Enterprise server service accounts - A/D Migration?

RTCAdmin

Member
Background:
I am the non-JDE network admin of my company (I don't even have a JDE signon). Our Windows 2000 JDE Enterprise server is using an NT4 domain account to start the "JDE Update 4 B733 Queue" and "JDE Update 4 B733 Network" services. These services must be reconfigured to use an Active Directory or local user account so I can migrate the machines to Active Directory.


My Question:
*** Is there anything outside the obvious windows tasks (change accounts, restart services) that needs to be done to ensure these services retain all functionality? ***


So far, I haven't been able to find any mention of accounts starting these services needing any special security, so I'm assuming I can just switch them to either an A/D or local account w/o issue. Would someone be so kind as to confirm my assumption? I'd hate to grind business to a halt.
shocked.gif


On a similar note, I will eventually need to migrate the Enterprise server and Deployment servers to A/D, anyone know of any gotchas I need to be aware of? AFAIK, these should be like any other server migration I've done...

Regards,
Jeff
 
The service account MUST be a domain account!

I found that this service account is the context under which print jobs are being submitted to our Windows queues. If I were to switch to a server local account, nothing would print..
 
I finally changed the service account last night and all is well.
cool.gif


The steps I took were:
1. Copy the current service account's windows profile to "Default User".
2. Verify the new service account has no profile, or delete it if it exists.
3. Verify the new service account is an administrator of the enterprise server.
4. Log in as the new service account to create a profile copied from the copy of the old service account's profile.
5. Change the service account username and passwords.
6. Restart the services.
7. Execute a RUNUBE job to verify system functionality.

This may have been overkill, but since I have pretty much no information to work with, I took the safe route. I also added the new service account to the administrators group on our print servers, because the old service account was configured as a domain admin for some reason. This isn't allowed under our A/D policy.

The RUNUBE test definately isn't the best way to test, but like I said before, I don't even use JDE and that's all I had available.
grin.gif


Hopefully this will help some other admin, there isn't a whole lot of helpful documentation or posts out there.
 
Ok, final update. I migrated the machine to Active Directory this past weekend, and there have been no reported issues.
 
Back
Top