Permissions on original source file location

David Zemdegs 1,591 Reputation points
2020-08-21T00:35:39.077+00:00

When deploying an application, I copy the source files to a folder under a share, say \server\apps, and then distribute that content. Users installing the software get the source files from the DPs. What permissions are required on \server\apps? Im assuming its not Users-read? The reason I ask is that some clever users have found \server\apps and are installing software directly from it. I just want to check that if I remove users-read that it wont cause problems. Do any CM service accounts need access?
Thanks
David Z

Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Amandayou-MSFT 11,141 Reputation points
    2020-08-21T03:22:01.73+00:00

    Hi,

    Thanks for posting in Q&A.

    The computer account for the systems hosting the SMS Provider needs read access to the location(s) specified. If we remove users-read, it will not cause problem. We could operate like this:

    Kindly check computer tab in the object types and enter the computer account in the check names tab. Here is the screenshot we could refer to:
    19302-8211.png
    19361-8212.png

    Hope my answer will help you.


    If the response is helpful, please click "Accept Answer" and upvote it.

    Best regards,
    Amanda You

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,306 Reputation points Microsoft Employee
    2020-08-22T22:15:02.97+00:00

    Note that for driver and update packages, this account also needs write access.

    0 comments No comments

  2. David Zemdegs 1,591 Reputation points
    2020-08-25T02:17:10.12+00:00

    Why do the computer accounts need write access?
    Is this for all drivers and software updates?


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.