Exchange Server 2010 cannot be installed on a domain controller if the forest is in split permission mode
Topic Last Modified: 2010-06-14
The Microsoft Exchange Best Practices Analyzer tool determines whether the /ActiveDirectorySplitPermissions parameter is set to TRUE on the computer on which you want to install Microsoft Exchange Server 2010.
If the /ActiveDirectorySplitPermissions parameter is set to TRUE on a domain controller, and if the current forest is in split permission mode, Exchange Server 2010 is not installed. When this occurs, you receive the following error message:
In Active Directory split permission mode, Exchange Servers should not be installed on a domain controller. |
The /ActiveDirectorySplitPermissions parameter is configured on the Exchange Organization Name page in the Setup program during a new installation of Exchange Server 2010. If setup is run on a domain controller for a new installation, and the ActiveDirectorySplitPermissions check box is selected, the prerequisite check for org prep will not fail. But, the prerequisite checks for other server roles, such as CAS, MBX, HUB, UM will fail.
If the /ActiveDirectorySplitPermissions parameter is set to TRUE, do not create non-delegating role assignments to the following RoleTypes roles:
-
MailRecipientCreation
-
ActiveDirectoryPermissions
-
SecurityGroupCreationAndMembership
Remove any non-delegating role assignments from these RoleTypes roles, if the assignments exist.
If /ActiveDirectorySplitPermissions parameter is set to FALSE, the non-delegating role assignments that are listed in this section will not be recovered. You must create the assignments manually.
If the current forest is in AD split permission mode, an attempt to install any server roles (such as CAS, MBX, HUB, or UM) on a domain controller will fail the Prereq check.
