2008 Failover cluster unable to create computer account

Hello,
I have created a 2008 R2 Failover cluster and I am trying to add a Fail over File server to this.
I get the dreaded
Cluster network name resource 'OfMaClusterFS' failed to create its associated computer object in domain 'xxx.domain' for the following reason: Unable to create computer account.
The text for the associated error code is: Access is denied.
Please work with your domain administrator to ensure that:
- The cluster identity 'OFMACLUSTER$' can create computer objects. By default all computer objects are created in the 'Computers' container; consult the domain administrator if this location has been changed.
- The quota for computer objects has not been reached.
- If there is an existing computer object, verify the Cluster Identity 'OFMACLUSTER$' has 'Full Control' permission to that computer object using the Active Directory Users and Computers tool.
I have created clusters frequently in the past, on my own Domains that I am a domain admin of.  Now I am trying to make one on our larger corporate domain that I am not a domain admin of and get this error.
By default, domain users can not add computer accounts to our domain.  I do however have an limited account that can add computers to the domain... but I have tried all the tricks I can think of to try and add the Network name to AD and no luck.#
I have tried running the cluster service with this account, but it is still trying to use the OFMACLUSTER$ identity to create the Network name.  I have tried manually creating the network name using my limited account, but that doesn't work either,
same error.  I don't have the ability to change permissions on the computer name I added for the network name to AD.
I have raised a ticket to our wintel team to try and get them to help, but they aren't exactly the most responsive bunch.  I'm just wondering what the best way around this problem is if I am not a domain admin and I can't make the changes I need, or
what concise instructions I can give to the domain admins so that they can help me out without saying that it is a security breach etc.
I would appreciate any advice on this as it's now urgent and also something I will have to do in the future fairly regularly and don't want to get caught in the situation in the future.

Hi jogdial,
To create a cluster, the minimum permission is: Requires administrative permissions on the servers that will become cluster nodes. Also requires
Create Computer objects and Read All Properties permissions in the container that is used for computer accounts in the domain.
If you create the cluster name account (cluster name object) before creating the cluster—that is, prestage the account—you must give it the
Create Computer objects and Read All Properties permissions in the container that is used for computer accounts in the domain. You must also disable the account, and give
Full Control of it to the account that will be used by the administrator who installs the cluster.
The related KB:
Failover Cluster Step-by-Step Guide: Configuring Accounts in Active Directory
http://technet.microsoft.com/en-us/library/cc731002(v=ws.10).aspx
More information:
How to Create a Cluster in a Restrictive Active Directory Environment
http://blogs.msdn.com/b/clustering/archive/2012/03/30/10289577.aspx
I’m glad to be of help to you!
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place.

Similar Messages

  • Automatically Create Computer Accounts

    Hey Everyone, been searching a bit but I thought I might ask the forums how everyone else has solved this issue. When we bind some MacBook Pros or MacBooks to Open Directory, we would like for it to automatically create computer accounts in Workgroup Manager that we may be able to assign preferences to them via Computer Groups that we have set up. Similar to how Windows and Active Directory work when you add a computer to a domain. Can this be done? I'm sure it will require authentication when binding so is there any documentation on that by chance?
    Thanks!
    Jeff

    I think I answered my own question. I was used to authenticating using the check box prior to 10.6.3. Looks like they ended up changing the process a bit.
    http://support.apple.com/kb/HT4068

  • Unable to create webOS account to set up HP Touchpad

    Alright, so I got my Touchpad Saturday, and tried to set it up the day after.  So in order to actually use it, you have to create a webOS account, but every time I try, I get the error "We are unable to create an account for you.  Please try again in a few minutes or contact HP for help resolving this problem.  Visit palm.com/support for more information."  I tried countless times, still getting the same error, even after starting the setup process over, restarting the touchpad and my router, trying different wireless connections, trying it at different times during the day, as well as changing the security question, password and email to see if that had an effect.  I have tried going to the site suggested and trying to chat online with them, as well as calling them, but they were busy, so I was hoping I could find an answer here.
    Post relates to: HP TouchPad (WiFi)
    This question was solved.
    View Solution.

