Deployment Automation features in the HMC 3.5 deployment tool

Introduction

The HMC 3.5 deployment tool carries out a lot of automated tasks, with somewhat mysterious names like "Initialize Active Directory for Hosting".  Many customers have asked me what it is actually doing to their Active Directory configuration!  This info is actually buried in the HMC 3.5 documentation (in the Deployment Automation Appendix), but I have created a simple listing of what each step actually does.

Following is an overview of what each deployment automation feature does.

1.1.1  Initialize Service Account Security

Steps Performed.

1.  Ensure Windows-based Hosting Service Accounts exists in the Users container.  If it does not exist, create it.

2.  Reference the dn of this group in an OtherWellKnownObject on the domain OU.

3.  Remove the Authenticated Users group from the Pre-Windows 2000 Compatibility Group

4.  Add the Domain Computers group to the Pre-Windows 2000 Compatibility Group

5.  Apply a read ACL to the domain root giving the Windows-based Hosting Service Accounts group read access to the directory tree.

1.1.2   Create Servers OU

Steps Performed.

1.  Creates the Servers OU hierarchy in Active Directory

 

1.1.3   Configure MPS SQL Service Account

Steps Performed:

1.  Add the MPSSQLService account to the Windows-based Hosting Service Accounts group

 

1.1.4   Configure MPS Cluster Admin

Steps Performed:

1.  Add the MPSClusterAdmin account to the Windows-based Hosting Service Accounts group

 

1.1.5   Configure MPF Service Account

Steps performed.

1. Add the MPFServiceAccts group to the Windows-based Hosting Service Accounts group

2.  Query the registry to discover the name of the MPF Configuration Server

3.  Query WMI to determine if configuration server represents a cluster.

4.  If configuration server is a cluster, enumerate the nodes of the cluster.

5.  Query WMI to determine the names of any MPF engine servers

6.  For each MPF engine, configuration server, or configuration server node, add the MPFServiceAccts group to the local Administrators group on each machine.

 

1.1.6  Initialize Namespace Security

Steps Performed:

Configures the context under which various provisioning namespace procedures run.

 

1.1.7  Initialize Active Directory for Hosting

Steps Performed:

1.     Creates the Hosting OU

2.     Removes permissions from the Authenticated Users group to the Hosting OU

 

1.1.8   Configure MOM Service Account

Steps Performed:

1.  Add the MOMService account to the Windows-based Hosting Service Accounts group

2.  Grant the following user rights to the MOMService account on the MOM servers specified in <serverName>:

                        Act as part of the operating system

    Create a token object

    Log on as a batch job

    Log on as a service

 

1.1.9  Configure MOM Action Account

Steps Performed:

1.  Add the MOMAction account to the Windows-based Hosting Service Accounts group

 

1.1.10  Configure Reporting Services

Configures service startup behavior on the MOM SQL Server

Steps performed.

1. Set Distributed Transaction Coordinator (DTC) service to Automatic startup

2. Set SQLSERVERAGENT service to Automatic startup

3. Set Microsoft Search Agent to Disabled

4. Start DTC service

5. Start SQLSERVERAGENT

6. Stop Microsoft Search Agent

 

1.1.11  Disable Domain RUS

Disables the domain Recipient Update Service.

Steps Performed:

1.   Disables the Domain Recipient Update Service in Exchange.

 

1.1.12  Native Mode

Sets Microsoft Exchange to Native Mode

Steps Performed:

1.  Sets Microsoft Exchange to Native Mode

 

1.1.13  Prepare Address List Security

Configures security on the All Address Lists container to prevent users and customers from resolving each other's names in Outlook.

Steps Performed:

1. Secures the "All Address Lists" container in Exchange

a. Disable inheritable permissions from propagating from parent

b. Remove Authenticated Users Group

c. Remove Everyone Group

 

1.1.14  Configure Exchange Address List Security

Steps performed

1. Delete default address lists

a. Delete All Users default address list

b. Delete All Groups default address list

c. Delete All Contacts default address list

d. Delete Public Folders default address list

2. Secure the Global Address List

a. Disable inheritable permissions from propagating from parent

b. Remove Authenticated Users Group

c. Remove Everyone Group

 

1.1.15  Configure Exchange Front End Servers

Automates configuration of an Exchange Front End Server.

