Computer Association - Import Computer rights
I am attempting to setup a console for our staging partner for system deployment using OSD. One of the roles the staging partner needs is the ability to import computers into SCCM using the "Computer Association" section of OSD. When I import into the "All Systems" collection only, everything works great. When It ry to import into a specific collection, i receive the error below. The user account has the same security on the "All Systems" collection and the "deployment" collections. I have the following currently setup:Site - Read, ImportComputer Association - Read, Delete, CreateAll Systems Collection - Read, Modify, Read Resource"deployment" collections - Read, Modify, Read ResourceI am receiving the following error when I go through the process and try to add it to one of my "deployment" collections:---------------------------------------------------------------------------------------------Error: Following computers have not been imported: Name: test11212 MAC Address: 11:11:11:11:11:11 SMBIOS GUID: Source Computer: Choose Target Collection: Register-NCRErrorsYou do not have security rights to perform this operation.ConfigMgr Error Object:instance of SMS_ExtendedStatus{ Description = "User \"domain\\ncraccess\" has no read resource rights in any collection for this ResourceID"; ErrorCode = 1112017920; File = "e:\\nts_sms_fre\\sms\\siteserver\\sdk_provider\\smsprov\\sspcollection.cpp"; Line = 735; ObjectInfo = "1"; Operation = "ExecMethod"; ParameterInfo = "SMS_Collection.CollectionID=\"XXX00082\""; ProviderName = "WinMgmt"; StatusCode = 2147749889;};---------------------------------------------------------------------------------------------What am I missing?Thanks,Brian
February 21st, 2008 8:36pm

Brian, In SCCM Console, right click your Site Name under Site Management and Click Properties. Click Security Tab Add the "Import Computer Entry" right to the"Class Security Rights" for that particular user. I created a group for the users that will be doing imaging, and granted the Security Group the Import Computer Entry Right. Good luck! Sean
Free Windows Admin Tool Kit Click here and download it now
April 3rd, 2008 11:19pm

Hi Brian!I know that your post ist "very" old. But i think other people like me will run into the same problem and therefore i post the thing you miss. The user or group must have the collection class "read resource" right. Why this is needed i don't know. Because the Import without the class read resource right an without using a destitionation collection will work fine.Markus
May 21st, 2008 12:31pm

Hi Seanka, Thanks , its worked for me.... :) Muthu
Free Windows Admin Tool Kit Click here and download it now
November 29th, 2010 11:59pm

I've just written a blog for this problem: http://pleasepressanykey.blogspot.com/2011/04/restricted-users-cannot-create-direct.html
April 7th, 2011 8:49am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics