Security Compliance
Permission issues to scan fileshare and change permissions on shares in ARM
Sometimes the scan of the fileserver or the permission change on shares fails with Error code 1385.
First published date
Last published date
Overview
- In the logs you will see the same error for the permission change if the account set for the change is the same or if it has not the right permissions. When a fileshare permission change is done through ARM the whole change will be done in the context of the collector responsible for the fileserver scan. To call the related API the ARM Service account (the one for AD and the one for FS changes if they are different) needs the 'Log on locally' right on the collector machine.
Product section
Cause
- This can happen when the user configured for the scan and/or for permission changes has not got the right to 'Log On Locally' on the Collector machine, or it is configured in the 'Deny Log On Locally setting in the relevant GPO.
Resolution
Ensure the related service account has the right to Log on locally and is not included in Deny log on locally. The locations of the respective settings in the machine's Local Security Policy are:
- Configuration > Policies > Security Settings > Local Policies > User Rights Assignment > Allow log on locally
- Configuration > Policies > Security Settings > Local Policies > User Rights Assignment > Deny log on locally