Results 1 to 2 of 2

Thread: AGPM Service Account - minimal privileges

  1. #1
    DavidWerner is offline Getting Started on GPanswers.com
    Join Date
    May 2010
    Posts
    1

    Default AGPM Service Account - minimal privileges

    According to the documentation for AGPM 4.0,

    the minimum privileges required for the AGPM Service Account include:
     Membership in the Group Policy Creator Owners group in each domain the AGPM Server manages.
     Membership in the Backup Operators group in each domain the AGPM Server manages.

    Assuming you have a Forest with multiple child domains, whatever or wherever your AGPM service account is, it cannot be added to the child domain Group Policy creator Owners groups in the other child domains. This group is a global group!

    What is the best way to use AGPM, a AGPM service account with multiple domains?

  2. #2
    chrisadam2 is offline Getting Started on GPanswers.com
    Join Date
    Sep 2010
    Posts
    2

    Default AGPM Service Account - minimal privileges

    Using an account with the Editor role, request the creation of a GPO, which you then approve using an account with the Approver role. With the Editor account, check the GPO out of the archive, edit the GPO, check the GPO into the archive, and request deployment.

    __________________________________________________ ___

    Want to get-on Google's first page and loads of traffic to our website? Hire a SEO Specialist from Ocean Groups seo specialist

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Search Engine Friendly URLs by vBSEO