Twitter: langonej

Additional Info

User login

Reply to comment

Minimum Active Directory User Account Permissions for VMware View Composer's QuickPrep (with Instructions for 2000/2003/2008)

The user account used by VMware View Composer to join computers to the domain needs to have the ability to add and move Computer accounts in and out of the Computers container (as new computer accounts joined to the domain, unless pre-staged, end up in the Computers container first, and are then moved to the appropriate OU defined in the QuickPrep settings:

For a 2000 or 2003 Active Directory Domain:

  • Right-click Computers in Active Directory Users and Computers (ADUC) and click Properties.
  • Click Security and then click the Advanced tab.
  • Under Permissions add the appropriate user account.
  • Click the user account object and under the Permissions list add Create Computer Objects and Delete Computer Objects select Allow.
  • Click Apply.
  • In the main Permissions list, set Write All property to Allow for the appropriate User account.
  • For a 2008 Domain:

  • Right-click Computer in the Active Directory Administrative Center and click Properties.
  • Click Security and then click the Advanced tab.
  • Under Permissions add the appropriate user account.
  • Click the user account object and select Edit. Under the Permissions list add Create Computer Objects and Delete Computer Objects select Allow.
  • Click Apply.
  • In the main Permissions list, set Write permission to Allow for the appropriate User account.
  • However, if you want to prevent Computer accounts from joining the Computers container first, and then being moved, you can use redircmp if your domain functional level is at 2003 or later.
    Please ensure that the PDC Emulator FSMO role is available during this command execution.
    An example:
    C:\windows\system32>redircmp ou=HoldingTank,DC=thinkvirt,dc=com

    More on why Computer accounts join the Computers container by default can be found here.

Reply

Accolades






Video

"Green IT" - Leveraging VMware to provide a green datacenter.

Preview of the upcoming VMware View iPad App with PCoIP support.

Ubertechnik 350Z at VIR.

Latest from Disqus

Consulting Gigs

CURRENT GIGS for 1099 VCP's

  • * VMware Site Recovery Manager Consultant.

    Status: FILLED.


    Duration: 3 Weeks

    Location: Reston, VA

    Clearance: None

  • * Senior Solaris Consultant.

    Duration: 3+ Weeks

    Location: Reston, VA

    Clearance: TS SCI

Note: All 1099 consultants must be a current VCP.