Submitting forms on the support site are temporary unavailable for schedule maintenance. If you need immediate assistance please contact technical support. We apologize for the inconvenience.
Can an Enterprise Admin account be used as for the DC access account for multiple Domains in the same Forest?
Description
Trying to install the Forest Recovery Agent with an account from the root domain that has Enterprise Admin rights, as well as specify the same account for the Domain Access account in the FR Project, results in a logon failure. Using an account from the domain that each DC is a member of allows the agent to be installed and Verify Settings to work. Can an Enterprise Admin account be used instead of a Domain Admin account from each domain?
Resolution
WORKAROUND:
The following steps will allow you to use a single account that has Enterprise Admin rights for the the DC Access account in the FR Project:
Close the FR console
Edit the FRConsoleSettings.xml file found under the following path on the server where the FR Console is installed:<installDrive>\Program Files\Dell\Recovery Manager for Active Directory Forest Edition
Note: If you had previously upgraded from RMAD to RMADFE, the xml file may be under: <installDrive>\Program Files\Dell\Recovery Manager for Active Directory
Search for AllowExplicitCredentials and modify the line from: <AllowExplicitCredentials defaultValue="False">False</AllowExplicitCredentials>
To <AllowExplicitCredentials defaultValue="False">True</AllowExplicitCredentials>
Open the FR Project
You can now set the DC Access credentials for each DC using domain\username. Alternatively you can select a DC from each domain, click view next to Use Default Domain Access Credentials and enter the credentials there. You can then select to use the Default credentials for any DC from that domain
Click Verify Settings to test
Note: A reboot of the RMAD server may be required.
STATUS:
Enhancement request PT141395163 has been submitted to Development for consideration in a future release of Recovery Manager for Active Directory Forest Edition.
Defect ID
PT141395163
Additional Information
Provided the root domain is available to process authentication requests, and there are no network issues, the restore should work using the root account. This was tested in the lab to work, however there were no issues in any domain when the restore was tested.
It is suggested to test different restore scenarios, however if there is any doubt, use an account from each domain as the Access account for the DCs in those domains.
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Recommended Content
Product(s):
Recovery Manager for AD Forest Edition
Topic(s):
Configuration
Article History:
Created on: 3/28/2017 Last Update on: 5/7/2023
Thank you for your feedback for Topic Request
Your Request will be reviewed by our technical reviewer team and, if approved, will be added as a Topic in our Knowledgebase.
Welcome to Quest Support
You can find online support help for Quest *product* on an affiliate support site. Click continue to be directed to the correct support content and assistance for *product*.
Search All Articles
IE 8, 9, & 10 No longer supported
The Quest Software Portal no longer supports IE8, 9, & 10 and it is recommended to upgrade your browser to the latest version of Internet Explorer or Chrome.