Skip to content
SCCM AD Accounts Used by ConfigMgr

SCCM AD Accounts Used by ConfigMgr

Written By Anoop C Nair
Last Updated August 7, 2024
Posted In SCCM
SHARE

SCCM AD Accounts Used by ConfigMgr? Have you ever tried understanding the functionality of AD accounts used in ConfigMgr? We need to do more Planning in AD account allocation for Configuration Manager 2012, 2007, and 2012.  

What important points must we understand before performing AD accounts allocation for CM 2012? First and foremost, we need to understand the functionality of each account. One perfect example is below.

Wrong account allocation can result in unexpected behavior in the environment. Recently, I was asked to troubleshoot a cross-forest client communication issue.

Finally, the issue was caused by the wrong account allocation. I’ll provide more details on this issue in the next post.

Patch My PC

SCCM AD Accounts Used by ConfigMgr

SCCM AD Accounts Used by ConfigMgr - Fig.1
SCCM AD Accounts Used by ConfigMgr – Fig.1

The Active Directory Forest Account is used to discover network infrastructure from Active Directory forests. CAS and primary sites also use this account to publish site data to the AD forest.

This account must have full control permissions to access the System Management container and all its child objects in each Active Directory forest where you want to publish site data. SCCM AD Accounts are used by the ConfigMgr Endpoint Manager.

AD account details are explained in the GitHub article. However, it’s not very easy to find these details. Download the PDF file, which will provide you with the details in the following format. Account Name, Details about the Account usage, functions, and Permission requirement.

10 other very important points that we need to remember as SCCM/ConfigMgr administrators are given below.

1. AD Group Discovery Account: Distribution groups are not discovered as group resources.

2. Capture Operating System Image Account: Do not assign this account interactive logon permissions. Do not use the Network Access account for this account. SCCM AD Accounts Used by ConfigMgr

3. Client Push Installation Account: Do not grant this account the right to log on locally.

4. Health State Reference Querying Account, Management Point Database Connection Account, Multicast Connection Account: Do not grant this account interactive logon rights.

5. Network Access Account: Do not grant this account interactive logon rights or the right to join computers to the domain. If you must join computers to the domain during a task sequence, use the Task Sequence Editor Domain Joining Account. SCCM AD Accounts Used by ConfigMgr

6. Package Access Account: You do not have to add the Network Access Account as a Package Access Account.

7. Software Update Point Connection Account: The Site System Installation Account can install components for software updates but cannot perform software update-specific functions on the software update point. If you cannot use the site server computer account for this functionality because the software update point is in an untrusted forest, you must specify this account in addition to the Site System Installation Account. SCCM AD Accounts Used by ConfigMgr

8. Site System Installation Account: Configuration Manager also uses the Site System Installation Account to pull data from the site system computer after installing the site system and any site system roles. Each site system can have a different Site System Installation Account. Still, you can configure only one Site System Installation Account to manage all site system roles on that site system. SCCM AD Accounts Used by ConfigMgr

9. Task Sequence Editor Domain Joining Account: Do not assign this account interactive logon permissions or use the Network Access Account for it.

10. Task Sequence Editor Network Folder Connection Account: Do not assign this account interactive logon permissions or use the Network Access Account for it.

Resources

Free SCCM Training Part 1 | 17 Hours Of Latest Technical Content | ConfigMgr Lab HTMD Blog (anoopcnair.com)

How To Disable SCCM Application Deployment | ConfigMgr | MEMCM – HTMD Blog #2 (howtomanagedevices.com)

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here – HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His primary focus is Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 3 comments

  1. Hi good doc on the AD accounts and restrictions.. I have been wondering for a long time which account is being used while taking remote control? Is it network access account?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read