SMS: Permissions That Are Assigned to Domain Local Groups Do Not Work on Member Servers (305332)
The information in this article applies to:
- Microsoft Systems Management Server 2.0
This article was previously published under Q305332 SYMPTOMS
After you apply the post Systems Management Server 2.0 (SMS) Service Pack 3 (SP3) hotfix for Q266712 or SMS 2.0 Service Pack 4 (SP4) or later on your SMS 2.0 primary site, users of the SMS Administrator console may be unable to enumerate SMS objects such as collections. Prior to the application of the hotfix, users were able to inherit permissions that were assigned to domain local groups.
CAUSE
The fix that is included with Q266712 contains a change in how a user's groups are enumerated by the SMS provider. Because of this change, using domain local groups to assign permissions is no longer possible on member servers. Note that domain local groups still work when the SMS provider resides on a domain controller (DC).
WORKAROUND
To work around this issue, use any of the following methods individually:
- Use domain global groups to grant access and assign permissions to SMS object classes and instances.
- Use machine local groups to grant access and assign permissions to SMS object classes and instances.
- Use individual user accounts to grant access and assign permissions to SMS object classes and instances.
Modification Type: | Minor | Last Reviewed: | 6/14/2005 |
---|
Keywords: | kbenv kbprb kbsms200preSP4fix KB305332 |
---|
|