This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Problem Migration Clients to Enterprise Console

Hi there

We have installed a fresh installation of the "Sophos Enterprise Console 4.5" on a server at customer site, this server is in "Domain B". We have an old , soon depricated version, em library installation on a old win2k server in "Domain B". Because the migration of the systems and users of "Domain A" to "Domain B" is very slow in progress i wan't that already all computers in the old domain connect to the new Sophos Enterprise Console. I see the system on the new console greyed out. I have now added a new Group for them and now woul'd add them to this console. But when i wan't to add the login of the domain admin of the old domain he always say that the credentials are invalid. I have tried to add both domains to trust each other but it doesn't help.

have anyone an idea?

greeting

:9413


This thread was automatically locked due to age.
Parents
  • HI,

    So you're trying to protect machines in another domain (DomainA) but the account you enter in the protect wizard in SEC 4.5 (Domain B) isn't working?

    If you enter:

    DomainA\Administrator

    as the protection account you need to ensure that that account can log on to the SEC management server (where the Sophos Management Service is running).  If the management service is installed on a DC it could be that you need to update the policy to ensure that DomainA\Administrator can log on to the DC of DomainB.

    As a test, on the SEC 4.5 management server I would run:

    runas /user:domaina\administrator cmd.exe

    This should prompt you for the password.  If it fails the error should help.

    If it succeeds then that account should be able to protect the machines in the other domain, if not, I would double check that on one of the machines in the other domain you can't deploy to that in the local administrators group the correct domain groups are in there and they can be resolved, i.e. not just a bunch of SID values.

    I hope this helps.

    Regards,

    Jak

    :9423
Reply
  • HI,

    So you're trying to protect machines in another domain (DomainA) but the account you enter in the protect wizard in SEC 4.5 (Domain B) isn't working?

    If you enter:

    DomainA\Administrator

    as the protection account you need to ensure that that account can log on to the SEC management server (where the Sophos Management Service is running).  If the management service is installed on a DC it could be that you need to update the policy to ensure that DomainA\Administrator can log on to the DC of DomainB.

    As a test, on the SEC 4.5 management server I would run:

    runas /user:domaina\administrator cmd.exe

    This should prompt you for the password.  If it fails the error should help.

    If it succeeds then that account should be able to protect the machines in the other domain, if not, I would double check that on one of the machines in the other domain you can't deploy to that in the local administrators group the correct domain groups are in there and they can be resolved, i.e. not just a bunch of SID values.

    I hope this helps.

    Regards,

    Jak

    :9423
Children
No Data