A cloud-based identity and access management service for securing user authentication and resource access
Hello EFR,
You pointed me in the right direction.
(It’s not just "Administrators" but also "NETWORK SERVICE" that cause the problem.)
On a Windows client:
- MSI:
- Extract the MSI using dark.exe (WiX Toolset) (download wix314-binaries.zip from GitHub)
- Create a directory for extraction: (c:\ExtractedFiles)
- dark.exe AADConnectProvisioningAgentSetup.exe -x c:\ExtractedFiles
- In c:\ExtractedFiles\AttachedContainer, right-click the file named "a0"
- Rename the file exactly to:
AADConnectProvisioningAgent.msi
- ORCA:
- Download the web installer for the current Windows SDK directly from the Microsoft Windows SDK download page.
• When selecting features to install, choose only "MSI Tools" (Windows SDK components for Windows Installer developers) and uncheck everything else to save disk space.
• Complete the SDK installation.
• Once the SDK setup is finished, the actual installation file for Orca will be located in a subdirectory of your Windows Kits folder (by default, at a path like C:\Program Files (x86)\Windows Kits\10\bin<version number>\x86).
• Look for the file Orca-x86_en-us.msi (or a similarly named file) there.
• Double-click this MSI file to install Orca.exe on your system.
- Create MST:
- Launch Orca.
- Open the MSI file AADConnectProvisioningAgent.msi. - Menu: Transform - New Transform
- Under Tables: Wix4SecureObject
- Delete the domain (builtin) for UserAdministrators and change the User to "Administratoren"
- Delete the domain (NT Authority) for the NETWORK SERVICE user and change the User to "Netzwerkdienst" (or whatever the local account is named on the DC—launch services.msc to check the exact account name, as there are likely already services running under this account).
- Menu: Transform - Generate Transform - name and save the .mst file (e.g., fix-accounts.mst).
- Copy it to the DC along with the .msi file.
Start the installation via the command line:
msiexec.exe /i "C:\Sources_AADConnect_msi_mst\AADConnectProvisioningAgentSetup.msi" TRANSFORMS="@C:\Sources_AADConnect_msi_mst\fix-accounts.mst" /qn /norestart /L*v "C:\Sources_AADConnect_msi_mst\install.log"
The wizard should now launch.
(Use at your own risk)
It would be great to see a timely solution from Microsoft, though. It’s in their interest, after all—they want us on M365.
This whole process is an incredibly messy workaround.