"Roger Abell [MVP]" <> wrote in message
news:#...
Okay.. Roger.... most of this thread is just a ping-pong game now so I'm not
really going to quote much of it at all, as that's not really going to
accomplish anything.
Either you want help troubleshooting this or not -- but arguing about what
you will or won't do, or what will or won't work -- without even trying --
doesn't really encourage me to keep offering help at all.
I'm intimately familiar with, and lived through, almost =every= encountered
malfunction that occurs between the remote MMC and the WSUS Server.
Two things are constant in the design of this whole package:
[1] The remote workstation and the WSUS Server =COMPUTERS= must be member of
the same domain. But being members is not just enough. The =COMPUTER=
accounts must also be successfully authenticating with the DOMAIN
CONTROLLER - thus my suggestion to reset the computer account of the WSUS
Server, but you're convinced this couldn't possibly be the issue so you've
opted not to take that advice.
[2] A DOMAIN account used to access the WSUS Server via the remote MMC
=must= have membership in one of these three:
[a] Either a member of Domain Admins, wherein Domain Admins is also a
member of the local Administrators group on the WSUS Server.
[b] A member of the local Administrators group on the WSUS Server.
[c] A member of the local WSUS Administrators group on the WSUS Server.
In addition, if reporting-ONLY is desired, a member of the local WSUS
Reporters group on the WSUS Server.
But it's absolutely pointless to even worry about reporting access if the
console isn't even accessible to those with FULL permissions!?
If your "WSUS Administrators" group is not giving access to the remote
console, then there's one of three known causes that need to be investigated
and /confirmed/ not-at-fault:
[1] The WSUS Administrators group must belong to the appropriate
security groups, and those security groups, along with the WSUS
Administrators group must have the appropriate security permissions, if the
domain account is a member of the WSUS Administrators group.
[2] The local Administrators group must have the appropriate
permissions, if the domain account is a member of the local Administrators
group or a member of the Domain Administrators group.
[3] The remote computer and the WSUS Server must have a "Domain Trust"..
that is, they must either:
[a] be AUTHENTICATED members of the same Active Directory
Domain, or
[b] the account name/password of the logged on user of the
remote machine must be identical in the SAM of the WSUS Server,
and have the correct group memberships
(Administrators, WSUS Administrators)
Now.. please don't get hung up on the term "Domain Trust" -- we're not
talking about multiple domains here, we're talking about two systems being
authenticated members of the same domain =and= the user account also being
an authenticated member of the same domain. So far, the only thing you've
actually confirmed is that the =user= account is properly authenticated.
You've not confirmed that both =computer= accounts are properly
authenticated.
Now, so far, as I recall, the only thing we've demonstrated, functionally,
is that a local ADMIN account on the WSUS Server console can successfully
access the MMC Admin Console of the WSUS Server. Nothing else works. To
me... that seems pretty simple... some security mechanism somewhere is
mucked up.
Where would you like to start?
My suggestion was the simple one --- reset the COMPUTER account of the WSUS
Server and confirm that the WSUS Server computer account is properly
authenticated with the domain. Maybe this won't make any difference at all.
But at least we will have =ELIMINATED= this possible cause!
As for [1] and [2] above, the various security permissions and memberships
of the various accounts and groups affecting WSUS operations are pretty
complex. So complex, that if [1] or [2] seems to be the case, my advice,
generally, is going to be to reinstall the entire system from scratch.
--
Lawrence Garvin, M.S., MCBMSP, MCTS(x4), MCP
Senior Data Architect, APQC, Houston, Texas
Microsoft MVP - Software Distribution (2005-2008)
MS WSUS Website:
http://www.microsoft.com/wsus
My Websites:
http://www.onsitechsolutions.com;
http://wsusinfo.onsitechsolutions.com
My MVP Profile:
http://mvp.support.microsoft.com/pro...awrence.Garvin