Change the account under which the Cluster service run in windows server 2008


hi experts,

in environment windows cluster service runing local service account. want run service newly created service account. service account has full control on both node of cluster

i searched on google , found solution treid same. did not worked me.. example:-

to change account under cluster service runs

  1. stop cluster service on nodes:

    • make sure account has membership in local administrators group on nodes.
    • open local security policy , grant following rights account, or local administrators group, on nodes:
    where? security settings/local policies/user rights assignments

    • act part of operating system
    • back files , directories
    • restore files , directories
    • adjust memory quotas process
    • log on service
    • increase scheduling priority
    default, cluster service account inherits following user rights result of being member of local administrators group:

    • manage auditing , security log
    • debug programs
    • impersonate client after authentication
    if organization has removed these user rights default set of privileges assigned local administrators group, need assign these user rights cluster service account.

    • open computer management.
    • in computer management, double-click services , applications, , click services.
    • in details pane, click cluster service.
    • on action menu, click stop.
  2. repeat step 1 on other nodes.
  3. in details pane of 1 node, double-click cluster service.
  4. on log on tab, type account name in this account, type password in password, , confirm password , click ok.
  5. on action menu, click start.
  6. repeat steps 2, 3, 4, , 5 on other nodes.

notes

  • to perform procedure, must member of administrators group on local computer, or must have been delegated appropriate authority. if computer joined domain, members of domain admins group might able perform procedure. security best practice, consider using run perform procedure.
  • to open computer management, click start, click control panel, double-click administrative tools, , double-click computer management.
  • to open local security policy, click start, point settings, click control panel, double-click administrative tools, , double-click local security policy. select show advanced user rights view available security settings.
  • the cluster service on nodes must stopped , restarted during procedure. cluster service must use same account , password @ times on nodes within cluster.
  • you must use active directory users , computers view account properties if account in windows 2000 or windows server 2003 family domain. must use user manager domain view account properties if account in windows nt 4.0 domain. user manager domain can installed using client-based network administration tools running setup.exe windows nt server 4.0 media in clients\srvtools\winnt\ directory or running usrmgr.exe clients\srvtools\winnt\i386 or clients\srvtools\winnt\alpha directory.

but when run cluster service got error message.

event id:- 7000

the cluster service service failed start due following error:

a privilege service requires function not exist in service account configuration. may use services microsoft management console (mmc) snap-in (services.msc) , local security settings mmc snap-in (secpol.msc) view service configuration , account configuration.

pls help



balwan singh



that kb applies win2003.

it not possible run clussvc under custom account in win2008 , beyond

thanks!
elden



Windows Server  >  High Availability (Clustering)



Comments

Popular posts from this blog

Edit Group Policy

Hyper-V VM not reaching OS 'Logon' screen

DNS question...