<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Matt Goedtel on Operations Management : Operations Manager 2007, Active Directory MP</title><link>http://blogs.technet.com/mgoedtel/archive/tags/Operations+Manager+2007/Active+Directory+MP/default.aspx</link><description>Tags: Operations Manager 2007, Active Directory MP</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>ADMP and Tuning for Performance Reports</title><link>http://blogs.technet.com/mgoedtel/archive/2009/02/22/admp-and-tuning-for-performance-reports.aspx</link><pubDate>Mon, 23 Feb 2009 04:27:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3205535</guid><dc:creator>mgoedtel</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/mgoedtel/comments/3205535.aspx</comments><wfw:commentRss>http://blogs.technet.com/mgoedtel/commentrss.aspx?PostID=3205535</wfw:commentRss><description>&lt;P&gt;The latest Active Directory management pack deployment guide has a small section entitled "Enabling or Disabling Performance Data for Reports" and it was generating some good dialog internally between some colleagues and the product group.&amp;nbsp; This section recommends that you disable the Performance monitor for the class "Active Directory Domain Controller Server 200x Computer Role" in order to minimize performance data collection for reports.&amp;nbsp; However, this is a&amp;nbsp;base aggregate monitor that is basically&amp;nbsp;responsible for reflecting the best/worse case of health relative to the state of the child monitors.&amp;nbsp; It has no direct impact on controlling the behavior of the child monitors, nor performance collection in general.&lt;/P&gt;
&lt;P&gt;If you really want to disable performance data collection because reporting is not important to you, then you should be focusing on the performance collection rules.&amp;nbsp;&amp;nbsp;They are denoted as such with the words "performance collection" in the name of the respective rule.&amp;nbsp; Examples in the ADMP are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;AD Global Catalog Search Time Response Performance Collection &lt;/LI&gt;
&lt;LI&gt;AD DC Performance Collection - Metric Memory Committed Bytes&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;If you want to disable performance alerts because you are not concerned with certain performance issues with your DC's (as you may already know these facts and don't want to be constantly reminded), then you should be disabling the respective performance unit monitor.&amp;nbsp; Examples in the ADMP are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;AD DC Last Bind Monitor&lt;/LI&gt;
&lt;LI&gt;AD DC Op Master Domain Naming Last Bind Monitor&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3205535" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Operations+Manager+2007/default.aspx">Operations Manager 2007</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Management+Packs/default.aspx">Management Packs</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Active+Directory+MP/default.aspx">Active Directory MP</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Configuration/default.aspx">Configuration</category></item><item><title>Active Directory Management Pack - Replication Monitoring Account Permissions</title><link>http://blogs.technet.com/mgoedtel/archive/2007/11/22/active-directory-management-pack-replication-monitoring-account-permissions.aspx</link><pubDate>Fri, 23 Nov 2007 03:55:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2545638</guid><dc:creator>mgoedtel</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/mgoedtel/comments/2545638.aspx</comments><wfw:commentRss>http://blogs.technet.com/mgoedtel/commentrss.aspx?PostID=2545638</wfw:commentRss><description>&lt;P&gt;I have been monitoring some of the blogs lately in the management community and came across some entries around guiding customers with respect to properly configuring the Run As account for the Replication Monitoring Rule in the Active Directory Management Pack for Operations Manager 2007.&amp;nbsp; Unfortunately some of the recommendations I reviewed&amp;nbsp;were technically inaccurate.&amp;nbsp; My efforts here are to help clarify the specific permissions that need to be granted to the Replication Monitoring Run As Account.&amp;nbsp; Otherwise, the Replication Monitoring script will generate an alert indicating "Event ID 67&amp;nbsp;- Access Denied" in trying to create the Domain Controller object, the&amp;nbsp;replication container, or modify the attributes of the DC object.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&amp;nbsp; &lt;EM&gt;The latest version of the Active Directory management pack, version 6.0.6452.0 has changed the name of the replication container used for replication monitoring in Operations Manager.&amp;nbsp; It is now OpsMgrLatencyMonitors and was not pointed out in the ADMP deployment guide.&amp;nbsp; Therefore, this blog has been updated to reflect that name change and has been updated to recommend the appropriate minimum security rights that should be granted to the Run As account.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In order to monitor replication between domain controllers in the forest, the Active Directory Management Pack Guide instructs you to configure a domain account that will be used only for replication monitoring.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is found on page 10.&amp;nbsp; However, what is not clearly detailed are the partitions in Active Directory that you must ensure the security permissions are granted correctly for the replication monitoring account to allow it to modify the OpsMgrLatencyMonitors container within each of those partitions.&lt;/P&gt;
&lt;P&gt;By default, the Replication Monitoring script will monitor the Domain partition, and application partitions in the directory service.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The Configuration partition is not monitored by default and is optional.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The following steps must be completed to ensure the replication monitoring account has rights to modify the objects and attributes under the OpsMgrLatencyMonitors container:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;(Note:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Steps 2 and 3 are only necessary if you are using Microsoft DNS that is running on your domain controllers and configured with AD Integrated DNS.)&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 47.35pt; mso-list: l0 level1 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;1.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Set permissions for the Replication Monitoring Run As account on the Domain partition in each domain in the forest.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 47.35pt; mso-list: l0 level1 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&lt;/SPAN&gt;To do this, follow these steps on a domain controller in the domain:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Start&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Run&lt;/B&gt;, type &lt;B style="mso-bidi-font-weight: normal"&gt;Adsiedit.msc&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, right-click &lt;B style="mso-bidi-font-weight: normal"&gt;ADSI Edit&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Connect to&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;c.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Under &lt;B style="mso-bidi-font-weight: normal"&gt;Connection Point&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Select or type a Distinguished Name or Naming Context,&lt;/B&gt; type the following, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;:&lt;/P&gt;
&lt;P style="MARGIN: 6pt 0in 3pt 1.5in" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension&lt;/I&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;d.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, locate and right-click &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;CN=MOMLatencyMonitors,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension&lt;/I&gt;&lt;/B&gt; and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Properties&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;e.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions&lt;/B&gt; tab, click &lt;B style="mso-bidi-font-weight: normal"&gt;Add&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;f.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Enter the object name to select box&lt;/B&gt;, type the name of the replication monitoring Run As account, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Check Names&lt;/B&gt; to verify the name.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;g.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions Entry for OpsMgrLatencyMonitors &lt;/B&gt;dialog box appears.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;h.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Apply onto&lt;/B&gt; drop-down list, click &lt;B style="mso-bidi-font-weight: normal"&gt;This object and all child objects&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;i.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click to select the &lt;B style="mso-bidi-font-weight: normal"&gt;Allow&lt;/B&gt; check box for the&amp;nbsp;&lt;B style="mso-bidi-font-weight: normal"&gt;Read, Write, Create&amp;nbsp;All Child Objects&lt;/B&gt;&amp;nbsp;permission, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;j.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Advanced Security Settings for OpsMgrLatencyMonitors&lt;/B&gt; dialog box, click &lt;B style="mso-bidi-font-weight: normal"&gt;Apply&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;k.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Close the ADSI Edit window.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 47.35pt; mso-list: l0 level1 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;2.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Set permissions for the Replication Monitoring Run As account on the DomainDNSZones application partition in each domain in the forest.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To do this, follow these steps on a domain controller in the domain:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Start&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Run&lt;/B&gt;, type &lt;B style="mso-bidi-font-weight: normal"&gt;Adsiedit.msc&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, right-click &lt;B style="mso-bidi-font-weight: normal"&gt;ADSI Edit&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Connect to&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;c.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Under &lt;B style="mso-bidi-font-weight: normal"&gt;Connection Point&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Select or type a Distinguished Name or Naming Context,&lt;/B&gt; type the following, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=DomainDNSZones,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension &lt;/I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;d.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, locate and right-click &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;CN=OpsMgrLatencyMonitors,DC=DomainDNSZones,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension &lt;/I&gt;&lt;/B&gt;and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Properties&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;e.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions&lt;/B&gt; tab, click &lt;B style="mso-bidi-font-weight: normal"&gt;Add&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;f.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Enter the object name to select box&lt;/B&gt;, type the name of the replication monitoring Run As account, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Check Names&lt;/B&gt; to verify the name.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;g.