Avatar of Albert Widjaja
Albert Widjaja
Flag for Australia

asked on 

SCCM service account minimum privilege ?

Hi People,

Due to the PCI requirement, I am forced to minimized the members of Domain Admins group.

This is including:
The SCCM client push install service account DOMAIN\SCCM-PUSH-SVC
The SCCM 2012 R2 Standard (Site Server) AD computer account itself PRODSCCM01-VM.

So I wonder what's the minimum service account that is recommended with bare minimum without breaking SCCM functionality ?
Can I remove the AD computer account from the Domain Admins group ?

My SCCM version is 2012 R2 or the vNext edition which I only use for Workstation only not the servers.

Thanks in advance.
SCCMActive DirectoryWindows OSMicrosoft Server AppsMicrosoft Server OS

Avatar of undefined
Last Comment
Albert Widjaja

8/22/2022 - Mon