Logo
CAR REVIEW
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
PREGNANCY
 
 
Windows Server

Microsoft Systems Management Server 2003 : Creating Packages for Distribution (part 2) - Creating a Package from Scratch - Defining Access Accounts

4/15/2013 6:17:31 PM
Defining Access Accounts

By default, when SMS creates the SMSPKGx$ share, it grants Read access to the local Users group and Full Control to the Administrators group. The default Users and Administrators entries map to the local Users and Administrators groups for Windows distribution points. These accounts are known as generic package access accounts.

Since the default share is a hidden share, the only way a client should know that a package is available to it is through the package distribution process. In other words, the client agent will see an advertisement for that package that targets a collection the client is a member of. Bear in mind that users will be users, and it’s possible that they will find the hidden share, navigate to a package folder, and execute any programs they find there. This could also happen if you create your own shares.

There are a couple of ways to deal with this little breach of security. One would be for you to evaluate the share (or NTFS) security for the SMS shares or for the package folders within the share. This is a time-consuming and potentially destructive process if you happen to lock out SMS from accessing the share. The other solution is to define access accounts for the package through the SMS Administrator Console. When you define an access account, you also define the level of access or permission for the specified user or group. This is much like creating ACLs in Windows.

To define an access account, follow these steps:

1.
Navigate to the Packages folder, find your package entry, and expand it.

2.
Right-click Access Accounts, choose New from the context menu, and then choose the type of access account you want to create.

3.
The two types of access accounts are listed here:

  • Windows User Access Account —Defines a Windows user or group account and the level of permission to allow

  • Generic Access Account —Defines additional or replacement user, guest, or administrator accounts and the level of permission to allow that maps to an operating system–specific account

Select the appropriate option to display the Access Account Properties dialog box, shown in Figure 8.

Figure 8. The Access Account Properties dialog box.


4.
Click Set to specify the account information as follows:

  • For a Windows user account, the Windows User Account dialog box will appear, as shown in Figure 9. Enter the user or group account in \\Domain\user format, and select User or Group.

    Figure 9. The Windows User Account dialog box.

  • For a Generic account, the Generic Account dialog box will appear, as shown in Figure 10. Select the account type.

    Figure 10. The Generic Account dialog box.

5.
Click OK to return to the Access Account Properties dialog box. Select the appropriate level of permissions from the Permissions drop-down list, as shown in Figure 11. For most applications, Read permission will be sufficient. However, if the program requires any kind of writing back to the source directory, you’ll need to assign at least Change permission.

Figure 11. The Permissions list of the Access Account Properties dialog box.


6.
Click OK to create the account.
Other -----------------
- Microsoft Systems Management Server 2003 : Running Software Metering Reports
- Microsoft Dynamics GP 2010 : Improving performance by adjusting AutoComplete settings, Cleaning up Accounts Receivable with Paid Transaction Removal
- Microsoft Dynamics GP 2010 : Maintaining Dynamics GP - Preventing entry of wrong dates by Closing Periods
- Windows Server 2008 R2 : Creating and Administering Hyper-V Virtual Machines (part 2) - Installing the guest operating system
- Windows Server 2008 R2 : Creating and Administering Hyper-V Virtual Machines (part 1) - Virtual machine disk types
- Backup and Restore of Microsoft Lync Server 2010 : Backup Processes (part 2) - Backing Up the Central Management Store, Backing Up Lync Server Servers
- Backup and Restore of Microsoft Lync Server 2010 : Backup Processes (part 1) - Backing Up Lync Server Databases
- SQL server 2008 R2 : Creating and Managing Stored Procedures - Using Input Parameters
- SQL server 2008 R2 : Creating and Managing Stored Procedures - Modifying Stored Procedures
- Microsoft Dynamics Ax 2009 : RunBase Framework Extension (part 4) - Adding a Query
- Microsoft Dynamics Ax 2009 : RunBase Framework Extension (part 3) - Adding Property Methods, Adding Constructors
- Microsoft Dynamics Ax 2009 : RunBase Framework Extension (part 2) - Bike-Tuning Service Offers Example
- Microsoft Dynamics Ax 2009 : RunBase Framework Extension (part 1) - Property Method Pattern, Pack-Unpack Pattern
- Nginx HTTP Server : Basic Nginx Configuration - Testing your server
- Nginx HTTP Server : Basic Nginx Configuration - A configuration for your profile
- Windows Server : Network Access Policy and Server and Domain Isolation (part 4) - Planning NAP DHCP Enforcement, Domain and Server Isolation
- Windows Server : Network Access Policy and Server and Domain Isolation (part 3) - Planning NAP VPN Enforcement, Planning NAP 802.1x Enforcement
- Windows Server : Network Access Policy and Server and Domain Isolation (part 2) - Planning NAP IPsec Enforcement
- Windows Server : Network Access Policy and Server and Domain Isolation (part 1) - Network Access Protection Overview
- Monitoring Windows Small Business Server 2011 : Using Performance Monitor
 
 
Most view of day
- Windows Server 2003 on HP ProLiant Servers : Server Placement (part 2) - DC Placement, GC Placement
- SharePoint 2010 : Configuring Search Settings and the User Interface - Search Keywords
- SQL Server 2012 : Running SQL Server in A Virtual Environment - AN OVERVIEW OF VIRTUALIZATION
- Fine-Tuning MDT Deployments : Creating a Linked Deployment Share (part 1) - Understanding Linked Deployment Shares
- Managing Client Protection : User Account Control (part 3) - UAC Virtualization, UAC and Startup Programs, Compatibility Problems with UAC
- Client Access to Exchange Server 2007 : Getting the Most Out of the Microsoft Outlook Client - Security Enhancements in Outlook 2007
- Windows Phone 8 : Working with File Explorer (part 1) - Adding Media to Your Phone
- Windows Phone 7 Programming Model : Application Data Persistence
- Windows Phone 8 : Working with the Windows Phone Software (part 8) - Removing Multimedia Content - Removing Pictures from Your Phone
- Microsoft Dynamics Ax 2009 : RunBase Framework Extension (part 3) - Adding Property Methods, Adding Constructors
Top 10
- Windows Phone 8 : Scheduled Tasks - Scheduled Task API Limitations
- Windows Phone 8 : Scheduled Tasks - Updating Tiles Using a Scheduled Task Agent
- Windows Phone 8 : Scheduled Tasks - To-Do List Scheduled Task Sample (part 5) - Editing an Existing To-Do Item
- Windows Phone 8 : Scheduled Tasks - To-Do List Scheduled Task Sample (part 4) - Creating the To-Do Item Shell Tile, Saving a To-Do Item
- Windows Phone 8 : Scheduled Tasks - To-Do List Scheduled Task Sample (part 3) - Debugging Scheduled Tasks
- Windows Phone 8 : Scheduled Tasks - To-Do List Scheduled Task Sample (part 2) - TodoService, TodoItemViewModel
- Windows Phone 8 : Scheduled Tasks - To-Do List Scheduled Task Sample (part 1) - TodoItem,TodoDataContext
- Windows Phone 8 : Scheduled Tasks - Using Scheduled Tasks
- Windows Phone 8 : Scheduled Tasks - Background Agent Types
- Windows Phone 8 : Windows Phone Toolkit Animated Page Transitions - Reusing the Transition Attached Properties
 
 
Windows XP
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
2015 Camaro