Export (0) Print
Expand All

About Package Access Accounts

Updated: July 1, 2009

Applies To: System Center Configuration Manager 2007, System Center Configuration Manager 2007 R2, System Center Configuration Manager 2007 R3, System Center Configuration Manager 2007 SP1, System Center Configuration Manager 2007 SP2

By default, when Configuration Manager 2007 creates the package share on a distribution point, it grants Read access to the local Users group and Full Control to the Administrators group. However, it is often useful to exercise greater control over who can access the packages on this share, and package access accounts provide that means.

Package access accounts enable you to set permissions to specify the users and user groups that can access a package folder. In this way, if packages contain sensitive data or should otherwise have restricted access, you can configure package access accounts to limit access to specific users and user groups. If a client does not have sufficient rights to the package folder, the advertised programs within the package will not run.

noteNote
When adding a new access account or modifying an existing one, it's highly recommended that you refresh all distribution points associated with your package to ensure that the current access account information will be propagated to each distribution point.

Two types of access accounts are available:

  • Windows User Access Accounts- This account defines a Windows User or group account and specifies the level of permissions assigned. Windows User access accounts are specified using the Windows Account dialog box.

  • Generic Access Accounts- This account defines additional or replacement user, guest, or administrator accounts and specifies the level of permissions assigned, mapping them to an operating system-specific account. Generic access accounts are specified using the Generic Account dialog box.

The following permissions can be specified for users and user groups:

 

Permission Description

No Access

Prevents the account from reading, writing, or deleting files on the package share.

Read

Enables the account to view and copy files, run programs, change folders within the shared folder, and read extended attributes of files.

Change

Enables the account to change the contents and extended attributes of files and to delete files. Change permission is required for applications that need to write information back to the shared package folder on the distribution point.

Full Control

Enables the account to view or change the contents and extended attributes of files. This includes all rights specified by both the Read and Change permissions.

ImportantImportant
If you remove the Administrators default account, Configuration Manager 2007 components cannot update and modify the package data.

See Also

For additional information, see Configuration Manager 2007 Information and Support.
To contact the documentation team, email SMSdocs@microsoft.com.
Was this page helpful?
(1500 characters remaining)
Thank you for your feedback

Community Additions

ADD
Show:
© 2014 Microsoft