Jump to content


liquidcourage1

SCCM admin account on server

Recommended Posts

We are looking at a huge deployment of SCCM and I thought SCCM needed an account user that had domain administration rights. Is this incorrect?

 

What is the highest level of access this account needs within the domain? Keep in mind the following:

 

The server will take care of asset management, imaging (PXE), and patch management.

Share this post


Link to post
Share on other sites

the System Center Configuration Manager SMSadmin user only needs to be a Local Administrator of the SCCM server itself, no need to be a domain admin, that's overkill and a security risk

Share this post


Link to post
Share on other sites

We already had a group that granted local workstation admin rights to our deskside team which was enforced using a GPO. We put our SCCM service account in that group so we could deploy clients to a pre-existing environment after enabling certificates for native mode. Don't use this approach on a DC! That'll give the service account domain admin rights - just do a manual install on those machines. Once the client has been deployed across the domain you can remove this membership as long as you are deploying OS's using SCCM - the services run as Local System and SCCM will handle the new client installs for you during OS deployment. I recommend using a long complex password for the service account.

 

Basically the account needs to have enough rights to install the client on pre-existing machines (IF you aren't refreshing the OS using SCCM) and it needs local admin rights on the SCCM server and the remote SQL server (if applicable).

Share this post


Link to post
Share on other sites

tp install the client on existing machines you need a separate client push account, THAT account must be a member of the Local Administrators group on the machines you intend to install the client on

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.