SCCM Collection Security
Hi All This might be a dumb question. I have a multi site hierarchy I do all my collection creation at the top level site and set the security permissions on this collection. The collection flows down but the security doesn't, Is this correct ? Or do I have to go to each Site Server and set the security again at that collection or do I have an issue with my SCCM sites ? The SCCM version is SP1 R2. Many Thanks Neil
November 6th, 2008 12:50pm

No not a dumb question.The behaviour you are seeing is normal. Collections propogate down a site heirarchy. Security rights don't. Retarded isn't it!So yes, you do have to go to each Site Server and set security again. Having said that, think about whether you really need to do this. Are you (or your SCCM administrators) doing configuration work on multiple site servers? There are instances where this does make sense. It all depends on your specific environment.Cheers.Blah Blah Blah
Free Windows Admin Tool Kit Click here and download it now
December 19th, 2008 5:11am

Collections at child sites automaticallyget locked so you can't edit them anyway. So whythere's a need to set security rights on them?
December 19th, 2008 12:10pm

What if I want to allow administrators of the Child Primary the ability to create collections underneath the locked collection?
Free Windows Admin Tool Kit Click here and download it now
January 19th, 2011 10:53am

Does not work using the console, but what's the requirement behind that? It *might* be possible using the SDK.
January 19th, 2011 11:17am

We have a Central server where we do global administration. So there are standard packages, collections that everyone should see. However, then at each of the Primaries in the regions, each team looks after their own clients. But (BIG but) there are departments within those regions. So for example Department A & B. They both need access to the same Primary site, but not access to the other Primaries in the hierarchy. They then need access to only their own departmental clients within their Site. It's a pretty complex setup. (Would've been better to get vNext in, but the decision was made that it would only go in later.) They then need to be able to create objects in SCCM that only their department can access. Make sense?
Free Windows Admin Tool Kit Click here and download it now
January 20th, 2011 2:59am

Makes sense, but why do they have to create subcollections under the locked ones on the primary child? You can create new collections at the top level. Isn't that not enough (given that you set up appropriate security rights)?
January 20th, 2011 3:34am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics