Run the Windows Configuration Script for the Domain Controllers
Run the Windows Configuration Script for Domain Controller script on all of the domain controllers at each site, (excluding read-only domain controllers (RODCs)) and for each domain that will integrate with Secure Access. The configuration script prepares the domain controllers to communicate with the AD Connector. When you run the script, the domain controller should register with Secure Access.
- As an administrator, open an elevated command prompt.
Before running the script, you must create the Cisco_Connector user account. Also, there are several Group Policies that affect system operation that may need manual configuration. The script displays the status of these settings and, if needed, provides instructions on how to change them. - Locate the Windows Configuration Script for Domain Controller file and run the script in the command prompt.
Substitute the Windows configuration script filename (including the .wsf file extension) in the cscript command.cscript <Windows Configuration Script filename with extension> or cscript <Windows Configuration Script filename with extension> --username <sAMAccountName for custom user>
Important: The script displays your current configuration, and then offers to auto-configure the domain controller. If the auto-configure steps are successful, the script offers to registers the domain controller with Secure Access. Registration only occurs if you accept this offer.
Repeat the steps to add your domain controllers in Secure Access. It is essential that each domain controller in each AD domain environment has the configuration script run on it in order for the service to work as expected, both for high availability and overall reliability.
|
The configuration script is not an application or service. If you change the IP address or hostname of the domain controller, remove the previous instance of the domain controller and re-register the domain controller.
|