AGMP - How do I create an account correctly?

Андрей Михалевский 3,331 Reputation points
2024-07-11T12:39:57.86+00:00

Hi, I am studying in the AGMP lab environment. I don't understand how to make a service account.

https://video2.skills-academy.com/en-us/microsoft-desktop-optimization-pack/agpm/step-by-step-guide-for-microsoft-advanced-group-policy-management-40#steps-for-installing-and-configuring-agpm

  1. In the AGPM Service Account dialog box, select a service account under which the AGPM Service runs and then select Next. This account must be a member of either the Domain Admins group or, for a least-privilege configuration, the following groups in each domain managed by the AGPM Server:
    • Group Policy Creator Owners
    • Backup Operators
    This account must be member of the local Administrators Group on the AGPM Server Computer. This is required to successfully handle Additionally, this account requires Full Control permission for the following folders:
    • The AGPM archive folder, for which this permission is automatically granted during the installation of AGPM Server if it's installed on a local drive.
    • The local system temp folder, typically %windir%\temp.
  • A1
  • A2

After deploy GPO, i gor error:

A3

Deploy GPO: New Group Policy Object8...Failed

[GPMC Error] Could not take ownership of the production GPO. Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))

I found a solution here: https://archive.z-nerd.com/blog/2016/12/24-gpos-screw-it-well-do-it-live-iv/

But I don't understand what the script does.

  1. Why doesn't it work according to the documentation ?
  2. What's missing?
  3. How do I fix it? Can you show the correction through a graphic editor ? I don't understand what I am doing using Powershell in the script from the link above.
Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
13,272 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.