

Protecting Microsoft Exchange Server Environments › Create an Exchange Server Domain User Account
Create an Exchange Server Domain User Account
To avoid Exchange Server auto-configuration problems, make sure you are using a domain admin account. Operations fail if the local system account is used. If you cannot permit use of the Domain Admin account, use this procedure.
Note: The Network Traffic Redirection method you choose also requires permission in order to complete the redirection process. Exchange Server scenarios typically use DNS or Move IP Address redirection methods.
- Create a Domain User account. This account will be used as a service account for Arcserve RHA. Set the password to Never Expire. If your policy is to periodically change passwords, do so manually to avoid breaking scenarios when passwords expire.
- Assign the Arcserve RHA Engine service account to the Local Administrators Group on both the Master and Replica servers. If you do not grant the Engine service account Local Administrator privileges, you must grant the Engine service account Full Access to each directory containing data to be replicated on both the Master and Replica servers.
- Assign the newly created service account to the Arcserve RHA Engine service on the Master and Replica servers.
- Click Start, Settings, Control Panel, Administrative Tools, LocalSecurityPolicy.
- Open Local Policies.
- Select User Rights Management.
- Find Log on as a Service.
- Right-click Log on as a Service and go to Properties.
- Confirm the Engine service account is listed. To add it, click Add User or Group.
- In the Select Users or Groups field, make the From This Location is set to the Domain and add the Engine service account.
- Click OK to close the Add User or Group dialog.
- Click OK to close the Log On as a Service Property dialog.
- Repeat this procedure on all servers involved in the scenario.
- Grant the Engine Service Exchange Full Administrator privileges.
- Open Exchange System Manager and select the Exchange Domain.
- Choose Action, Delegate Control.
- In the Exchange Administration Delegation wizard, click Next.
- Click Add.
- Click Browse.
- Change the location to be the Domain.
- Enter the name of the Engine service account.
- Click OK to add the account.
- Click OK in the Delegate Control Box.
- Click Next to finish the Exchange Administration Delegation wizard.
- Assign the Engine service account the appropriate permissions to the Engine service account User Object.
- Open ADSI Edit.
- Connect to the domain.
- Open the OU containing the User Objects. By default, this is CN=Users.
- Find the Engine service account object. CN=Arcserve RHA Engine service account
- Right-click the object and select Properties.
- Click Security tab.
- Click Add.
- Add the Engine service account.
- Set Permissions to Full Control.
- Assign full permission to the A or Host record of the Master server record in DNS zone.
- Right-click the Master's A record and click Properties.
- Click Security.
- Choose Full Control rights for the Arcserve RHA service account.
Copyright © 2015 Arcserve.
All rights reserved.
 
|
|