Permissions on original source file location

David Zemdegs 1,586 Reputation points
2020-08-21T00:35:39.077+00:00

When deploying an application, I copy the source files to a folder under a share, say \server\apps, and then distribute that content. Users installing the software get the source files from the DPs. What permissions are required on \server\apps? Im assuming its not Users-read? The reason I ask is that some clever users have found \server\apps and are installing software directly from it. I just want to check that if I remove users-read that it wont cause problems. Do any CM service accounts need access?
Thanks
David Z

Microsoft Configuration Manager
0 comments No comments
{count} votes

Accepted answer
  1. Amandayou-MSFT 11,051 Reputation points
    2020-08-21T03:22:01.73+00:00

    Hi,

    Thanks for posting in Q&A.

    The computer account for the systems hosting the SMS Provider needs read access to the location(s) specified. If we remove users-read, it will not cause problem. We could operate like this:

    Kindly check computer tab in the object types and enter the computer account in the check names tab. Here is the screenshot we could refer to:
    19302-8211.png
    19361-8212.png

    Hope my answer will help you.


    If the response is helpful, please click "Accept Answer" and upvote it.

    Best regards,
    Amanda You

    1 person found this answer helpful.
    0 comments No comments

2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,176 Reputation points Microsoft Employee
    2020-08-22T22:15:02.97+00:00

    Note that for driver and update packages, this account also needs write access.

    0 comments No comments

  2. David Zemdegs 1,586 Reputation points
    2020-08-25T02:17:10.12+00:00

    Why do the computer accounts need write access?
    Is this for all drivers and software updates?