Forums on Intune, SCCM, and Windows 11

Welcome to the forums. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your topics and posts, as well as connect with other members through your own private inbox!

SOLVED SCCM Configuration Manager 1702 Installation issue

k2017

Member
Messages
12
Reaction score
0
Points
1
Hi all,

New to this site and wondered if you could shed some light on a problem I don’t seem to be able to resolve.

Background

I have a hp microserver running vmware Esxi 6 and I have a Windows 2012 R2 server VM running as a domain controller, DNS, DHCP.

I have another microserver running esxi 6 and it is running a VM with windows 2012 R2 which has SQL 2012 on it and I am trying to now install SCCM 1702 from fresh (no upgrade). This is joined to the same domain as the DC. I have followed a guide for configuring all the prereqs for SCCM so all went through ok.

Summary of Problem

When going through the installation of 1702, all is ok until I get to prerequisite checks, I get a warning advising “Warning; The site server might be unable to publish to Active Directory. The computer account for the site server must have Full Control permissions to the System Management container in its Active Directory domain. You can ignore this warning if you have manually verified these permissions. For more information about your options to configure required permissions, see http://go.microsoft.com/fwlink/p/?LinkId=233190.”

Looking in the ConfigMgrPrereq log file, I see the below:

INFO:CheckMachineAccountHasADAccess <computername>
ERROR: Site server does not have create child permission on AD ‘System Management’
WARN: Site server does not have delete child permission on AD ‘System Management’
<computername>; Verify site server permissions to publish to Active Directory.; Warning; The site server might be unable to publish to Active Directory. The computer account for the site server must have Full Control permissions to the System Management container in its Active Directory domain. You can ignore this warning if you have manually verified these permissions. For more information about your options to configure required permissions, see http://go.microsoft.com/fwlink/p/?LinkId=233190.

I have checked ADSIEdit and ADUC and the System Management container has the SCCM computer name added with full control to the System Management object and everything under it but I’m still getting this error..

Would anyone know how to resolve it? I’m hesitant to go ahead and install it until I get rid of these.

I've moved my DC VM onto the same micro server as my SCCM VM for testing purposes and get the same warning messages so believe this rules out anything on vmware side of things. Everything I can find online just says ensure permissions are set on the System Management container which they are but i’m still getting the error…

Many thanks for any help on this.

K2017
 
ERROR: Site server does not have create child permission on AD ‘System Management’
WARN: Site server does not have delete child permission on AD ‘System Management’

You could remove the site system account and add it again and verify if this warning comes up. Use ADUC > advanced features to delegate the permissions on system management container.
 
Hi,

Many thanks for your reply. I have tried:-

Removing the System Management and re-creating
Delegate to the computer account with full control, no joy
Adding computer account manually via security tab and ensuring it is for all dependents - no joy...

Could yo confirm what permissions should be on the System Management container so I can verify mine in case mine has any additional permissions that maybe causing a conflict?

Thanks!

K2017
 
Hi,

Yes, i went through this tutorial last night and even deleted the system management container and re-did, no change still the same error...

Any further ideas?

Should I be checking anything else to confirm something else is working ok?

Thanks

k2017
 
ok thanks, will do - I just didn't want to in case that would cause more problem further down the line...

Thanks!

K2017
 
Install it and let's see how if we encounter any issues. For now I will mark this thread as Solved and keep it open for discussions.
 
Hi,
Thanks, I've installed it, will see what happens when I get it setup and create a image to deploy etc.

Many thanks for your help!

k2017
 
Back
Top