rcarsey
asked on
Exchange 2013 CU5 installer fail
My environment is on 2013 CU4 (SP1) and I'm installing a new mailbox server with the CU5 installer.
I tried installing with a "Exchange Admin" account who has the following group memberships:
I get the following error when trying to run setup.exe /PrepareAD:
Obviously its a permissions problem. But what permission am I missing here??
I tried installing with a "Exchange Admin" account who has the following group memberships:
local admin
Enterprise Admins
Schema Admins
...and a bunch of other Exchange groups.I get the following error when trying to run setup.exe /PrepareAD:
[07/22/2014 22:00:25.0208] [2] Adding access control entries to the security descriptor for the object CN=Configuration,DC=monmouth,DC=edu.
[07/22/2014 22:00:25.0208] [2] The appropriate access control entry is already present on the object "CN=Configuration,DC=monmouth,DC=edu " for account "MONMOUTH0\Exchange Servers".
[07/22/2014 22:00:25.0224] [2] Taking ownership of CN=Deleted Objects,CN=Configuration,DC=monmouth ,DC=edu.
[07/22/2014 22:00:25.0286] [2] Active Directory operation failed on WLB-DCM0-01.monmouth.edu. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
[07/22/2014 22:00:25.0286] [2] The user has insufficient access rights.
[07/22/2014 22:00:25.0318] [2] Ending processing initialize-ExchangeConfigurationPerm issions
[07/22/2014 22:00:25.0318] [1] The following 1 error(s) occurred during task execution:
[07/22/2014 22:00:25.0318] [1] 0. ErrorRecord: Active Directory operation failed on WLB-DCM0-01.monmouth.edu. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
[07/22/2014 22:00:25.0318] [1] 0. ErrorRecord: Microsoft.Exchange.Data.Directory.AD OperationE xception: Active Directory operation failed on WLB-DCM0-01.monmouth.edu. This error is not retriable. Additional information: Access is denied.
Active directory response: 00000005: SecErr: DSID-031521D0, problem 4003 (INSUFF_ACCESS_RIGHTS), data 0
---> System.DirectoryServices.Protocols.D irectoryOp erationExc eption: The user has insufficient access rights.
at System.DirectoryServices.Protocols.L dapConnect ion.Constr uctRespons e(Int32 messageId, LdapOperation operation, ResultAll resultType, TimeSpan requestTimeOut, Boolean exceptionOnTimeOut)
at System.DirectoryServices.Protocols.L dapConnect ion.SendRe quest(Dire ctoryReque st request, TimeSpan requestTimeout)
at Microsoft.Exchange.Data.Directory.Po oledLdapCo nnection.S endRequest (Directory Request request, LdapOperation ldapOperation, Nullable`1 clientSideSearchTimeout, IActivityScope activityScope, String callerInfo)
at Microsoft.Exchange.Data.Directory.AD DataSessio n.ExecuteM odificatio nRequest(A DObject entry, DirectoryRequest request, ADObjectId originalId, Boolean emptyObjectSessionOnExcept ion, Boolean isSync)
--- End of inner exception stack trace ---
at Microsoft.Exchange.Data.Directory.AD DataSessio n.AnalyzeD irectoryEr ror(Pooled LdapConnec tion connection, DirectoryRequest request, DirectoryException de, Int32 totalRetries, Int32 retriesOnServer)
at Microsoft.Exchange.Data.Directory.AD DataSessio n.ExecuteM odificatio nRequest(A DObject entry, DirectoryRequest request, ADObjectId originalId, Boolean emptyObjectSessionOnExcept ion, Boolean isSync)
at Microsoft.Exchange.Data.Directory.AD DataSessio n.ExecuteM odificatio nRequest(A DObject entry, DirectoryRequest request, ADObjectId originalId, Boolean emptyObjectSessionOnExcept ion)
at Microsoft.Exchange.Data.Directory.AD DataSessio n.ExecuteM odificatio nRequest(A DObject entry, DirectoryRequest request, ADObjectId originalId)
at Microsoft.Exchange.Management.Tasks. Initialize ConfigPerm issions.In ternalProc essRecord( )
at Microsoft.Exchange.Configuration.Tas ks.Task.<P rocessReco rd>b__b()
at Microsoft.Exchange.Configuration.Tas ks.Task.In vokeRetrya bleFunc(St ring funcName, Action func, Boolean terminatePipelineIfFailed)
Obviously its a permissions problem. But what permission am I missing here??
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
No problem :) just here to help when and where I can.
ASKER
When I tried to use the domain\administrator account -- he lacked Schema Admin.. so he didn't work either.
Thanks Adam.