Skip to content
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access

How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access

Written By Anoop C Nair
Last Updated July 25, 2024
Posted In SCCM
SHARE

Today, I will discuss how to Verify WMI Permissions Required for ConfigMgr SCCM Console Access.

We will see how to check and confirm the WMI permissions Required for SCCM / ConfigMgr console access. Also, here are some handy links that can help you with console-related troubleshooting.

Index
WMI Permissions Required for ConfigMgr SCCM Console Access
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Table 1

WMI Permissions Required for ConfigMgr SCCM Console Access

Log file to look into SMSADMINUI.log. Location -> \Program Files\Microsoft Configuration Manager\AdminConsole\AdminUILog

  • Run wmimgmt.msc from the primary site server.
  • Go to WMI control –> properties
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access - Fig.1
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Fig.1

In the Security tab, expand root, and click SMS.

Patch My PC
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access - Fig.2
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Fig.2

Click security in the results pane to see the permission.

How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access - Fig.3
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Fig.3

Click Advanced, click SMS Admin, then view-edit.

How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access - Fig.4
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Fig.4

Grant the permission if the SMS Admins group does not have Enable Account and Remote Enable permission.

How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access - Fig.5
How to Verify WMI Permissions Required for ConfigMgr SCCM Console Access – Fig.5

Repeat this procedure for other groups used in addition to SMS Admins.

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and leader of the Local User Group Community. His main focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc..

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion · 8 comments

  1. Sccm primary site join to aaa.local and Added a security group to this sms admin local group, however the members (members comprise of aaa.local and bb. aaa.local) in that security group but members from bb.aaa.local are unable to access the console too. Any clue?

  2. It use to be working well, however we have restore the wsus dbs and that caused the issue.

    Yes aaa and bbb is a parent-child domain.

  3. We have tried to access from the same laptop that aaa.local users were able to access. But not for user from bbb.aaa.local

  4. Please note that if the June 2022 monthly patches were applied you might see “Access is Denied” or “You have typed invalid credentials” from Get-WmiObject in WinRE based systems. Using wbemtest you might see “0x8007005” “Access is denied” message. (i.e. WinRE -> MECM query)

    See the following change to DCOM protection that went life with June’s patches:

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-26414

    “…The security updates released on June 8, 2021 enable RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM clients by default and provide full protection after manually setting RequireIntegrityActivationAuthenticationLevel = 1 on DCOM servers using the steps in Managing changes for Windows DCOM Server Security Feature Bypass (CVE-2021-26414). Note that a reboot is required after making any changes to the RequireIntegrityActivationAuthenticationLevel registry key. Microsoft recommends enabling full protection as soon as possible to identify any OS and application intermobility issues between Windows and non-Windows operating systems and applications.

    With the June 14, 2022 security updates, RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM servers is now enabled by default. Customer who need to do so can still disable it by using the RequireIntegrityActivationAuthenticationLevel registry key.”

  5. While the workaround (of setting RequireIntegrityActivationAuthenticationLevel = 1) did resolve the issue. A more permanent fix is to uninstall the ADK and install the latest ADK which includes the new WinRM image w the fix/patch already baked in.

  6. I had the same issues launching the SCCM console on a particular machine and spent countless hours trying to fix until I came across this article
    In one posting here someone talks about June 2022 updates which enabled RPC_C_AUTHN_LEVEL_PKT_INTEGRITY on DCOM clients .
    What I did was running the latest July updates on this machine and the problem went away. The SCCM console is fully operational for me now. Thank you very much to all of you who commented on this post.

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws

Key Takeaways Windows 11 KB5101650 KB5099414 July 2026 Patch and 3 Zero Day Vulnerabilities and 570 Flaws! In the July 2026 Patch, Microsoft introduced new features designed to improve the overall Windows experience. The update adds enhancements to Windows Update for more flexible update management and introduces Point-in-Time Restore, providing an additional recovery option for […]

AC Anoop C Nair 9 min read
Intune

2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws

Key Takeaways 2026 June KB5094126 KB5093998 Windows 11 Patch | 3 Zero Day Vulnerabilities and 200 Flaws! The June 2026 Windows 11 Patch Tuesday update brings several improvements to File Explorer. It adds support for additional archive formats, including UU, CPIO, XAR, and NuGet Packages (NUPKG). The update also preserves View and Sort preferences in […]

AC Anoop C Nair 10 min read
Intune

2026 May KB5089549 KB5087420 Windows 11 Patch | 0 Zero Day Vulnerabilities and 120 Flaws

Key Takeaways The Windows 11 May 2026 Patch KB5089549 KB5087420 Update brings important security fixes, performance improvements, and reliability enhancements across the operating system. The update introduces new features such as Xbox Mode for gaming, File Explorer improvements, enhanced input and sharing experiences, better taskbar and Windows Hello reliability, and additional enterprise management capabilities for […]

AC Anoop C Nair 8 min read
SCCM

ConfigMgr 2603 Introduces New Early Update Enrollment Process

Key Takeaways In this post we are discussing the ConfigMgr 2603 Introduces New Early Update Enrollment Process. Microsoft has officially released Configuration Manager version 2603 to the Early Update Ring, giving organizations an opportunity to test upcoming improvements before the global production rollout. The release is targeted at enterprises running ConfigMgr version 2409 or later […]

AC Anoop C Nair 3 min read