AGMP - How do I create an account correctly?
Андрей Михалевский
3,331
Reputation points
Hi, I am studying in the AGMP lab environment. I don't understand how to make a service account.
- In the AGPM Service Account dialog box, select a service account under which the AGPM Service runs and then select Next. This account must be a member of either the Domain Admins group or, for a least-privilege configuration, the following groups in each domain managed by the AGPM Server:
- Group Policy Creator Owners
- Backup Operators
- The AGPM archive folder, for which this permission is automatically granted during the installation of AGPM Server if it's installed on a local drive.
- The local system temp folder, typically %windir%\temp.
After deploy GPO, i gor error:
Deploy GPO: New Group Policy Object8...Failed
[GPMC Error] Could not take ownership of the production GPO. Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))
I found a solution here: https://archive.z-nerd.com/blog/2016/12/24-gpos-screw-it-well-do-it-live-iv/
But I don't understand what the script does.
- Why doesn't it work according to the documentation ?
- What's missing?
- How do I fix it? Can you show the correction through a graphic editor ? I don't understand what I am doing using Powershell in the script from the link above.
Sign in to answer