Status message 4909, 4912, 4913, or 4915, or error code 8202 after you install Systems Management Server 2003 (830022)
The information in this article applies to:
- Microsoft Systems Management Server 2003
SYMPTOMSAfter you install Microsoft Systems Management Server (SMS)
2003, the Site Component Manager component may log the following status
messages: MessageID=4909
Severity=Error
Facility=Application
SymbolicName=SRVMSG_SITECOMP_CANNOT_FIND_SMS_AD_CONTAINER
Language=English
SMS Systems Management Server could not locate the "System Management" container in Active
Directory. Nor could it create a default container. This will prevent Site Component Manager from
updating or adding any objects to Active Directory. Possible cause: This site's SMS Service
account or the site server's machine account might not have the correct rights to update active
directory.
Solution: Either give the Service Account rights to update the domain's System Container, or
manually create the "System Management" container in this domain's Active Directory system
container, and give the Service Account full rights to that container (and all children objects). MessageID=4912
Systems Management Server cannot update the already existing object "System Management" in Active Directory. MessageID=4913
Systems Management Server cannot create the object "System Management" in Active Directory. MessageID=4915
Systems Management Server cannot delete the object "System Management" in Active Directory. The following entries may appear in the Hman.log
file: System Management container exists.
Searching for SMS-Site-123 Site Object.
SMS-Site-123 doesn't exist, creating it.
SMS-Site-123 could not be created, error code = 8202 If you use the ExtADsch.exe tool, the following
entries may appear in the ExtADsch.log file: Failed to create class cn=MS-SMS-Management-Point. Error code = 8202.
Failed to create class cn=MS-SMS-Server-Locator-Point. Error code = 8202.
Failed to create class cn=MS-SMS-Site. Error code = 8202.
Failed to create class cn=MS-SMS-Roaming-Boundary-Range. Error code = 8202.
Failed to extend the Active Directory schema. CAUSEThis problem may occur when the SMS Site Component Manager
cannot locate or does not have the correct permission to manage the
System Management container in the Active Directory directory
service.RESOLUTIONSMS must have permission to create or to modify the
System Management container in Active Directory. To resolve
this problem, use one of the following methods:
- If your SMS 2003 site uses Advanced Security, grant the
site server computer account Full Control permissions to the Active Directory
System container and to all its child objects.
- If your SMS 2003 site uses Standard Security, grant the
site server SMS service account Full Control permissions to the Active
Directory System container and to all its child
objects.
To grant the appropriate permissions to the
System container, follow these steps:
- Click Start, point to
Administrative Tools, and then click Active Directory
Users and Computers.
- On the View menu, click Advanced
Features.
- Expand your domain tree, right-click the
System container, and then click
Properties.
- On the Security tab, click
Add.
- Click Object Types. If SMS 2003 is
configured to use Advanced Security, make sure that the
Computers check box is selected. If SMS 2003 is configured to
use Standard Security, make sure that the Groups and
Users check boxes are selected. Click
OK.
- If Advanced Security is turned on, type the name of the
site server's machine account, click Check Names, and then
click OK. If Standard Security is turned on, type the name of
the SMS service account, click Check Names, and then click
OK.
- In Group or user names, click the account
that you added in step 6.
- In Permissions for Enterprise Admins,
click to select the Full Control check box, and then click
OK.
Restart the SMS Site Component Manager service to start updating
Active Directory. You can monitor the Sitecomp.log file to see the status of
the update. You can use the ADSIEdit.exe utility to manually create
the System Management container in the Active Directory
System container. However, SMS must have permissions to manage
the objects in the container. If you manually create the container,
you must make sure that the site server machine account (if you use Advanced
Security) or the SMS Service account (if you use Standard Security) has Full
Control permissions to the System Management container and to
all its child objects. If you manually create the System
Management container, follow these steps to grant the correct
permissions:
- Click Start, point to
Administrative Tools, and then click Active Directory
Users and Computers.
- On the View menu, click Advanced
Features.
- Expand your domain tree, expand System,
right-click the System Management container, and then click
Delegate Control.
- Click Next, and then click
Add.
- Click Object Types. If SMS 2003 is
configured to use Advanced Security, make sure that the
Computers check box is selected. If SMS 2003 is configured to
use Standard Security, make sure that the Groups and
Users check boxes are selected. Click
OK.
- If Advanced Security is turned on, type the name of the
site server's machine account, click Check Names, and then
click OK. If Standard Security is turned on, type the name of
the SMS service account, click Check Names, and then click
OK.
- Click Next, click Create a custom task to
delegate, and then click Next.
- Click This folder, existing objects in this
folder, and creation of new objects in this folder, and then click
Next.
- Click to select the Full Control check
box, and then click Next.
- Make sure that the information is correct, and then click
Finish.
STATUSMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
in the "Applies to" section.
Modification Type: | Major | Last Reviewed: | 8/14/2006 |
---|
Keywords: | kbActiveDirectory kbSCMan kbinterop kbSecurity kbnofix kbBug KB830022 kbAudITPRO |
---|
|