This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Cannot open Enterprise Console

We have recently installed a new domain controller server, with Enterprise Console currently remaining on the old but disabled DC (SBS2008).

Old server has also had AD removed.

The plan is to migrate Sophos to the new DC server, but cannot get into Enterprise Console to backup etc.

Latest error being  ‘In order to run the enterprise console you need to be a member of the Sophos console administrators group and have Dcom access by being a member of the distributed com users group’. The local administrator is a member of all local Sophos groups and also Dcom Users Group.

Would appreciate any thoughts on how to get access to Enterprise Console, or resolve the supposed rights issues as above.

Thanks in advance

Derek



This thread was automatically locked due to age.
  • Hello Derek,

    first of all, a backup (using DataBackupRestore.exe) is done from outside the console. Nevertheless you might encounter the error mentioned in the article - can't say whether the backup completely fails in this case. Is the database local?

    Installing on a DC is not recommended (although there might not be an alternative in small environments - Sophos Central could be an option, BTW). It's definitely not a good idea to demote a DC where SEC is installed.

    Can't say what actually causes the error - are the services running and is SUM still working (i.e. updates are downloaded)? If so, you have some breathing space. question is, what do you actually need from the old installation? How many endpoints, how many policies that would be hard to recreate (e.g device control exemptions)?

    Christian

  • Hi Christian,

     

    Many thanks the prompt response.

    Reason for the new install on a DC is purely size based. Maximum of 20-25 endpoints, and SUM currently pushing out to existing endpoints, but not new connections.

    From your comments, would probably be a better option to go for a clean install on our new server, although would it also be possible to import settings from a backup.

     

    Derek 

  • Hello Derek,

    guess you can successfully use Protect Computers in your AD environment.
    The backup contains the groups, policies, and the endpoints' history. If you don't need the latter I'd suggest a clean install. Which SEC version are you using right now, BTW?

    Christian

  • Hi Christian,

    Sophos support are going down the route of a fresh SEC install remotely on the new server.

    Thanks for your responses.

    Derek