To install MDM on a certification authority or an Active Directory® domain controller, follow these steps.
To assemble MDM together with a certification authority or domain controller
-
On the Active Directory domain controller, choose Start, choose All Programs, choose Administrative Tools, and then choose Active Directory Users and Computers.
-
In Active Directory Users and Computers, choose View, and then choose Advanced Features.
-
Expand the domain and then choose SCMDM2008 Infrastructure Groups.
-
Right-click SCMDM2008EnrolledDevices and then select Properties.
-
In the SCMDM2008EnrolledDevices Properties dialog box, on the Security tab, choose Advanced.
-
In the Advanced Security Settings for SCMDM2008EnrolledDevices dialog box, choose Add.
-
In the Select User, Computer, or Group dialog box, choose Object Types.
-
In the Object Types dialog box, select the Computer box, and then choose OK.
-
In the Select User, Computer, or Group dialog box, in the Enter the object name to select box, type the computer name, and then choose Check Names.
-
After Active Directory verifies the computer name, choose OK.
-
In the Permission Entry for SCMDM2008EnrolledDevices dialog box, on the Object tab, select the This object only box.
-
In the Permissions box, in the Allow column, select the Read Permissions box.
-
On the Properties tab, in the Apply onto list, select This object only.
-
In the Permissions box, in the Allow column, select the Read Members and Write Members boxes, and then choose OK.
-
Repeat steps 6 through 14 but in step 9, replace <computer name> with Network Service.
-
In the Advanced Security Settings for SCMDM2008EnrolledDevices dialog box, choose Apply, and then choose OK.
-
In the SCMDM2008EnrolledDevices Properties dialog box, choose OK.
-
In Active Directory Users and Computers, expand the domain, right-click SCMDM2008 Managed Devices, and then choose Delegate Control.
-
On the Welcome to the Delegation of Control Wizard page, choose Next.
-
On the Users or Groups page, choose Add.
-
In the Select Users, Computers, or Groups dialog box, choose Object Types.
-
In the Object Types dialog box, select the Computer box, and then choose OK.
-
In the Select User, Computer, or Group dialog box, in the Enter the object name to select box, type the server name of the enrollment server, and then choose Check Names.
-
After Active Directory verifies the computer name, choose OK.
-
On the Users or Groups page, choose Next.
-
On the Tasks to Delegate page, select Create a custom task to delegate, and then choose Next.
-
On the Active Directory Object Type page, select the Only the following objects in the folder box, select the Computer objects box, select the Create selected objects in this folder box, select the Delete selected objects in this folder box, and then choose Next.
-
On the Permissions page, select the General, Property-specific, and Creation/deletion of specific child objects boxes.
-
On the Permissions page, select the following boxes:
-
Read
-
Write
-
Create All Child Objects
-
Delete All Child Objects
-
Read All Properties
-
Write All Properties
-
Choose Next.
-
On the Completing the Delegation of Control Wizard page, choose Finish.
You must grant the Network Service and Local Service accounts Full Control to the Temp folders.
-
On the Start menu, choose Run, type explorer, and then choose OK.
-
In Windows Explorer, browse to the %SystemDrive%\Windows folder. Typically, the system drive is [C:].
-
Right-click Temp, and then choose Properties.
-
In the Temp Properties dialog box, on the Security tab, choose Add.
-
In the Select Users, Computers, or Groups dialog box, in the Enter the object name to select box, type network service, and then choose Check Names.
-
After Active Directory verifies the computer name, choose OK.
-
In the Permissions for NETWORK SERVICE box, in the Allow column, select the Full Control box, and then choose Add.
-
In the Select Users, Computers, or Groups dialog box, in the Enter the object name to select box, type local service, and then choose Check Names.
-
After Active Directory verifies the computer name, choose OK.
-
In the Permissions for LOCAL SERVICE box, in the Allow column, select the Full Control box, and then choose OK.
-
Repeat steps 1 through 10 to grant the Network Service and Local Service accounts Full Control permissions to the %SystemDrive%\Documents and Settings\<username>\Local Settings\Temp folder.