Run the Windows Configuration Script for the Domain Controllers
Run the Windows Configuration Script for Domain Controller on all of the domain controllers at each site, (excluding read-only domain controllers (RODCs)) for each domain that will integrate with Secure Access. The configuration script prepares the domain controllers to communicate with the AD Connector.
Before running the script, you must create the Cisco_Connector user. Also, there are several Group Policies that affect system operation that may need manual configuration. The script displays the status of these settings and, if needed, provides instructions on how to change them.
Repeat the steps to add your domain controllers in Secure Access. It is essential that each domain controller in each AD domain environment has the configuration script run on it in order for the service to work as expected, both for high availability and overall reliability.
|
The configuration script is not an application or service. If you change the IP address or hostname of the domain controller, remove the previous instance of the domain controller and re-register the domain controller.
|
Before you begin
- Full Admin user role. For more information, see Manage Accounts.
- For information about the requirements for deploying the Cisco AD Connector, see Prerequisites for AD Connectors.
Procedure
1 |
As an administrator, open an elevated command prompt. |
||
2 |
Locate the Windows Configuration Script for Domain Controller file and run the script in the command prompt. |
||
3 |
Substitute the Windows configuration script filename (including the .wsf file extension) in the cscript command.
|