Can't create IPAM GPO
when create gpo in child domain enterprise account, error.
ps c:\users\administrator.one> invoke-ipamgpoprovisioning -domain spb.one.lan -gpoprefixname ipam_ -delegatedgpouser adm inistrator@one.lan -ipamserverfqdn srv02.one.lan confirm invoke-ipamgpoprovisioning cmdlet creates , links 3 group policy objects in domain indicated domain parameter, provisioning ipam access settings on servers managed ipam. cmdlet modifies domain wide dns acl enable read access ipam. value of gpoprefixname must same 1 provided in ipam provisioning wizard when selecting option of group policy based provisioning. want perform action? [y] yes [n] no [s] suspend [?] (default "y"): y group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. removing authenticated users group may prevent processing of user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622 want continue ? [y] yes [n] no [s] suspend [?] (default "y"): y warning: group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. please add domain computers or authenticated users security group @ least read-only permissions. more information, please see https://support.microsoft.com/en-us/kb/3163622 group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. removing authenticated users group may prevent processing of user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622 want continue ? [y] yes [n] no [s] suspend [?] (default "y"): y warning: group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. please add domain computers or authenticated users security group @ least read-only permissions. more information, please see https://support.microsoft.com/en-us/kb/3163622 group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. removing authenticated users group may prevent processing of user group policies. more information, please see https://support.microsoft.com/en-us/kb/3163622 want continue ? [y] yes [n] no [s] suspend [?] (default "y"): y warning: group policy requires each computer account have permission read gpo data domain controller in order user group policy settings applied. please add domain computers or authenticated users security group @ least read-only permissions. more information, please see https://support.microsoft.com/en-us/kb/3163622 invoke-ipamgpoprovisioning : property 'exception' cannot found on object. verify property exists. @ line:1 char:1 + invoke-ipamgpoprovisioning -domain spb.one.lan -gpoprefixname ipam_ -delegatedgp ... + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ + categoryinfo : notspecified: (:) [invoke-ipamgpoprovisioning], propertynotfoundexception + fullyqualifiederrorid : propertynotfoundstrict,invoke-ipamgpoprovisioning
anyone know?
that's did. when powershell created gpo, kill him. did delegation gpo.
Windows Server > IPAM, DHCP, DNS
Comments
Post a Comment