Answered by:
Discovery Wizard not working correctly in 2019

Question
-
Hello all,
I've just completed a new SCOM 2019 deployment and am noticing some weird behavior with the Discovery Wizard. When attempting an Agent push the wizard will fail, if an account is used that does not have the log on as a service right (in the "Administrator Account" section in the wizard).
If such an account is used - and that includes the domain admin account - the wizard will fail immediately to the "no computers discovered" screen and log event 4625 in the security log (sanitized copy below).
This can't be by design - all previous SCOM versions did not work this way. Can anyone confirm?
Oh, and in addition, upn's don't work with the web console - seriously ?!?!
Thx&Rgds,
M.An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: SCOMCOMPUTERACCOUNT$
Account Domain: DOMAIN
Logon ID: 0x3E7Logon Type: 5Account For Which Logon Failed:
Security ID: NULL SID
Account Name: Administrator
Account Domain: SUBDOMAINFailure Information:
Failure Reason: The user has not been granted the requested logon type at this machine.
Status: 0xC000015B
Sub Status: 0x0Process Information:
Caller Process ID: 0xc18
Caller Process Name: C:\Program Files\Microsoft System Center\Operations Manager\Server\HealthService.exeNetwork Information:
Workstation Name: SCOMCOMPUTERNAME
Source Network Address: -
Source Port: -Detailed Authentication Information:
Logon Process: Advapi
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
Monday, April 8, 2019 11:31 PM
Answers
-
Hello!
There are some security changes in SCOM 2019, you must add your ”Operations Admins group” to the allow ”Log on as a Service” right on the SCOM management servers in order to be able to push SCOM agents.
Please refer to Kevin Holman’s blog about the changes in SCOM 2019:
https://kevinholman.com/2019/03/14/security-changes-in-scom-2019-log-on-as-a-service/
Best regards,
Blog:
https://thesystemcenterblog.com LinkedIn:
Tuesday, April 9, 2019 5:49 AM
All replies
-
Hello!
There are some security changes in SCOM 2019, you must add your ”Operations Admins group” to the allow ”Log on as a Service” right on the SCOM management servers in order to be able to push SCOM agents.
Please refer to Kevin Holman’s blog about the changes in SCOM 2019:
https://kevinholman.com/2019/03/14/security-changes-in-scom-2019-log-on-as-a-service/
Best regards,
Blog:
https://thesystemcenterblog.com LinkedIn:
Tuesday, April 9, 2019 5:49 AM -
Leon,
interesting - thx for the clarification.
Kind regards - M.
Tuesday, April 9, 2019 7:06 PM