Can't create IPAM GPO


when create gpo in child domain enterprise account, error.

ps c:\users\administrator.one> invoke-ipamgpoprovisioning -domain spb.one.lan -gpoprefixname ipam_ -delegatedgpouser adm  inistrator@one.lan -ipamserverfqdn srv02.one.lan    confirm  invoke-ipamgpoprovisioning cmdlet creates , links 3 group policy objects in domain indicated domain  parameter, provisioning ipam access settings on servers managed ipam. cmdlet modifies  domain wide dns acl enable read access ipam. value of gpoprefixname must same 1 provided in  ipam provisioning wizard when selecting option of group policy based provisioning. want perform  action?  [y] yes  [n] no  [s] suspend  [?] (default "y"): y    group policy requires each computer account have permission read gpo data domain controller in order  user group policy settings applied. removing authenticated users group may prevent processing of   user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622  want continue ?  [y] yes  [n] no  [s] suspend  [?] (default "y"): y  warning: group policy requires each computer account have permission read gpo data domain controller in  order user group policy settings applied. please add domain computers or authenticated  users security group @ least read-only permissions. more information, please see  https://support.microsoft.com/en-us/kb/3163622    group policy requires each computer account have permission read gpo data domain controller in order  user group policy settings applied. removing authenticated users group may prevent processing of   user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622  want continue ?  [y] yes  [n] no  [s] suspend  [?] (default "y"): y  warning: group policy requires each computer account have permission read gpo data domain controller in  order user group policy settings applied. please add domain computers or authenticated  users security group @ least read-only permissions. more information, please see  https://support.microsoft.com/en-us/kb/3163622    group policy requires each computer account have permission read gpo data domain controller in order  user group policy settings applied. removing authenticated users group may prevent processing of   user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622  want continue ?  [y] yes  [n] no  [s] suspend  [?] (default "y"): y  warning: group policy requires each computer account have permission read gpo data domain controller in  order user group policy settings applied. please add domain computers or authenticated  users security group @ least read-only permissions. more information, please see  https://support.microsoft.com/en-us/kb/3163622  invoke-ipamgpoprovisioning : property 'exception' cannot found on object. verify property exists.  @ line:1 char:1  + invoke-ipamgpoprovisioning -domain spb.one.lan -gpoprefixname ipam_ -delegatedgp ...  + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~      + categoryinfo          : notspecified: (:) [invoke-ipamgpoprovisioning], propertynotfoundexception      + fullyqualifiederrorid : propertynotfoundstrict,invoke-ipamgpoprovisioning

anyone know?

that's did. when powershell created gpo, kill him. did delegation gpo. 


Windows Server  >  IPAM, DHCP, DNS



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

Failed to setup initiator portal. Error status is given in the dump data.

Failed to delete the test record dcdiag-test-record in zone test.com