Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-5205: Device enrollment fails even when using a service account with full permissions to run the Cloud Connector

Centrify Identity Service, App Edition ,  

12 April,16 at 11:14 AM

Applies to: Centrify for Mobile

Problem:

When using a Service Account that has been granted full permissions to the OU specified for enrollment, device enrollment fails with the the following error found in the Cloud Connector log: 

 
CreateMachineForDevice Exception: System.UnauthorizedAccessException: Access is denied. 


​Cause: 

This error is presented due to a lack of permissions for the Service Account to the OU.  When a service account is specified to run the Cloud Connector service, the account is not automatically configured for proxy permissions on the OU.  


Resolution:

In order to grant the missing permissions for the account to the OU, the following steps will need to be taken:
  1. Open up ADSI Edit:​
    • Start > All Programs > Administrative Tools > ADSI
  2. ​Navigate to the OU in question, right-click on the OU and choose "Properties"
    • User-added image
  3. ​Navigate to > "Security" > "Advanced"
    • User-added image
  4. Under the "Permissions" tab navigate to the Service Account and click "Edit..."
    • User-added image
  5. In the "Apply to:" drop-down box, choose "This object and all descendant objects"
    • User-added image
  6. Click "OK" and then "Apply" on the Advanced Security Settings window.

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.