It might be a little late to respond, but in case this happens to anyone else:
1. make sure you have AD permissions.
2. Launch PowerShell as an administrator, EVEN IF YOU'RE LOGGED IN WITH AN ADMIN ACCOUNT.
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have a new install of Windows Server 2019 on a VMware VM. There are two domain controllers, DC-01 and DC-02. I'm trying to create gMSA to start SQL Server services. I run the command:
Add-KDSRootKey -EffectiveTime ((get-date).addhours(-10))
This works correctly. I use AD Administration Tool to create a group SQLServers and add the SQL-01 server to this group, then I rebooted SQL-01.
I try to create the gMSA by running, inside an Administrator Power Shell:
New-ADServiceAccount SQLsvc -ServicePrincipalNames "MSSQLServer/SQL-01.xxx.com" -PrincipalsAllowedToRetrieveManagedPassword "SQLServers"
(NOTE: I tried both SQLsvc and SQLsvc$ and both give the same error) (and replacing xxx.com with the actual domain name from AD)
I get prompted with the following:
cmdlet New-ADServiceAccount at command pipeline position 1
Supply values for the following parameters:
DNSHostName: SQLsvc.xxx.com
I get the following error:
New-ADServiceAccount : Access is denied
At line:1 char:1
The Windows System error log shows the following, which I think is related, but perhaps not:
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user STES\TurnerJ.DA SID (S-1-5-21-846075100-2544379057-207111340-1110) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
It doesn't matter if I run using the Administrator account, or my Domain Admin account. Whenever I try to include the DNS parameter, I get this error. I'm running it from the DC-01 domain controller using an elevated PowerShell window.
Does anyone have any idea how to overcome this problem? Is there any other information I should provide? I just created the AD servers, so I don't know what can be wrong.
Thanks,
Jack
Locked Question. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
It might be a little late to respond, but in case this happens to anyone else:
1. make sure you have AD permissions.
2. Launch PowerShell as an administrator, EVEN IF YOU'RE LOGGED IN WITH AN ADMIN ACCOUNT.