Azure / ArcEnabledServersGroupPolicy

Guidance and sample code to perform at-scale onboarding of servers to Arc via Group Policy
MIT License
9 stars 15 forks source link

Read-only Domain Controllers can't register using these scripts #23

Open endreigesund opened 11 months ago

endreigesund commented 11 months ago

Read-only Domain Controllers are not part of the groups "Domain Controllers" or "Domain Computers". They have their own group called "Read-only Domain Controllers".

Because of this those computers don't have permissions on the deployment folders nor permissions to decrypt the encrypted secret. Managed to onboard them using a modified version of the script, including this group and sid.