|

楼主 |
发表于 2019-8-30 06:11:25
|
显示全部楼层
终于找到问题所在了,需要DC和安装任务的服务器配合配置,大致总结如下:
前提:
1. 可以安装到DC或者备份DC上,安装Essentials Experience需要拥有FSMO;
2. 也可以安装到非DC(非备份DC)的域成员上。
配置向导(以安装到域成员为例):
1. 以域成员身份登录到安装Essentials的Server上;
2. 运行配置向导,第一次运行会失败,并在DC服务器的AD中自动创建一个Managed Service Account:ServerAdmin;
3. 再次运行向导前需要在DC设备将上述账户添加进默认组策略:
Group Policy Management --> Forest:xxx.com --> Domains --> xxx.com --> Domain Controllers --> 右键"Default Domain Controllers Policy" --> Edit --> Group Policy Management Editor --> Computer Configuration --> Policies --> Windows Settings --> Security Settings --> Local Policies --> User Rights Assignment --> Log on as a service Properties --> Add User or Group --> 手动添加Managed Service Account "xxx\ServerAdmin$";
4. 将安装域账户添加进Essentials服务器的Administrators策略组,并且删除孤立账户(orphaned accounts,相同窗体下类似于S-1-5-21-xxxx...的账户):
Server Manager --> Tools --> Computer Management --> System Tools --> Local Users and Groups --> Groups --> 双击策略组 "Administrators"修改;
注意:
1. DC和域成员Server都需要遵循命名规范("Naming Conventions in Active Directory for computers, domains, sites, and OUs"),计算机名不能超过15个字符,否则DNS解析会报错无法解析网络路径,从而安装失败;
2. 可使用Event Viewer排错:
Applications and Servers Log --> Microsoft --> Windows --> ...Essentials...
|
|