-polpulate the d:\SMSSIG$ and d:\SMSPKGD$ folders and added the site servers accounts to each of the folders and setting the share permissions to everone full control, I did this as I had the idea that I could you group policy preferences to prestage the folders permissions and shares for the sccm DP installation, but I have still had no luck, If I add the sms site servers account to the root of D:\ the folders will be created, but I will not be able to make this change to production servers, Any ideas would be apreciated.!! ;o) Cheers Tony
July 12th, 2010 1:51pm

You need to make sure the the site server computer account is a local admin on the DP box.Kent Agerlund | http://scug.dk/members/Agerlund/default.aspx | The Danish community for System Center products
Free Windows Admin Tool Kit Click here and download it now
July 12th, 2010 1:54pm

Thanks for your reply kent, and yes as above the site servers computer account is a member of the local administrators group.
July 12th, 2010 2:18pm

If I add the sms site servers account to the root of D:\ the folders will be created, but I will not be able to make this change to production servers Why not? Computer accounts are super-secure accounts. It's ultimately a user just like any other but much more secure. Have you tried using a server share DP?Jason | http://myitforum.com/cs2/blogs/jsandys | http://blogs.catapultsystems.com/jsandys/default.aspx | Twitter @JasonSandys
Free Windows Admin Tool Kit Click here and download it now
July 12th, 2010 3:47pm

Because of the data that is also stored on the file and print server the rights that would then be available to any user that logged onto the SMS site server would have rights to take ownership of the other folders located on the d:\ I have also tried using the server share option for DP, but run into the same issue unless I give permissions to the root of d:\ even though I have supplied the local administrators full contoll of the folder (NTFS) and provided everyone full control permissions on the share. Just FYI, my site servers are 2008 servers, DPs 2003. Cheers and thanks for all posts so far, Jason and Kent. Tony
July 12th, 2010 8:25pm

In the end I had to change the permissions on the branch servers, to allow create new folders to the root of the d:\ to the computer accounts.
Free Windows Admin Tool Kit Click here and download it now
September 9th, 2010 12:13am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics