locked
how to specify Deployment Admins from another domain in MSCRM 2011 RRS feed

  • Question

  •  I tried to add a new user from a different  forest as a Deployment Administrator (through the Deployment Manager) and it did not work.  It did not give an error, it just accepted the input and acted like it worked fine. It just didn't add them to the list.  I was successfully able to add a user from the same domain.

    I have gone through a blog where some workaround provided like establishing two-way trust to  to add deployment administrators from the other forest. But this workaround is not accepted in my project. 

    Is there any workaround?

    Wednesday, September 5, 2012 1:31 PM

All replies

  • At the very minimum it would need to be a one way trust between the domains.  This is by design. 

    The only other option would be to add that user to the local AD with the minimum permissions, and add him as a deployment admin locally.  I'm sure that they will not go for that option either.


    Jason Peterson

    Wednesday, September 5, 2012 5:37 PM
  • Hi,

    If you going add a user has Deployment Administrator means that user should be in local AD and user should be add in following groups.

    Group

    Description

    PrivReportingGroup

    Privileged Microsoft Dynamics CRM user group for reporting functions. This group is created during Microsoft Dynamics CRM Server Setup and configured during Microsoft Dynamics CRM Reporting Extensions Setup.

    PrivUserGroup

    Privileged Microsoft Dynamics CRM user group for special administrative functions; including CRMAppPool identity (domain user or NetworkService). The users who configure Microsoft Dynamics CRM Server 2011 must be added to this group.

    SQLAccessGroup

    All server processes/service accounts that require access to SQL Server; including CRMAppPool identity (domain user or NetworkService). Members of this group have db_owner permission on the Microsoft Dynamics CRM databases.

    ReportingGroup

    All Microsoft Dynamics CRM users are included in this group. This group is updated automatically as users are added and removed from Microsoft Dynamics CRM. By default, all Microsoft Dynamics CRM Reporting Services reports grant Browse permission to this group.


    Thanks & Regards, MS CRM Consultant, V.Surya. My Blog: http://inventcrm.wordpress.com/

    Thursday, September 6, 2012 4:29 AM
    Answerer