OpsMgr 2007: Agents connect to the wrong management server and generate 20064 events


Here’s a great tip sent to me by Sam Allen, one of the top Support Escalation Engineers in our Texas office.  If you find that some of your agents are reporting to the wrong server or are generating OpsMgr Connector sourced 20064 events then this is something you’ll definitely want to check out at:

========

Issue: After enabling AD integration in SCOM 2007, agents start getting 20064 events similar to the following:

Event Type: Warning
Event Source: OpsMgr Connector
Event Category: None
Event ID: 20064
Description:  The OpsMgr Connector has found multiple primary relationships in Active Directory for management group <group>. The primary relationship to <ServerName> has been ignored and treated as a secondary relationship; <OtherServerName> is the accepted primary. To address this issue, you can add an exclusion to the Active Directory assignment rule for the incorrect primary relationship.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Cause: This is caused by improper permissions on the container in Active Directory (AD).  The way an agent determines which management group and server it should report to is by the permissions on the containers.  On the MOM Team product group blog they discuss the correct permissions that should exist:

http://blogs.technet.com/momteam/archive/2008/01/02/understanding-how-active-directory-integration-feature-works-in-opsmgr-2007.aspx.

Resolution: Ensure that the proper permissions exist for all containers which are inherited by the Operations Manager containers.  Typically the easiest way to do this is set the proper permissions at the root level container (OperationsManager in AD) then remove and re-add it using the MOMADAdmin tool.

More Information: I recently worked and issue where Read permissions for Authenticated Users had been given to all the OperationsManager containers.  The result was that all computers could read the information and therefore thought that they should report to those machines. To fix this we removed Authenticated Users from the root folder and forced that change down the hierarchy.  We then used the MOMADAdmin tool to remove the container (the root OperationsManager container remained) and then re-added it.  Once we did this the permissions were correct and agents only reported to the correct servers.

========

Thanks Sam!

J.C. Hornbeck | Manageability Knowledge Engineer

Comments (2)

  1. show box says:

    Thanks for the great info. I really loved this. I would like to apprentice at the same time as you amend your web site, how could i subscribe for a blog site?
    For more info on showbox please refer below sites:
    http://showboxandroids.com/showbox-apk/
    http://showboxappandroid.com/
    Latest version of Showbox App download for all android smart phones and tablets.
    http://movieboxappdownloads.com/ – It’s just 2 MB file you can easily get it on your android device without much trouble. Showbox app was well designed application for android to watch movies and TV shows, Cartoons and many more such things on your smartphone.
    For showbox on iOS (iPhone/iPad), please read below articles:
    http://showboxappk.com/showbox-for-ipad-download/
    http://showboxappk.com/showbox-for-iphone/
    Showbox for PC articles:
    http://showboxandroids.com/showbox-for-pc/
    http://showboxappandroid.com/showbox-for-pc-download/
    http://showboxforpcs.com/
    There are countless for PC clients as it is essentially easy to understand, simple to introduce, gives continuous administration, effectively reasonable. it is accessible at completely free of expense i.e., there will be no establishment charges and after establishment
    it doesn’t charge cash for watching films and recordings.
    http://www.showboxforipad.org/showbox-apk/ Not simply watching, it likewise offers alternative to download recordings and motion pictures. The accompanying are the strides that are to be taken after to introduce Showbox application on Android. The above
    all else thing to be done is, go to the Security Settings on your Android telephone, Scroll down and tap on ‘Obscure sources’.
    http://www.showboxforipad.org/
    http://movieboxappdownloads.com/moviebox-apk-android/
    http://movieboxappdownloads.com/download-moviebox-pc/
    Movie Box, an esteemed movies application in which you can find stacks of programs and films. The guide is given here to download Movie Box app to Android and to Apple iOS 9.0.2, iOS 8.4/8.3 and also for the lower versions without Jailbreak.
    http://showboxforiphone.org/
    Please do login to Showbox application with the help of Ymail. You can login in Ymail from here –
    http://ymaillogintips.com/
    Sign Up & Do registration for latest movies on Showbox application