In order to deploy this solution, there are some basic steps that need to be followed; refer to the operations guide for more information about the following:
- AD schema update: Before this solution can be used, the AD schema needs to be extended by two new attributes.
- Administrator permissions: There are several permissions that must be set in order to allow the computers to update AD with their local administrator account details and to prevent unauthorized access to the passwords once they are stored in Active Directory:
- Add machine rights to enable each managed computer to update the new schema attributes
- Remove extended rights from all users to prevent access to the passwords
- Add user rights to enable the appropriate ...