Supported hypervisor platforms, Active directory (ad), Domain user accounts – Dell XC Web-Scale Converged Appliance User Manual

Page 9: Distributed key management container, 3 supported hypervisor platforms, 4 active directory (ad), 1 domain user accounts, 2 distributed key management container

Advertising
background image

9

Wyse Datacenter Appliance XC for vWorkspace

2.3

Supported Hypervisor Platforms

The hypervisor used in this solution can be Microsoft Windows Server 2012 R2 with Hyper-V role or
VMware vSphere 5.5 GA (not Update 1 or Update 2).

2.4

Active Directory (AD)

Active Directory is required for this solution; however, configuration of AD is beyond the scope of this
document except where noted. DNS is required for name resolution. All Windows servers must belong to
the same AD domain.

2.4.1

Domain User Accounts

We recommend creating domain accounts to be used specifically for SQL and System Center Virtual
Machine Manager (SCVMM) services as opposed to using local system accounts.

SCVMM service account requirements:

The domain account must be a member of the local administrators group on the VMM
management server.

You cannot change the service account after installation. To change it, you must uninstall and then
reinstall SCVMM.

SCVMM RunAs account: Used to perform administrative tasks on systems from VMM.

SQL:

Service account: It is recommended to run SQL Server and related services under a domain
account (or multiple domain accounts) with minimum privilege needed to run.

SQL administrators: domain account, group, or both with administrative access to the SQL server
and databases.

2.4.2

Distributed Key Management Container

VMM encrypts some data in the VMM database, and therefore, we recommend storing the encryption keys
in AD DS by using distributed key management instead of locally on the VMM management server. To set
up the necessary AD container, complete the following tasks:

1. Start ADSI Edit, right-click the root folder, select Connect To, and then click OK.
2. Select the root folder that represents AD domain structure. This should be labeled with a prefix

of DC=.

Advertising