Steps performed

1. Disable the Microsoft Exchange Information Store

2.  Enable Services

a. POP3

b. IMAP

3. Configure Virtual Directories

a. Exchange

b. Public

c. RPC

 

1.1.16  Configure MPS Exchange Security

Configure MPSExchangeAccts group

Steps Performed:

1.  Ensure MPSExchangeAccts group exists

2.  Add MPSExchangeAccts group to local administrators on MPS server

3.  Ensure MPSPrivAcct-xxxx is a member of MPSExchangeAccts group

 

1.1.17  Create OAB Lifetime Registry Keys

Create a registry key in order to configure automatic generation of Offline Address Books in the hosting environment.  Configuration of the OAB Lifetime registry key is required on all back, OAB Exchange Servers, and Front-end servers.

Steps Performed:

1.   Enumerate all Exchange servers

2.   Create the following registry keys on each server:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeSA\Parameters]

"OAL Folder Lifetime (days)"=dword:00000000

Note- by setting OAL Folder Lifetime to zero, this prevents Exchange from allowing Offline Address Books to expire.

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSExchangeSA\Parameters]

"Disable OABScanTask"=dword:00000001

Note - by disabling the OAB scan task, this prevents Exchange from trying to scan all of the OAB's during nightly online maintenance.

 

1.1.18  Configure Sharepoint Services Security

Required Input:

1.  <serverName>

2. <username> -- The domain logon name of the domain account created for Sharepoint services (e.g. Sharepoint_AppID). This should be in the format of Domain\UserName.

 

Steps Performed:

1. Ensure account existence.

2.  Create a new SQL Login for the supplied user name.

3.  Add the SQL Login to the following server roles:

a.  Security Administrators

b.  Process Administrators

c.  Database Creators

1 Comment

Leave a comment

Recent Entries

  • How to remove a VMHost from SCVMM 2008 R2 forcefully

    这几天碰到个问题,有个服务器原来安装的是 2008 Server Core系统,上面跑 Hyper-V,已经将其导入 SCVMM 2008 R2 来管理。最近实在是嫌 Server Core 管理太不方便,于是想把系统换成带图形界面的,也没在 SCVMM 里面把主机删除,直接就重装了,IP和计算机名什么的都没变,结果问题来了,再打开 SCVMM 的控制台,发现这台主机联系不上(当然,因为重装的没有了 Agent),就想删掉再重加,结果删除过程报错:Error (801) VMM cannot find ISO object . Recommended...

  • Outlook Mobile Update

    现在你可通过新的Microsoft Office Outlook Mobile更新程序和 Microsoft Exchange Server 2010 来保证你手上的信息是最有价值的。 这次的 Outlook Mobile 更新仅针对 Windows Mobile 6.1 的手机。 当你的手机连接到 Exchange Server 2010 时,如果有适合的更新你会收到自动的提示。 如果你的手机的系统是 Windows Mobile...

  • 哥们,我的更新汇总在哪呢?

    我刚刚在我全新的 Exchange 2010 服务器上安装了更新汇总1 - RU1, 然后运行 Get-Exchangeserver -Identity MyExchangeServer (译者: 可以用 Get-Exchangeserver -Identity MyExchangeServer | fl ExchangeVersion, AdminDisplayVersion)得到以下关于AdminsDisplayVersion 和 ExchangeVersion 的版本信息: 嗯, 这看上去有点眼熟(译者:...

  • Exchange 2010 Update Rollup 2

    Today Microsoft released Update Rollup 2 for Microsoft Exchange Server 2010. RU2 comes 3 months after the release of RU1. The list of included fixes...

  • HMC 4.0 Update Rollup 3 has been updated

    Description of Update Rollup 3 for Hosted Messaging and Collaboration 4.0http://support.microsoft.com/kb/979702/en-usMicrosoft released an update rollup that is dated December 2009. This update fixes issues that...

Close