locked
CRM Account RRS feed

  • Question

  • We used a CRMADmin account to install CRM 2011 on our servers, we want to keep using that account for production deployment. However we wish to create a dev account to work in development.

    I have ran into issues where I need to grant this account access as deployment manager , OS admin etc etc. I think there might be more needed with the database and possibly in whatever ad groups CRM might have created in installation.

    Is there a list of action or permissions I need to ensure I have to work with this dev account in order to apply rollups etc.

    your help is greatly appreciated.

    Wednesday, June 19, 2013 7:22 PM

Answers

  • When CRM is installed, several AD groups are created but you do not need to manage the membership of those groups (apart from a few situations which are described in the Implementation Guide).

    Applying update rollups requires local administrator privileges on the computer.

    Performing tasks in Deployment Manager requires a user to be a deployment administrator. See my earlier answer for more info on that.

    There is no need to give access to SQL Server (apart from when installing CRM) because the permissions are managed via the AD groups.

    • Marked as answer by live4help Thursday, July 11, 2013 6:19 PM
    Tuesday, June 25, 2013 9:29 PM
    Moderator

All replies

  • I'm not sure whether you are asking about setting up CRM on another server or creating more organisations in an existing deployment.

    For the latter, only deployment administrators can create and manager organisations and only deployment administrators can add/removed deployment administrators. The account that was used to install CRM will be the only deployment administrator to start with so you must login using that account to add more deployment administrators.

    Wednesday, June 19, 2013 9:48 PM
    Moderator
  • I'm talking about an account taking over the maintenance of that environment, so new orghanization or updating rollups

    Basically looking for an understanding of a list of items that I need granted to that new account.

    -Deployment Manager

    -Database Permission I.E Create , delete tables

    I was also under the impression that when you install a new instance of CRM, changes are made to AD (adding groups) etc for that account. Is there something there I need to be aware of in order to

    accomidate the new maintenance account to look after the development enviornment.

    I hope I was able to clarify a little better

    Thursday, June 20, 2013 2:37 PM
  • When CRM is installed, several AD groups are created but you do not need to manage the membership of those groups (apart from a few situations which are described in the Implementation Guide).

    Applying update rollups requires local administrator privileges on the computer.

    Performing tasks in Deployment Manager requires a user to be a deployment administrator. See my earlier answer for more info on that.

    There is no need to give access to SQL Server (apart from when installing CRM) because the permissions are managed via the AD groups.

    • Marked as answer by live4help Thursday, July 11, 2013 6:19 PM
    Tuesday, June 25, 2013 9:29 PM
    Moderator
  • The new dev user that you create should be provided System Administrator Role in CRM and added as a Deployment Manager and the new user would be able to support your CRM Install.

    Rest as Feridun mentioned is taken care of by CRM directly and no explicit permission need to be provided in SQL or AD.

    HTH

    Sam


    Dynamics CRM MVP | Inogic | http://inogic.blogspot.com| news at inogic dot com

    If this post answers your question, please click "Mark As Answer" on the post and "Mark as Helpful"

    Wednesday, June 26, 2013 3:42 AM