Smsapm32 may not run an advertisement on backup domain controllers (BDCs) when a program is configured to use the client software installation account. Advertised Programs Manager (APM) is trying to add the Microsoft Windows NT client software installation account to the local Administrators group.

You receive an error message similar to the following example in the Smsapm32.log file on the BDC:

ACCOUNT MGR : Granting Local admin rights to user 'domain1\SMSCliSftAcct'
ACCOUNT MGR : ERROR: NetLocalGroupAddMembers error for user domain1\SMSCliSftAcct. (2226)
ACCOUNT MGR : Failed to add admin rights to user domain1\SMSCliSftAcct
NOTE: he client software installation account e.g. SMSCliSftAcct is a user defined account, configurable in the Systems Management Server Admin console.


This behavior occurs because the account modification operation is incorrectly being performed against the BDC instead of the primary domain controller (PDC).


To work around this issue, manually add the Windows NT client software installation account to the local Administrators group in the domain.


Microsoft has confirmed this to be a problem in Systems Management Server version 2.0.


Prior to running a program, you can use Nconnect.exe to specify universal naming convention (UNC) paths to network servers that each client connects to using one of the Systems Management Server client network connection accounts. Nconnect.exe lets APM run programs under the smsclitokn& account and gain access to specific network resources.

The Windows NT client software installation account also provides this ability, but has the limitation regarding BDCs described in the Symptoms section of this article.

Disadvantages of the Nconnect.exe Approach

  • You must specify the paths in the static Nconnect.ini file. The network path cannot be determined by the target program at run time.

  • You must modify the package contents to contain Nconnect.exe and Nconnect.ini.

  • You must grant access to the target shares to each client network connection account used in your enterprise.

  • You must use separate programs for Windows NT clients and Microsoft Windows 95/98 clients, because Nconnect.exe is only supported on Windows NT clients.

Advantages of the Nconnect.exe Approach

  • Works on BDCs.

  • Does not require you to configure a Windows NT client software installation account because this method uses the Systems Management Server client network connection accounts.

You must place Nconnect.exe in the same location as the program you want to run, along with a configuration file that lists the UNC paths to which the program needs to connect. You need to change the program command line to insert the tool at the beginning of the command line. For example, if the following example is the current program command line:
myapp.exe /option1
the new command line looks like the following example:
nconnect.exe myapp.exe /option1
The tool makes a connection to each path listed in the configuration file, starts the program, waits for the program to stop, and then releases the connections and passes the program's exit code back to Systems Management Server. If the tool cannot create one or more of the connections, the program is not started and a status Management Information Format (MIF) causes Systems Management Server to report a status message containing the unsuccessful path and a description of the problem.

Example of an Nconnect.ini file:

[Status MIF]
Product=Testpkg4 - nconnect

