Search This Blog

Wednesday, February 12, 2014

add remove access role to server 2012 R2 got error "Please restart your computer to finish update"

this is confusing as I tried to add remove access role, then I restarted the server many times, I still got this error.
“The request to add or remove features on the specified server failed. the operation cannot be completed because the server that you specified requires a restart.”
the event logs shows
  • The MSSQL$MICROSOFT##WID service was unable to log on as NT SERVICE\MSSQL$MICROSOFT##WID with the currently configured password due to the following error:
    Logon failure: the user has not been granted the requested logon type at this computer.
    Service: MSSQL$MICROSOFT##WID
    Domain and account: NT SERVICE\MSSQL$MICROSOFT##WID
    This service account does not have the required user right "Log on as a service."

google search had some links
http://social.technet.microsoft.com/Forums/windowsserver/en-US/ae2baa1b-3aba-4d84-9a3c-0588b9a0f298/wsus-roles-install-on-server-2012-fails?forum=winserverwsus

http://support.microsoft.com/kb/2832204

http://social.msdn.microsoft.com/Forums/en-US/12d973bd-7210-48dc-95cb-d732da03eac9/windows-internal-database-and-log-on-as-a-service-on-windows-server-2012-vm?forum=WAVirtualMachinesforWindows
http://eskonr.com/2013/06/wsus-role-failed-on-windows-server-2012-with-error-the-operation-cannot-be-completed-because-the-server-that-you-specified-requires-a-restart/

resolution :

  • Assign the Log on as a service user right to NT SERVICE\ALL SERVICES in the GPO that defines the user right.
  • Exclude the computer from the GPO that defines the user right.  ( I am not sure about this)

so I checked domain policy , domain controller policy ( as I tried to setup pptp server on the 2012 R2 DC), the problem persists,
then do secpol.msc, I noticed NT SERVICE\ALL SERVICES is listed under denied logon as a service.
I manually remove the NT SERVICE\ALL SERVICES from the denied-list; WID sucessfully install, so is remote access role

interestingly, is there a local security policy on a domain controller ?




2 comments: