Article ID: 200670 - Last Review: October 26, 2007 - Revision: 2.5 SMS: Customizing the Systems Management Server Administrator Console
This article was previously published under Q200670 On This PageSUMMARY
In Microsoft Systems Management Server version 2.0, the Systems Management Server Administrator console is a Microsoft Management Console (MMC) snap-in that can be customized by adding specific Console Tree Items (for example, Collections). Using Systems Management Server Console security, you can further limit console functionality by customizing the view that your administrators have of the Systems Management Server Administrator console. You set permissions on object classes and instances using the Security console item.
MORE INFORMATION
When combined with MMC customizable consoles, the Systems Management Server 2.0 security model makes it easy to delegate Systems Management Server administrative tasks. Administrative tasks can be delegated by group. Define local groups on the site server that relate to required tasks. Corresponding global groups or users can be added as necessary. For example, a user group called HelpDesk can be created. Full permissions for Systems Management Server Remote Tools can be assigned to this group, but not permissions for Site Configuration objects. You can also create a customized MMC console that includes only the objects that the group requires to perform the tasks delegated to them. In this way, you can provide members of the HelpDesk group with all the tools required to support end users, yet prevent them from accessing unnecessary objects.
The following example outlines the steps needed to create a custom MMC console that shows only the Collections tree item. The second set of instructions demonstrates how to set security options so that the HelpDesk group will be able to view and use Remote Tools on the "All Windows NT Systems" collection. NOTE: Members of the HelpDesk local group or corresponding HelpDesk global group are required to be members of the permitted viewers list for the Remote Tools Client Agent and of the SMS Admins local group on the server housing the Systems Management Server provider (either the SQL or SMS system). Using this method, it is not necessary to directly add users through the Web Based Enterprise Management Permissions Editor (WBEMPERM). To Create a Customized Systems Management Server Console
To Set up Security Permissions
WMI 1.5-Enabled ComputersComputers that have been upgraded to Windows Management Instrumentation (WMI) 1.5 or Microsoft Windows 2000-based computers do not have the WMI 1.1 tool (Wbemperm.exe).NOTE: Windows NT 4.0 users which have WMI 1.5 installed, also need to install the Microsoft Security Configuration Editor (MSSCE), included on the Windows NT 4.0 Service Pack 4 (SP4) (and later) CD-ROM. On Windows NT-based computers, the tool is Wbemcntl.exe. MSSCE is required to edit the Access Control Lists (ACLs) on the Windows Installer (WI) namespaces. REFERENCES
Also see the following Knowledge Base articles: 230263
(http://support.microsoft.com/kb/230263/EN-US/
)
How to Create Custom MMC Snap-in Tools Using Microsoft Management Console
199869
(http://support.microsoft.com/kb/199869/EN-US/
)
SMS: Assigning Class and Instance Security Rights with the SMS User Wizard
201126
(http://support.microsoft.com/kb/201126/EN-US/
)
SMS: Troubleshooting Connectivity to the SMS Site Database
Additionally, the BackOffice 4.5 Resource Kit contains related information: Search for 'Custom MMC' from Microsoft Resource Kit Online Books.
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|






Windows Live
Facebook
Twitter
Linkedin
Digg it
Yahoo
Delicious
StumbleUpon
Yammer
Reddit
Technorati
FriendFeed
Email
Back to the top
