question

CharlesWhite-0188 avatar image
0 Votes"
CharlesWhite-0188 asked saldana-msft edited

Multiple ConfigMgr Remote Control Users groups in ADUC

Hi all,

Not sure what is going on. But I have about 137 groups named "ConfigMgr Remote Control Users\0ACNF:<ObjectGUID>" It looks like they are from SCCM updates but not every update has created them. The oldest one is from 5/23/2014. The newest ones are from 5/26/2020 (there are 47 of this one.).

Are the ones with the guid safe to delete? What could cause these?

SCCM is up to date with the current branch.
Version 2103
Site Version 5.0.9049.1000

Domain is 2012 R2 functional level

windows-active-directorymem-cm-general
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

This is an AD replication issue and is unrelated to ConfigMgr directly.

0 Votes 0 ·

1 Answer

SimonRenMSFT-3639 avatar image
0 Votes"
SimonRenMSFT-3639 answered Jason-MSFT commented

Hi,

Thanks for posting in Microsoft MECM Q&A forum.

Per my experience, you could safely delete these 137 unnecessary groups. Configuration Manager remote tools use only the Configuration Manager Remote Control Users group to store the accounts and groups that you set up in the Permitted Viewers list. The site assigns this list to each client.

Bset regards,
Simon


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
https://docs.microsoft.com/en-us/answers/articles/67444/email-notifications.html

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

I delete the groups and everything still seems to be working. I was thinking that should be the fix but I wanted to make sure before I started deleting anything.

Thank you
Charles

0 Votes 0 ·

You're only fixing a symptom here. The root cause is your AD replication so you still need to address that.

0 Votes 0 ·