Local accounts after joining domain

I have installed DV and joined the domain on my Proplus. I'm not quite sure what to do with the Emerson and Administrator accounts now. The Administrator account gets disabled during installation. Emerson is just a local account. I did the complete install logging in with my domain admin credentials. What is the typical application?  When I first tried logging in after install.. I could log in with any account, but in order to get to windows desktop, i had to use the domain admin account. I don't know why the administrator (after enabling) or the Emerson account wouldn't work. 

In the past with workgroups we would primarily use Administrator for well, admins that could get to windows desktop and then a SUPER account that did not have admin privileges and would only be good for DeltaV logon.  

I'm not sure what best practices are with this setup. Oh, i have v15 on a R660 server 2022. I have 2 IDDCs. 

Thanks

19 Replies

  • In reply to Lun.Raznik:

    Assuming you are still using IDDC when you re-installed DeltaV, few questions:
    - Did you clean-up DNS and AD before you re-install DeltaV?
    - If you are using supported hardware and OS image, there should be a local "emerson" account that you can use to login locally. Login using Emerson and inspect Event Viewer.

    Also, is someone else owning "IDDC"? If yes, can you verify that the admin didn't make any changes to policies as applied by DeltaV? If they made changes, then all bets are off. Talk to your IDDC admin and have them figure it out.
  • In reply to Lun.Raznik:

    v15fp1
    yes, redundant IDDCs
    yes, it's a newer machine, not a concern

    I was able to get to the point of running workstation config after reinstall. But, then it wouldn't accept my services account password. Which is nonsense, because I know it's correct. I ran ServPwd on the Proplus and also updated the DeltaVAdmin password on the IDDC in active directory, reboooted everything. This didn't help my workstation accepting the password. So, i said, okay reboot. When it came back.. it started DeltaV and even let me login with a domain user. However, DeltaV Live is grayed out on FlexLock. So, no good. Oh, and yes i donwloaded the workstation in explorer. Also, all hell has broken lose on Live Administration.

    I have a few other issues going on in parallel so it's kind of hard to track this all down in a thread. One issue leads to another leads to another..
  • In reply to TreyB:

    Provided you have Guardian support, don't hesitate to contact the GSC for assistance. Most domain installations work just fine and offer a lot of security and global user administration advantages that you just can't do with a work group. The GSC has experience helping with domains.
  • In reply to Randy Pratt:

    they haven't been very helpful.

    i reinstalled DeltaV again... 3rd or 4th time. This time i made sure before i did anything that my NICs showed the domain rather than unidentified network. Seems to have helped some. Still couldn't accept my services account password, so i log out when that fails and it seems to not care. Then I have to run Servpwd. Once I reboot, FileServer won't start. It was throwing errors. I ended up doing the following:

    dism /online /cleanup-image /restorehealth

    That cleaned up some corrupted files related to .NET framework.

    Then Another service RTS.CoreService wouldn't start. I don't know how i fixed that one. But, after that the rest of the services, namely ADDB was able to start.

    I still have other issues, but my services seem happy at the moment.

    I have a ticket open for my other problems.