I added the WSUS role to a completely new 2012 R2 VM. All available updates installed before adding the role. I set it to store updates locally on E:\WSUS
After the role has been added, Server Manager asks me to allow some "After Deployment Configuration tasks" to be done. I accept. However the action fails without any specific error. When I launch the WSUS Console it asks me for where to store updates.
The value I added earlier is already entered (E:\WSUS). I hit OK but after a while it fails and references a log file, see further down below.
I try to reinstall the role but with same problem.
I also tried to use C:\WSUS as the location but with the same error.
I have tried to add "Full access" for "Authenticated users" on the folder with no luck.
Thank you,
Jonas
Log file:
....
2015-07-31 15:11:11 Value is C:\WSUS
2015-07-31 15:11:11 Fetching group SIDs...
2015-07-31 15:11:11 Fetching WsusAdministratorsSid from registry store
2015-07-31 15:11:11 Value is S-1-5-21-2082564118-847745128-1538012364-1001
2015-07-31 15:11:11 Fetching WsusReportersSid from registry store
2015-07-31 15:11:11 Value is S-1-5-21-2082564118-847745128-1538012364-1002
2015-07-31 15:11:11 Creating group principals...
2015-07-31 15:11:11 Granting directory permissions...
2015-07-31 15:11:11 Granting permissions on content directory...
2015-07-31 15:11:11 Granting registry permissions...
2015-07-31 15:11:11 System.Security.AccessControl.PrivilegeNotHeldException: Processen saknar privilegiet SeSecurityPrivilege som krävs för denna åtgärd.
vid System.Security.AccessControl.Win32.GetSecurityInfo(ResourceType resourceType, String name, SafeHandle handle, AccessControlSections accessControlSections, RawSecurityDescriptor& resultSd)
vid System.Security.AccessControl.NativeObjectSecurity.CreateInternal(ResourceType resourceType, Boolean isContainer, String name, SafeHandle handle, AccessControlSections includeSections, Boolean createByName, ExceptionFromErrorCode exceptionFromErrorCode,
Object exceptionContext)
vid System.Security.AccessControl.RegistrySecurity..ctor(SafeRegistryHandle hKey, String name, AccessControlSections includeSections)
vid Microsoft.Win32.RegistryKey.GetAccessControl(AccessControlSections includeSections)
vid Microsoft.UpdateServices.Administration.ConfigurePermissions.GrantRegistryPermissions(IdentityReference identity, RegistryRights registryRights)
vid Microsoft.UpdateServices.Administration.ConfigurePermissions.GrantRegistryPermissions()
vid Microsoft.UpdateServices.Administration.PostInstall.Run()
vid Microsoft.UpdateServices.Administration.PostInstall.Execute(String[] arguments)