CCA deployment fails to end-points when using non-domain credentials

Version 1

    Verified Product Versions

    Management Center 8.7Management Center 8.6Management Center 8.5Management Center 8.4Management Center 8.3Management Center 8.2Management Center 8.1Management Center 8.0


    When trying to deploy the Client Communications Agent (CCA) to an end-point using Local Administrator accounts rather than Domain Administrator accounts, the deployment fails with an access denied error message.


    The CCA deployment mechanism tries to connect to the ADMIN$ share of the end-point but by default, Windows Vista and newer versions of Windows prevent local accounts from accessing administrative shares through the network.

    Create a REG_DWORD value named LocalAccountTokenFilterPolicy in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System and set it to 1 on the end-point that you are trying to deploy to. 

    There is no need to reboot the end-point after making the change.

    See Microsoft Technet article KB947232