    I too am having the same problems and can't get the WebOS Doctor because I don't have the palm account. There has to be a way to download the doc without an account.

  • Unable to create Contract account

    I am unable to create contract account. I am getting the error message as "Key selection not defined for application R company code List of budget billing proceuders(R301)"
    How to go further?

    Hi, Jack
    Did you go to the path I indicated? In there, for each company code, you need to maintain which budget billing procedures you allow.
    0 means no BB procedure.
    SAP says:
    "If you enter 1 (statistical procedure), budget billing requests are managed as statistical items in the Contract Accounts Receivable and Payable (FI-CA) component and do not affect the general ledger.
    If you enter 2 (debit entry procedure), budget billing requests are posted as partial bills.
    If you enter 3 (payment plan procedure), the budget billing amount is requested as the new bill amount instead of the bill amount determined by billing and invoicing. The difference between the actual bill amount and the payment plan amount is managed in a special item. This procedure is used for monthly billing.
    If you enter 4 (payment scheme procedure), the bill amount is integrated into the budget billing plan. The bill can no longer be paid separately. The budget billing requests are posted as statistical items in the same way to the installment plan.
    If you enter 5 (down payment request plan), a special payment plan is created for industry customers. This plan is suitable for industry customers with monthly periods as the down payment plan for the month after next. To use this procedure, establish the settings in Customizing."
    After that, you need to maintain all the activities related to the BB procedures you want to use, in SAP Utilities / Invoicing / Budget Billing Plan. Check all activities and see what you need to customize.

  • Is there any way to enable eventlog replication between two nodes in windows 2008 failover cluster.

    Is there any way to enable eventlog replication between two nodes in windows 2008 failover cluster.
    Thanks Azam When you see answers please Mark as Answer if Helpful..vote as helpful.

    Hi,
    As far as I know there don’t have the log replica function between failover cluster node, if you want to have the Unified log management you can refer the following related
    KB:
    Configure Computers to Forward and Collect Events
    http://technet.microsoft.com/en-us/library/cc748890.aspx
    Hope this helps.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Windows 2008 Failover Cluster - Cannot add a generic service

    Trying to add a generic service in a failover cluster.
    Select the option Services and Application and it opens the wizard and then displays the error "An error was encountered while loading the list of services. QueryServiceConfig failed. The system cannot find the file specified"
    The cluster validation wizard completes successfully. Permissions do not appear to be an issue as this account can seemly do everything else so I am at a loss to understand why this API is failing when it tries to query the server for services information.
    Having searched the Internet the only thing I have found was someone posting a similar issue in the Greek language Technet forum(if I recall correctly) and their comment was they rebuild their cluster.
    Windows 2008 (SP2) x64 two node cluster running a non-Microsoft database. We need to add a non-Microsoft Enterpirse backup solution and this is their documented method (adding it as a generic service) - both bits of software are from big vendors.
    Symantec AV, but have tried with that disabled so don't think it has anything to do with that. Something is stopping the API from reporting back but I can't find what.
    Really appreciate some help before we have to log a chargable call with Microsoft support
    Thank you

    Hi,
    Have you tried the suggestion? I want to see if the information provided was helpful. Your feedback is
    very useful for the further research. Please feel free to let me know if you have addition questions.
    Best regards,
    Vincent Hu

  • MSDTC set up in SQL Server 2008 failover cluster

    Hi Guys,
    I am in the process of setting up failover cluster using SQL Server 2008  (64Bit) Enterprise on Windows Server 2008 R2 (64Bit) I have completed almost all the works but I got few questions regarding MSDTC configuration whether the MSDTC disk should
    be assigned from SAN or it should be local to the disk ,  Separate disk for each nodes in the cluter or 1 disk to be used across all the servers for MSDTC in windows fail over cluster.
    With regards, Gopinath.

    Hi Gopinath,
    Please review the following similar blogs to get more details about configuring MDTC and pros & cons of different options.
    How to Configure Multiple Instances of Distributed Transaction Coordinator (DTC) on a Windows Server Failover Cluster 2008
    http://blogs.technet.com/b/askcore/archive/2009/02/18/how-to-configure-multiple-instances-of-distributed-transaction-coordinator-dtc-on-a-windows-server-failover-cluster-2008.aspx
    How to configure DTC for SQL Server in a Windows 2008 cluster
    http://blogs.msdn.com/b/cindygross/archive/2009/02/22/how-to-configure-dtc-for-sql-server-in-a-windows-2008-cluster.aspx
    Thanks,
    Lydia Zhang
    Lydia Zhang
    TechNet Community Support

  • Can't create computer account in Workgroup Manager

    Hi everybody !.
    I am installing a new Xserve with Mac OS X Server 10.5.6 and I am having some trouble with computer accounts in Workgroup Manager.
    I have a couple of PCs with Windows XP that I have added to the Windows domain created by Mac OS X Server with no problem,and they do appear in my computer account list, with the name PC_NameX$.
    My Xserve also appears in this list with the name ServerName.DomainName$
    But my iMacs (with Mac OS X 10.4.11) are not listed. When I try to create their accounts, I write their names and their MAC address but when I push the button "Save", Workgroup Manager says that I can't create this account because there is a computer with that name and that MAC address yet.
    I can't find a solution for this problem by myself. Could anybody give some advices to solve it ?.
    Many thanks.

    Hi Mabel,
    In my computer list appears my Windows computer names (followed by a "$" symbol, i.e., name$) and my Xserve name followed by domain name and a "$" symbol, i.e, name.domain$. Finally, there is a Guest account I added a few days ago (without "$" symbol).
    No iMac is listed here. When I try to add them manually, I write "Name", "Short Name" and "Ethernet ID" fields, and when I push "Save" button, I get this message:
    "The name you have chosen conflicts with a name assigned to another computer. You can’t assign the name “Pollux” to two different computers. Remember that names are not case-sensitive when checking for conflicts." (Pollux is the name I gave to one of the iMacs).
    If I change this name and use another one, but I don't change "Ethernet ID" and then push "Save", the message is:
    "The ethernet address you have chosen conflicts with an ethernet address assigned to another computer. You can’t assign the ethernet address “00:17:f2:d3:38:95” to two different computers."
    So, It seems that WGM knows Name and Ethernet ID from this iMac because it does not let me type them again, but I have not typed this information before nor the iMacs are listed in computer list.
    This is what I don't understand.
    I have have read chapter 6 "Setting Up Computers and Computer Groups", the one that starts on page 105, from top to bottom. I have not found a single clue that helps me solving this problem. Here explains the procedure when everything is working properly.
    Finally, another piece from the puzzle. There is an iMac, that always connects to Directory with Airport interface. I have tried to add this iMac, manually. Well, I get the name conflict message, the Ethernet ID conflict message (with its airport id) and... an Ethernet ID message when I type its Ethernet ID. It seems Directory knows this Ethernet ID even, it has never been used to connect to it.
    Is there some detail I am missing ???.
    Kind regards.

  • Users unable to create Mobile Accounts

    Good afternoon.
    I have an interesting problem with the creation of Mobile Accounts.
    We have a Computer Group with its Preferences set to allow the creation of Mobile Accounts & Portable Home Directories; with due consideration given to what to synchronise and what not to. The iBooks & Mac Books in this group are all used by one staff member only. They are all running 10.4.7 and have 256 or 512 MB RAM.
    The first two laptops added to the list allowed their users to create Mobile Accounts & PHDs no problem, and they continue to work. But any other machines I add to the group refuse to allow the creation of a Mobile Account. It seems that Workgroup Manager does no pass on their changed Preferences during subsequent logons. I have tested this by renaming a laptop at its entry in the group and seeing if the name is changed on the machine at the next login. It is not, but stepping through the machine’s settings at the logon display does give me a green light for network availability.
    I can create a Mobile Account on a machine by logging on as a user and amending their account Preferences, but this does not provide the same degree of flexibility in configuring synchronisation settings.
    Has anyone else seen this problem please?
    Brian Bowell ICT Support
    [email protected]
    Tel: 07 856 6537
    Fax: 07 856 6588-- -

    The problem was an error in naming the computer group. Renaming it solved the problem.

  • Inexplainable 2008 Failover Cluster Issues

    Hi,
    We have a 2008 Failover Node & Disk Majority SQL 2005 cluster.
    There are 2 nodes in the cluster with 2008 Ent 64-bit SP2 installed.
    At around 00:20 each morning we see various FailoverClustering errors in the event logs on both servers.
    EventID: 1135, 1069, 1177
    Before the FailoverClustering events are seen, 2 informational events appear regarding the 'Microsoft Failover Clustering Virtual Adapater'
    EventID: 4201 'The system detected that network adapter Local Area Connection* 9 was connected to the network, and has initiated normal operation.'
    This is causing the resources to failover to the secondary node.
    I have run the Cluster Validation Wizard and everything passes. I have disabled the Windows Firewall service on both nodes.
    We are presenting the storage via NetApp and the nodes have 3 nics installed
    NIC1 - Server Vlan - Speed/Duplex Set to 1000Mb Full
    NIC2 - Storage Vlan - Speed/Duplex Set to 1000Mb Full
    NIC3 - Heartbeat - Speed/Duplex Set to 100Mb Full
    Please can anyone help me troubleshoot these issues ?
    Thanks
    Scott

    Hi Scott,
    Event ID 1135 — Cluster Service Startup
    http://technet.microsoft.com/en-us/library/dd353973(WS.10).aspx
    Event ID 1069 — Clustered Service or Application Availability
    http://technet.microsoft.com/en-us/library/dd353893(WS.10).aspx
    Event ID 1177 — Quorum and Connectivity Needed for Quorum
    http://technet.microsoft.com/en-us/library/dd353872(WS.10).aspx
    Event ID 4201 — TCP/IP Network Interface Connectivity
    http://technet.microsoft.com/en-us/library/dd392958(WS.10).aspx
    Hope it helps.
    Tim Quan - MSFT

  • I can't find failover cluster management after creating hyper-v cluster on SCVMM 2012 R2

    I've created a hyper-v cluster on scvmm 2012 r2 but I can't find the failover cluster manager to move storage resources. all hosts are showing to have hyperv role and failover clustering feature installed. disk Witness in Quorum is good, same as for the
    other CSV lun. Please help me Microsoft. Thank you. 

    The management consoles are not getting installed while building the cluster through SCVMM. However, its not mandatory to have the management tools on the server. You can have it on a different machine with this management tools installed and connect to
    this cluster remotely.
    Optimism is the faith that leads to achievement. Nothing can be done without hope and confidence.
    InsideVirtualization.com

  • I am unable to create an account on the HP eprint center login page

    Has anyone else had problems creating an account on the eprint center login page

    Try following the instructions in the iPod Users Guide:
    iPod touch User Guide (For iOS 4.3 Software)

  • Unable to Create an account

    for 2 days I have been able to create an account for mybestbuy on bestbuy.com. I complete the form and get 'An error occurred When we try to create an account. Try again later.' I've tried on Chrome, Firefox and Safari. I'm using a valid email address (receive best buy ad emails there) and U.S. Zip. I already called tech support and they tried to create an account and got the same error and said it was probably a temporary site issue. I've tried for 2 straight days now and would like some help. Thanks.

    Greetings RNinFL, and welcome to the Best Buy forum,
    I can imagine feeling frustrated if you have tried for two days straight to create a BestBuy.com and My Best Buy account without success.  I am not aware of any recent or ongoing website related issues, so I wonder if the information you are using is perhaps already associated with active accounts or maybe just does not fit the criteria.
    With that being said, please send me a private message with the below information and I will see if I can help create those accounts for you.  You can send a private message by clicking on the blue button in my signature labeled "Private Message."  Once I have had the opportunity to try creating the accounts, I will follow up with you.
    Name
    Phone #
    Mailing address
    Email address
    I hope you have a great weekend, and thank you for posting!
    Derek|Social Media Specialist | Best Buy® Corporate
     Private Message

  • Windows Server 2008 failover cluster in VirtualBox

    Hi,
    I'm a Windows NT student and I need help with understanding how to do clustering using multiple Windows 2008 R2 Enterprise servers in VirtualBox 4.3.8. I have a Windows 7 host computer. I was wondering if someone could provide clearly detailed step-by-step
    directions (ex. Click this, then click that) on what I need to do prior to clustering, as well as starting the clustering process. Please ask if you need additional information. 
    Thank You.

    I'm sorry. I'm such a noob. Should I have 3 virtual machines, where one is the domain controller and the other 2 are nodes? Or is it ok to just have 2 virtual machines?
    It's optional. You just need your both cluster nodes (VMs) belong to the same domain. It can be own domain serviced by your private VM or it can be "external" one. See:
    Using Guest Clustering for High Availability
    http://technet.microsoft.com/en-us/library/dn440540.aspx
    Active Directory domain requirements
    Failover clusters require that nodes of the same cluster are members of the same Active Directory domain. However, there is no requirement that a guest cluster belongs to the same Active Directory
    domain as the physical hosts on which the virtual machines are running.
    Also you'll need some shared storage. See (same URL as above):
    Storage options
    The following tables lists the storage types that you can use to provide shared storage for a guest cluster.
    Storage Type
    Description
    Shared virtual hard disk
    New in Windows Server 2012 R2, you can configure multiple virtual machines to connect to and use a single virtual hard disk (.vhdx) file. Each virtual machine can access the virtual hard disk
    just like servers would connect to the same LUN in a storage area network (SAN). For more information, see Deploy a Guest Cluster Using a Shared Virtual
    Hard Disk.
    Virtual Fibre Channel
    Introduced in Windows Server 2012, virtual Fibre Channel enables you to connect virtual machines to LUNs on a Fibre Channel SAN. For more information, see Hyper-V
    Virtual Fibre Channel Overview.
    iSCSI
    The iSCSI initiator inside a virtual machine enables you to connect over the network to an iSCSI target. For more information, see iSCSI
    Target Block Storage Overview and the blog post Introduction of iSCSI Target
    in Windows Server 2012.
    Shared VHDX is out as you don't have proper software (Windows 7 is not supported as a host and Windows 2008 R2 does not support shared VHDX as a guest), virtual Fibre Channel is out as you again don't have Windows Server 2012 R2 (and don't have any FC gear).
    So iSCSI is your only choice. Either spawn dedicated Windows (or other OS if you like UNIX) VM with iSCSI stack or use third-party Windows software running on your host. Windows Server 2008 R2 does not have iSCSI target embedded so you can get it here:
    MSFT iSCSI Target 3.3 Download
    http://www.microsoft.com/en-us/download/details.aspx?id=19867
    Good luck and happy clustering :)
    StarWind VSAN [Virtual SAN] clusters Hyper-V without SAS, Fibre Channel, SMB 3.0 or iSCSI, uses Ethernet to mirror internally mounted SATA disks between hosts.

  • Creating new cluster - Unable to create the cluster entry

    I'm trying to create cluster in a newly installed iAS 6.0 SP2. I fill
    out the form at /Administrator.apm and after submitting, cluster
    creation fails at "Adding the cluster entry in the configuration
    directory". I created a new slapd instance for this purpose (as
    outlined in ByuerXpert's installation guide).

    I'm trying to create cluster in a newly installed iAS 6.0 SP2. I fill
    out the form at /Administrator.apm and after submitting, cluster
    creation fails at "Adding the cluster entry in the configuration
    directory". I created a new slapd instance for this purpose (as
    outlined in ByuerXpert's installation guide).

Maybe you are looking for