Tuesday, November 29, 2005

MIIS password management App

1. Installed MIIS. MIIS created five AD security groups. No password management application was installed after MIIS installation.
2. System administrator deleted “MIISPasswordSet” group. Realized two days later that it was a mistake so manually recreated the “MIISPasswordSet” security group in AD.
3. Installed Password management application and getting the error “Could not add the user account to password set group. Check password set group name”. I checked the group name and it was correct. The account that was used to install the application has domain admin access and the account to run password management is already in “MIISPassswordSet” group.
Question: Can action in Step 2 cause issue that I am seeing in 3? If so, Do I need to reinstall MIIS to recreate security groups?

This is a problem with the Password Management setup. It happens whenever the MIISPasswordSet group is not a local security group. The setup does not read the MIIS configuration to see where the MIISPasswordSet group is located, and assumes it is on the local machine.
Work-around:
1. Create a new local group on the machine where you are installing the Password Management application called MIISPasswordSet
2. Run the setup for the Password Management app.
3. Take note of what users were placed into the local Password Management group and add them to the Domain Global group you have configured to be the MIISPasswordSet security group.
4. Delete the local MIISPasswordSet security group.

No comments: