<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows 2003 Machine Account (Local System) access to CIFS share in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66071#M6003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shaunjurr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have the same problem with our new netapp to get access to a share with the computeraccount. We tried your way with the usermap.cfg. It seems to work half the way. We get an authenticaton message to input our credentials from the sccmuser. Should this not happen automatically and how can this be done?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Aug 2012 12:10:14 GMT</pubDate>
    <dc:creator>niedermeier</dc:creator>
    <dc:date>2012-08-23T12:10:14Z</dc:date>
    <item>
      <title>Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66052#M5997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently looking to migrate a Microsoft SCCM file store from the local SCCM server to a CIFS share on NetApp 7.3.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue we have found during testing is that the Windows machine account (Local System Account) on that Windows 2003 server is unable to access the CIFS share.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have updated the ACLs to include the Windows machine account access to both the CIFS share and the containing files - but still we are unable to even list the files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "cifs shares" shows that the Windows machine account has "Full Control" and the everyone group also has "Full Control".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sectrace shows &lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;"Access denied because 'Read' permission (0x1) is not granted on file or directory (Access denied by the share-level ACL) - Status: 1:188743680:32:192"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Windows Active Directory User accounts access the CIFS share without any issues. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I am concerned that there is some limitation with Windows Machine Account (Local System Account) access to CIFS shares.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Does anyone have any experience with this type of CIFS access ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2025 06:55:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66052#M5997</guid>
      <dc:creator>greg_upton</dc:creator>
      <dc:date>2025-06-05T06:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66057#M5999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe, there was NetApp knowledge base and the problem definitely was discussed here already. IIRC this won’t work, account needs to be proper user account, not the machine one. Unfortunately I can’t find references right now, try to search kb/communities.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 May 2011 02:38:07 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66057#M5999</guid>
      <dc:creator>aborzenkov</dc:creator>
      <dc:date>2011-05-13T02:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66062#M6001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://communities.netapp.com/message/53431#53431" target="_blank"&gt;http://communities.netapp.com/message/53431#53431&lt;/A&gt;&lt;SPAN&gt; we have a similiar problem, access with machine account work. But not with PowerShell Script.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first Problem we had with the Access was NTLM, you have to deactivate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 May 2011 07:32:19 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66062#M6001</guid>
      <dc:creator>daehnrich_bsh</dc:creator>
      <dc:date>2011-05-13T07:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66067#M6002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to create a CIFS share that is meant to be accessed only by a machine account, you can map the IP address of the server to a local account on the filer in usermap.cfg and then add that user with useradmin and finally add full control for that user on the share.&amp;nbsp; You may want to add other rights to the share for administration of files.&amp;nbsp; I found it helpful to make the shares hidden to reduce the chance of others accessing the file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've done this for Notes storage on a set of filers for a lot of years.&amp;nbsp; It seemed like a hack at the time, but it has been suprisingly stable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.10.10.10:"" =&amp;gt; sccmuser&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (a backend storage IP subnet to limit access via IP spoofing can be a good idea)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;useradmin user add sccmuser -g administrators -c "SCCM server"&amp;nbsp; (or some other more limited group)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cifs access &amp;lt;sccm_share&amp;gt; sccmuser Full Controll&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this should get things rolling.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The documentation says that machine accounts should be able to access the data.&amp;nbsp; Not sure if you've looked at that specifically or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 May 2011 00:18:35 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66067#M6002</guid>
      <dc:creator>shaunjurr</dc:creator>
      <dc:date>2011-05-15T00:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66071#M6003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shaunjurr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have the same problem with our new netapp to get access to a share with the computeraccount. We tried your way with the usermap.cfg. It seems to work half the way. We get an authenticaton message to input our credentials from the sccmuser. Should this not happen automatically and how can this be done?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 12:10:14 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66071#M6003</guid>
      <dc:creator>niedermeier</dc:creator>
      <dc:date>2012-08-23T12:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66076#M6004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In general to confirm the user is valid user or not. We can use the command called "getXXbyYY getpwbyname_r root or &amp;lt;username&amp;gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the output, you will know that user is valid user to access the filer or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;AK G&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 17:10:21 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66076#M6004</guid>
      <dc:creator>AGUMADAVALLI</dc:creator>
      <dc:date>2012-08-23T17:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows 2003 Machine Account (Local System) access to CIFS share</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66081#M6005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;more over enable the cifs audit : &lt;STRONG&gt;options cifs.audit.enable on&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;browse thru the /etc/messages for audit logs or you can rdfile &lt;/STRONG&gt;&lt;STRONG&gt;/etc/log/adtlog.evt&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;thank you,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AK G&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 17:14:31 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Windows-2003-Machine-Account-Local-System-access-to-CIFS-share/m-p/66081#M6005</guid>
      <dc:creator>AGUMADAVALLI</dc:creator>
      <dc:date>2012-08-23T17:14:31Z</dc:date>
    </item>
  </channel>
</rss>

