Windows Server 2012 Cluster - Cluster Service Getting Access Denied

We are having difficulties with changing the account that our cluster service runs under from the local system account to a domain account.

This is a new cluster in a lab environment.  Everything seems to run fine when running under the local system account.  When trying to switch the cluster service on both nodes (2 node cluster) to run as a domain account, the cluster services start momentarilly and then stop with an access denied error (see below). 

We have configured the account in local security policy on both nodes to be able to (and group policy does not appear to be overriding any of these settings):

  • Act as part of the operating system
  • Back up files and directories
  • Restore files and directories
  • Adjust memory quotas for a process
  • Log on as a service
  • Increase scheduling priority
  • Manage auditing and security log
  • Debug programs
  • Impersonate a client after authentication

The account is a member of the administrators group on both nodes.

Any ideas would be greatly appreciated.

We have 2 similarly configured Windows Server 2008 R2 2 node clusters already running successfully in our environment.

Thank you kindly!

Errors:

Log Name:      System
Source:        Service Control Manager
Date:          8/16/2013 8:28:41 AM
Event ID:      7024
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Description:
The Cluster Service service terminated with the following service-specific error:
Access is denied.

Log Name:      System
Source:        Service Control Manager
Date:          8/16/2013 8:28:41 AM
Event ID:      7031
Task Category: None
Level:         Error
Keywords:      Classic
User:          N/A
Description:
The Cluster Service service terminated unexpectedly.  It has done this 55 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.

August 16th, 2013 4:54pm

Hi,

Please see the article below:

Failover Cluster Step-by-Step Guide: Configuring Accounts in Active Directory
http://technet.microsoft.com/en-us/library/cc731002(v=ws.10).aspx

Specifically please see this sector:

Computer account of a clustered service or application
 
When the High Availability wizard is run (to create a new clustered service or application), in most cases a computer account for the clustered service or application is created in Active Directory. The cluster name account is granted the necessary permissions to control this account. The exception is a clustered Hyper-V virtual machine: no computer account is created for this.

If you prestage the computer account for a clustered service or application, you must configure it with the necessary permissions.

Free Windows Admin Tool Kit Click here and download it now
August 19th, 2013 5:42am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics