You cannot install ISA Server 2004, Enterprise Edition Service Pack 2 in a domain (915419)



The information in this article applies to:

  • Microsoft Internet Security and Acceleration Server 2004, Enterprise Edition

SYMPTOMS

Consider the following scenario:
  • Active Directory Application Mode (ADAM) is configured on a computer that is part of a domain.
  • Microsoft Internet Security and Acceleration (ISA) Server 2004 array members are members of a workgroup.
In this scenario, you cannot install ISA Server 2004, Enterprise Edition Service Pack 2 (SP2) in the domain.

CAUSE

This issue occurs because ISA Server 2004, Enterprise Edition SP2 assumes that the connection to the ADAM-based computer was established by using the same credentials that you used to log on to the ISA Server computer.

WORKAROUND

To work around this issue, follow these steps:
  1. Create a local user on the ADAM-based computer. Make sure that the local user name and password that you create on the ADAM-based computer are the same as the user name and password that you use to log on to the ISA Server computer.

    For example, if you log on to the ISA Server computer by using the "MyAdmin" user account and the "IsA@adam" password, create the same user account and password on the ADAM-based computer.
  2. Add the local user account that you created on the ADAM-based computer to the ISA Server Enterprise Administrators group. To do this, follow these steps:
    1. Click Start, point to Programs, point to ADAM, and then click ADAM ADSI Edit.
    2. On the Action menu, click Connect to, and then type 2171 in the Port box.
    3. In the Distinguished name (DN) or naming context box, type CN=FPCConfiguration.
    4. Expand FPCConfiguration, and then expand CN=Roles.
    5. Right-click CN=Administrators, and then click Properties.
    6. Under Attributes, click Member, and then click Edit.
    7. In the Multi-valued Distinguished Name With Security Principal Editor dialog box, click Add Windows Account.
    8. Click Locations, and then click the location that points to the local ADAM-based computer.
    9. In the Enter the object names to select (examples) box, type the account name that you created on the ADAM-based computer by using the computer\account or domain\account format. For example, type ADAM\MyAdmin.
    10. Click OK. The new user name appears in the Multi-valued Distinguished Name With Security Principal Editor dialog box as a member of the ISA Server Enterprise Administrators group.
    11. Click OK two times to return to the ADAM ADSI Edit snap-in.
You can now install ISA Server 2004, Enterprise Edition 2004 SP2.

Modification Type:MinorLast Reviewed:4/7/2006
Keywords:kbtshoot kbprb KB915419 kbAudITPRO