For the complete documentation index, see llms.txt. This page is also available as Markdown.

ConfigMgr Permission Requirements for Patch My PC Publisher

Applies to: Patch My PC Publisher V3.x

Patch My PC (PMPC) Publisher has the following Microsoft ConfigMgr Software Requirements:

ConfigMgr Security Role

Publisher can create, manage, update, and delete applications in ConfigMgr as well as perform other functions like triggering a Software Update Point (SUP) sync.

In order to be able to perform these functions, Publisher requires the following permissions in ConfigMgr:

  • Application: Read, Modify, Delete, Set Security Scope, Create, Move Object, Modify Folder

  • Distribution Point: Read, Copy to Distribution Point

  • Distribution Point Group: Read, Copy to Distribution Point Group

  • Folder Class: Read, Modify, Create

  • Security Scopes: Read

  • Site: Read

  • Software Updates: Read, Modify

The PatchMyPCService service runs in the SYSTEM context by default.

PatchMyPCService service

If Publisher is installed on the ConfigMgr Site Server, no further action is required as the SYSTEM account has the required access.

However, if Publisher is installed on a remote server, the Computer$ account of that server will require the permissions detailed above.

Note

During a scheduled sync, these operations are performed under the context of the logon account specified for the PatchMyPCService. By default, this will be SYSTEM. Tasks performed manually in Publisher are performed under the context of the currently logged-on user.

More details can be found in the following KB, including how to create a custom Security Role to grant these permissions.

Content Source Folder

To create, manage, and update third-party application content in ConfigMgr, Publisher needs at least the Modify permission on both the SMB share and NTFS folder you specify as the Source Folder during configuration.

Connections to the application source UNC path are performed using the server's computer account because the Publisher service runs in the SYSTEM context. This applies whether content is being created, updated, or cleaned up.

Because of this, the computer account must be granted the appropriate permissions at both the SMB share level and NTFS folder level.

The minimum required permission is Modify. This allows Publisher to create folders, write application content, update files during application revisions, and remove content when applications are deleted.

In this example, Publisher is installed on BB-CM1, and the application source folder is hosted on BB-APP1. As Publisher accesses the content over SMB, all file operations authenticate as BB-CM1$.

To ensure application creation and management works correctly, BB-CM1$ must be granted Modify permissions on the SMB share and the underlying NTFS folder on BB-APP1. Without these permissions, application creation, updates, or cleanup operations will fail.

NTFS and SMB Permissions

Note

Publisher automatically creates a root folder called Applications (which cannot be changed) in the configured UNC source path.

All application content generated by Publisher is stored beneath this folder, with vendor and product-specific subfolders created automatically as applications are published.

Source Folder Structure

Note

See Connection and Source Options for more information.

Last updated

Was this helpful?