Hyper-V 2012 R2 roles, access denied, failed to connect to service, AzMan....


hi all,

i have followed dozens of tutorials set roles hyper-v, keep coming short. have no problem managing 5 domain-joined 2012 r2 core hyper-v servers have remotely windows 8.1 pc, have lab box grant specific permissions desk users on.

the key tutorial have followed john howard (http://blogs.technet.com/b/jhoward/archive/2008/04/01/part-4-domain-joined-environment-hyper-v-remote-management-you-do-not-have-the-requested-permission-to-complete-this-task-contact-the-administrator-of-the-authorization-policy-for-the-computer-computername.aspx), still not allow non-admin account use hyper-v manager remotely. without tutorial, access denied "testuser" account. after following steps, hyper-v manager appears connect server, says "the virtual machine management service not available." using hvremote /show flag, shows passed.

digging deeper, see dozens of failed audit event viewer logs saying "testuser" requesting read service control manager. sent me searching, , found http://arnoutboer.nl/weblog/?p=300 and http://msdn.microsoft.com/en-us/library/windows/desktop/aa374928(v=vs.85).aspx. after granting "au" (authenticated users) every permission resembling "read", hyper-v manager shows "there no virtual machines show" (or along lines); though know there 30 vms on host. try create new vm (out of curiosity, , options appear), , permission denied immediately after the create vm wizard pops up.

why such convoluted process? appreciate creating roles hyper-v 2012.

thank in advance!

azman deprecated in 2012 , removed in 2012 r2. lot of wiring still there, such initialstore.xml, won't work.

what want buy scvmm.

one alternative option use hyper-v administrators group, going ok if want give people level of power. other option create custom powershell remote endpoints. built similar you're asking for, unfortunately can't share them because sold them publisher upcoming book. but, if follow through article series, it's not tough roll own.


eric siron
altaro hyper-v blog
independent blog contributor, not altaro employee. solely responsible content of posts.



Windows Server  >  Hyper-V



Comments

Popular posts from this blog

Error: 0x80073701 when trying to add Print Services Role in Windows 2012 Standard

Disconnecting from a Windows Server 2012 R2 file sharing session on a Windows 7,8,10 machine

Windows 2016 RDS event 1306 Connection Broker Client failed to redirect the user... Error: NULL