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions Entry for OpsMgrLatencyMonitors &lt;/B&gt;dialog box appears.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;h.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Apply onto&lt;/B&gt; drop-down list, click &lt;B style="mso-bidi-font-weight: normal"&gt;This object and all child objects&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;i.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click to select the &lt;B style="mso-bidi-font-weight: normal"&gt;Allow&lt;/B&gt; check box for the&amp;nbsp;&lt;B style="mso-bidi-font-weight: normal"&gt;Read, Write, Create All Child Objects&lt;/B&gt;&amp;nbsp;permission, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;j.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Advanced Security Settings for OpsMgrLatencyMonitors&lt;/B&gt; dialog box, click &lt;B style="mso-bidi-font-weight: normal"&gt;Apply&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;k.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Close the ADSI Edit window.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 47.35pt; mso-list: l0 level1 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;3.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Set permissions for the Replication Monitoring Run As account on the ForestDNSZones application partition.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 47.35pt; mso-list: l0 level1 lfo1" class=MsoNormal&gt;To do this, follow these steps on a domain controller in the domain:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;a.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Start&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Run&lt;/B&gt;, type &lt;B style="mso-bidi-font-weight: normal"&gt;Adsiedit.msc&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;b.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, right-click &lt;B style="mso-bidi-font-weight: normal"&gt;ADSI Edit&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Connect to&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;c.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Under &lt;B style="mso-bidi-font-weight: normal"&gt;Connection Point&lt;/B&gt;, click &lt;B style="mso-bidi-font-weight: normal"&gt;Select or type a Distinguished Name or Naming Context,&lt;/B&gt; type the following, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;:&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=ForestDNSZones,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension &lt;/I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;d.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the task pane, locate and right-click &lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;CN=OpsMgrLatencyMonitors,DC=ForestDNSZones,DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain&lt;/I&gt;,&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;DC=&lt;I style="mso-bidi-font-style: normal"&gt;Domain_extension &lt;/I&gt;&lt;/B&gt;and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Properties&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;e.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions&lt;/B&gt; tab, click &lt;B style="mso-bidi-font-weight: normal"&gt;Add&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;f.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Enter the object name to select box&lt;/B&gt;, type the name of the replication monitoring Run As account, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;Check Names&lt;/B&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;to verify the name.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;g.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;Permissions Entry for OpsMgrLatencyMonitors &lt;/B&gt;dialog box appears.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;h.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Apply onto&lt;/B&gt; drop-down list, click &lt;B style="mso-bidi-font-weight: normal"&gt;This object and all child objects&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;i.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Click to select the &lt;B style="mso-bidi-font-weight: normal"&gt;Allow&lt;/B&gt; check box for the&amp;nbsp;&lt;B style="mso-bidi-font-weight: normal"&gt;Read, Write, Create All Child Objects&lt;/B&gt;&amp;nbsp;permission, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;j.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;In the &lt;B style="mso-bidi-font-weight: normal"&gt;Advanced Security Settings for OpsMgrLatencyMonitors&lt;/B&gt; dialog box, click &lt;B style="mso-bidi-font-weight: normal"&gt;Apply&lt;/B&gt;, and then click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;.&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 83.35pt; mso-list: l0 level2 lfo1" class=MsoNormal&gt;&lt;SPAN style="mso-list: Ignore"&gt;k.&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;Close the ADSI Edit window.&lt;/P&gt;
&lt;P&gt;Hopefully you find this helpful and it clarifies the permissions you need to grant to the Run As account specific to the&amp;nbsp;replication monitoring&amp;nbsp;container in the directory service.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt;&amp;nbsp; &lt;EM&gt;Once the replication monitoring script in the management pack creates an object for each DC and monitoring begins to operate under normal parameters, you can go ahead and remove the old replication monitoring container in the directory service - MOMLatencyMonitors from each domain in the forest and the applicable application partitions that was being monitored as well.&lt;/EM&gt;&amp;nbsp; &lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2545638" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Operations+Manager+2007/default.aspx">Operations Manager 2007</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Management+Packs/default.aspx">Management Packs</category><category domain="http://blogs.technet.com/mgoedtel/archive/tags/Active+Directory+MP/default.aspx">Active Directory MP</category></item></channel></rss>