Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Help Installing FIM Password Reset Client

Posted on 2013-06-20
5
Medium Priority
?
1,350 Views
Last Modified: 2013-06-30
We are in the process of implementing FIM, and we need to install the password reset client on several machines. I have tried to use Config Mgr to push it out, but it comes back with the following error message:

An error occurred while preparing to run the program for advertisement "2172008B" ("21700047" - "FIM Client X86"). The operating system reported error 2147942405: Access is denied.

Additional program properties:
Command line: msiexec.exe /q /i "\\servername\updates\fim\PswdClient\x86\Add-ins and extensions.msi" ADDLOCAL="PasswordClient" RMS_LOCATION=server REGISTRATION_PORTAL_URL=https://server:port number
Working directory: \\servername\updates\FIM\PswdClient\x86
Drive letter (? = any):

Possible cause: This message most commonly occurs when the program's command-line executable file could not be found, when a required drive letter connection to a distribution point could not be established, or when the program is configured to use the SMS Software Installation Account but the account is not specified, could not be found, or does not have the appropriate permissions.
Solution: Check each of the items listed above. This program will be retried
.

The software will install when i run the command not using the /quiet command on one test machine. So, i know the command is correct. I also checked the folder permissions and they seem ok as well.

Any suggestions or assistance would be appreciated as we do not want to go around to 500+ machines to install the software manually.

Thanks!
0
Comment
Question by:jwcchelpdesk
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 20

Expert Comment

by:strivoli
ID: 39264997
I understand that you would like to use ConfigMgr because you have it and are used with it, but, since there's a problem either with it (at least in this specific situation) or with the FIM client, why not trying using the AD/GPO simple approach?

BTW, please let us know the ConfigMgr version. Thank you.
0
 

Author Comment

by:jwcchelpdesk
ID: 39271315
We are using Config Mgr 2007, sorry about that.

As for using a GPO, i haven't looked at that much since we are higher ed and most of the machines this would be installed on, are frozen machines using Depp Freeze. We would have to un-freeze them first, then install, then freeze the machine again. I wasn't for sure if the GPO option allows us to install at a certain time\date because we would have to probably do the install overnight.
0
 
LVL 20

Expert Comment

by:strivoli
ID: 39274016
GPO is very "basic" compared to your actual solution but I think a test is worth it since it will request 20-30' to get the result. No, GPO will not allow to unfreeze/install/freeze. GPO will install the software at boot time if the software isn't already installed. The time taken to install depends on the software itself. If it takes 10-20" it might be acceptable.
The GPO way is very simple:
a. Create a test OU,
b. Put a client in the OU,
c. Create (and link it to the test OU) a GPO that installs the software,
d. Reboot the client in order to install the software (you might need to reboot more than once at least the very first time the policy is applied),
e. Check client's Windows Application/System logs if the software doesn't install.

Let me know.
0
 

Accepted Solution

by:
jwcchelpdesk earned 0 total points
ID: 39276407
I figured out the problem to why SCCM was giving me an access denied error message. It was using an account, and the password for that account was not updated to the current one. So, once we updated the password, i was able to push out the FIM password reset client successfully.

Plus now we can set the install to be pushed out at a particular time of day, and we can check the logs to see if it was successful. Those are two things about software installs using GPO does not have, and we needed to have that.
0
 

Author Closing Comment

by:jwcchelpdesk
ID: 39287928
Did some more research on why i was getting the error and realized the account that config mgr was using, the password was out of date, and needed to be updated. Once i updated the password, no more error message and client was pushed out successfully.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you're a modern-day technology professional, you may be wondering if certifications are really necessary. They are. Here's why.
Ready to get certified? Check out some courses that help you prepare for third-party exams.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

704 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question