Close Menu
    Facebook X (Twitter) Instagram
    Saturday, October 11
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»configmgr»1602»SCCM Current Branch Remote Console connectivity issues Insufficient privilege to connect, error Access is denied

    SCCM Current Branch Remote Console connectivity issues Insufficient privilege to connect, error Access is denied

    Eswar KonetiBy Eswar KonetiApril 07, 7:23 pm4 Mins Read 1602 18,888 Views
    Share
    Facebook Twitter LinkedIn Reddit

    Since few days ,i have been working on the SCCM console connectivity issues from remote box. This is completely new setup replacing the existing CAS with primaries and going with flat design (1 Primary site.There is blog post coming soon on the SCCM design considerations and notes from the field )

    As part of setting up SCCM current branch ,was creating RBAC for the team and for testing ,I have installed the current branch console (1702) on citrix and remote boxes (server/workstation) to try with different user accounts.

    When i try to launch the console ,it failed with generic error message with some default possible solutions to check.

    image

    Next is to look at admin UI log SmsAdminUI.log on the console installation folder (C:\Program Files (x86)\Microsoft Configuration Manager\AdminConsole\AdminUILog) for further troubleshooting.

    Insufficient privilege to connect, error: 'Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))'\r\nSystem.UnauthorizedAccessException\r\nAccess is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))\r\n   at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32 errorCode, IntPtr errorInfo)

    image

    As you can see above, the log doesn't say much about the issue except that, Insufficient privilege to connect, error: 'Access is denied .

    The account which am trying to connect to the console is full administrator and is working on local SCCM server but not from any other remote box.

    Since the console access is not working for anyone from any remote box ,i suspect the issue is almost on the SCCM server with DCOM permissions.

    I have checked the DCOM permissions ,WMI security permissions (wmigmmt.msc) and wbemtest locally on the server ,all looks good.I could not able to find anything wrong with security permissions to SMS admin group .I have also compared the DCOM permissions from working SCCM site (another domain) with this newly setup current branch 1702 site but i could not able to find any permission issues.

    Following are the permissions to re-validate on DCOM .

    From run command, type dcomcnfg.msc (if it prompt for password ,type in for admin ).

    Go to my computer and properties

    image

    Make sure following is checked under default properties .

    image

    Then looked at event viewer if i can any information pertaining to DCOM permissions ,all looks clean from event viewer .

    what else could go wrong here except security permissions on the DCOM,WMI ? well , after spending sometime on the troubleshooting  colleague of mine helped to look at MSDTC service and have decided to uninstall MSDTC (Distributed Transaction Coordinator service)  ,install and reboot the SCCM server which fixed the issue of remote console connectivity.

     

    What made colleague to look at MSDTC component ?As he explain,for any remote connections to happen it either go with DCOM/WMI/RPC .In this case ,i could not able connect to remote SCCM server using wmi (wbemtest) and console just failed. So ,there seems major issue on DCOM connection .         For this ,we checked the permissions on DCOM (dcomcnfg) ,all looks good t,hen went to registry to look for DCOM enabled ,it also looks good. The next part of troubleshooting in DCOM is to reinstall MSDTC component .

    How do you uninstall MSDTC component ?

    Open the cmd as run as administrator ,perform net stop MSDTC

    image

    run MSDTC –uninstall

    image

    Review event log: In Application Event Log message confirms that MSTDC was successfully uninstalled

    image

    Run MSDTC –install

    image

    image

    Review event log: In Application Event Log message confirms that MSTDC was successfully installed

    start MSDTC services using net start MSDTC

    image

    Reboot the SCCM server ,launch the console ,you see the nodes there .

    If the reinstall of MSDTC doesn't work ,then  we may have to go little deeper into DCOM to troubleshoot.

    See you in the next post!

    0x80070005 Access is denied cannot connect to site configmgr DCOM permissions Insufficient privilege to connect MSDTC SCCM SCCM Console connectivity issues SmsAdminUI.log wmi access wmimgmt
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    SCCM SQL Report – Compare Installed Apps on TWO Different Computers

    July 13, 10:35 am

    Optimize Your Intune Workflow with a Powerful Browser Extension

    March 22, 10:39 am

    Migrate Microsoft 365 Updates from SCCM/MECM to Intune for Co-Managed Devices

    February 11, 9:50 pm

    3 Comments

    1. Safari Agaba on May 19, 2017 12:56 AM

      Had same issue, all i did was to re-organize my groups and memberships. How, have a sql setup account and sccm setup account member of one group and add that group directly to sccm > security > and give it full administrator or whatever you want the use to have

      Reply
    2. ramg1967 on April 7, 2017 8:07 PM

      Hi - That is very odd. How the hell one can know DTC is the issue. If you see the service running fine then you assume it is working fine. Good you had a partner who thought about DTC and finally were able to fix the issue.

      Thanks for sharing. This note going to KB collection.

      Ram

      Reply
      • Eswar Koneti on April 7, 2017 10:00 PM

        Well ,It is one of the DCOM troubleshooting method since the remote console access is not working which means ,there is serious issue with DCOM/WMI. as part of DCOM, checked the DCOM permissions ,registry ,all looks good .So next step is to reinstall MSDTC component .Even if this MSDTC component doesnt solve the issue, we may have to go little deeper into DCOM which is not required in this case.

        Regards,
        Eswar

        Reply

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.