Per the KACE SMA Admin Guide, in order to Join a domain with the appliance, in order to use SSO (Single Sign On), you are to use an Admin account. However, in some environments, full admin rights may not be granted by the Enterprise Admin to an account a KACE Administrator has access to. KACE admin may be asked for the minimum rights needed to be granted to an account, that can be used to join the domain. The attached document provides a tested set of permissions that should allow an account the rights to create the objects the appliance needs to use SSO.
Active Directory permissions can be quite complex. Although these settings have been tested, there is no guarantee they will work in all environments, in all cases. The default, using a domain admin account, as per the Admin guide, may still be necessary.
Set permissions per the attached PDF.
© ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center