2015年10月15日 星期四

"Access Denied" in Runbook Designer when connecting to the Orchestrator

To add additional users and/or security groups to be authorized for remote access, launch and activation of the omanagement DCOM Server, follow the instructions below:
  1. On the System Center Orchestrator Management Server, launch dcomcnfg to open up the Component Services applet.
  2. Expand Component Services, then Computers, then My Computer.
  3. Right-click My Computer, then click Properties.
  4. Click the COM Security tab.
  5. Under Access Permissions, click Edit Limits.
  6. Click Add then enter details of the desired local or Active Directory based security group and click OK.
  7. Click the new entry and then select the Allow checkbox for each permission then click OK.
  8. Under Launch and Activation Permissions, click Edit Limits.
  9. Click Add then enter details of the desired local or Active Directory based security group and click OK.
  10. Click the new entry and then select the Allow checkbox for each permission then click OK.
  11. Click OK to close the My Computer Properties dialog.
  12. Expand My Computer, then click DCOM Config.
  13. Locate omanagement, then right-click and choose Properties.
  14. Click the Security tab.
  15. Under Launch and Activation Permissions, click Edit.
  16. Click Add then enter details of the desired local or Active Directory based security group and click OK.
  17. Click the new entry and then select the Allow checkbox for each permission then click OK.
  18. Under Access Permissions, click Edit.
  19. Click Add then enter details of the desired local or Active Directory based security group and click OK.
  20. Click the new entry and then select the Allow checkbox for each permission then click OK.
  21. Click OK to save the changes.
  22. Close the Component Services applet.
  23. Open a Command Prompt.
  24. Type sc stop omanagement and press Enter.
  25. Type sc start omanagement and press Enter.
Once the Orchestrator Management Service (omanagement) is restarted, direct users and members of security groups that were added will now be able to successfully connect to the System Center Orchestrator Management Server using the Runbook Designer.

