Re: SMS client push error #5

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Kerwin Medina [MSFT] (kerwinm_at_online.microsoft.com)
Date: 02/04/05


Date: Fri, 4 Feb 2005 14:50:37 -0800

The push account also has to have admin rights to the site server machine
since it needs to read files from it and write to the log file.

"Donald" <Donald@discussions.microsoft.com> wrote in message
news:1A20C1CD-35D0-4FA1-8D49-EADC63F285F5@microsoft.com...
> Account does have admin rights to the machine im am trying to push.
>
> Logged in as xxxxx1, on the sms 2003 site server I can connect to
> \\techbackup65Admin$. I can also connect remotely to techbackup65
> registrey.
>
>
> "Jeff Harbaugh [MSFT]" wrote:
>
>> You need to create a client push installation account that has admin
>> rights
>> to the machine you are trying to install.
>> Error 5 is access denied.
>> --
>> Thanks,
>> Jeff Harbaugh [MSFT]
>> This posting is provided "AS IS" with no warranties, and confers no
>> rights.
>>
>> "Donald" <Donald@discussions.microsoft.com> wrote in message
>> news:B72F1789-C2B4-46BE-A011-B672BEA67C5A@microsoft.com...
>> > SMS 2003 running on my test network. Trying to get remote tools
>> > installed.
>> > Remote control agent does not appear on clients computer; but in the
>> > sms
>> > consol it shows that remote control is enabled.
>> >
>> > Remote control is enabled on the server side. Trying to force an instal
>> > to
>> > the client computer, this is what i get from the ccm.log in SMS
>> >
>> >
>> >
>> > code:
>> > --------------------------------------------------------------------------------
>> > Attempting to connect to administrative share '\\TECHBACKUP65\admin$'
>> > using
>> > account 'JCH.ORG\xxxxx1~ $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> WNetAddConnection2 failed (LOGON32_LOGON_NEW_CREDENTIALS) using
>> > account
>> > JCH.ORG\xxxxx1(00000005) $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> Lost local access after ImpersonateLoggedOnUser
>> > (LOGON32_LOGON_INTERACTIVE) using account JCH.ORG\xxxxx1
>> > $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> The 'best-shot' account has now succeeded 1 times and failed 1
>> > times.
>> > $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> Trying each entry in the SMS Client Remote Installation account
>> > list~
>> > $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> Attempting to connect to administrative share
>> > '\\TECHBACKUP65\admin$'
>> > using account 'JCH.ORG\xxxxx1~ $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> WNetAddConnection2 failed (LOGON32_LOGON_NEW_CREDENTIALS) using
>> > account
>> > JCH.ORG\xxxxx1 (00000005) $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> Lost local access after ImpersonateLoggedOnUser
>> > (LOGON32_LOGON_INTERACTIVE) using account JCH.ORG\xxxxx1
>> > $$<SMS_CLIENT_CONFIG_MANAGER>
>> >
>> > ---> Attempting to connect to administrative share
>> > '\\TECHBACKUP65\admin$'
>> > using account 'jch\xxxxx1'~ $$<SMS_CLIENT_CONFIG_MANAGER>
>> > -----------------------------------------------------------------------------------
>> > Logged in as xxxxx1 I can connect to computer's Admin$ from the site
>> > server.
>> > I aslo can connect the the computers registrey using regedt32 from the
>> > site
>> > server. Accounts are in the local admin accounts on the computer.
>> >
>> > Client is runnning Win2k Sp 4; Server is running Win2k Server Sp4.
>> >
>>
>>
>>



Relevant Pages

  • Re: SMS Remote Installation Account and Client Push Installation Wizard
    ... domain admin account for your push account. ... The secondary site only has the option to do site wide push installation. ... Enabling client push installation on the general tab will allow the site ...
    (microsoft.public.sms.admin)
  • Re: troubles with Advansed client install
    ... Have you defined a push account with admin rights ... Do I need to create this account myself or should sms do it for me? ... be clear on exactly where I'm talking about: Site settings> client ...
    (microsoft.public.sms.admin)
  • Re: Must the SMS client be installed at a domain member computer?
    ... > any local admin-level account) as one of the Client Push Installation ...
    (microsoft.public.sms.setup)
  • RE: Securing the media server
    ... The second issue is that when I tell the encoder to copy the settings of the publishing point that I set up for Encoder Push, it doesn't see to copy the anonymous user that is used. ... > it to an account of your liking, but you will need to fix ... The server would then attempt to use negotiate ...
    (microsoft.public.windowsmedia.server)
  • Re: Removing Local Admin Accounts - What do you think?
    ... people the necessary admin rights on the workstations, ... The local admin account poses a high risk in terms of workstations ... Does this pose a security risk to have a local administrator account on ... Is this a general best practice, from a security point of view? ...
    (Security-Basics)