This IIS log signature means a Configuration Manager client’s BITS upload to the management point’s CCM_Incoming endpoint received HTTP 403 Forbidden and HRESULT 0x80070005, commonly an access-denied error. It does not, by itself, prove that BITS is broken or that the incoming folder’s NTFS permissions are wrong: IIS authentication, authorization, client certificates, domain identity, or management-point configuration can also reject the request. Start with the full IIS status fields, then repair the specific layer that refused it.
What the error means
BITS_POST identifies a BITS upload request; /CCM_Incoming/ is the Configuration Manager management point’s incoming-data endpoint. Microsoft documents 0x80070005 as an access-denied error, while BITS reports HTTP errors separately. In this signature, the HTTP 403 is evidence that the web server refused the request, not a diagnosis of which security check failed. See Microsoft’s references for COM error codes and BITS return values.
A typical entry may include a request GUID, a second GUID inside bits_error, the status tuple, port, username, client IP, and user agent. For example, a logged username such as DOMAINCOMPUTER-3$ is the identity IIS associated with that request; it does not alone establish which identity needs NTFS access. Likewise, Microsoft+BITS/7.5 is a recorded BITS user-agent value, not the Configuration Manager client version.
Read the complete IIS record first
Do not troubleshoot from the shortened phrase bits_error 0x80070005 alone. Find the matching request in the management point’s IIS W3C logs, commonly under %SystemDrive%inetpublogsLogFiles; the exact directory depends on the IIS site and logging configuration. Capture the time, client IP, URI, username if present, port, and these fields:
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- COMPLETE M6 RACK SCREWS KIT:Includes 45 square rack cage nuts, 45 rack mounting screws and 45 black washers stored in a plastic storage box for easy organization and quick access
- DURABLE CARBON STEEL WITH BLACK NICKEL PLATING:Rack screws and cage nuts are built of carbon steel with black nickel coating to deliver excellent oxidation, rust, corrosion and wear resistance for long-term use in high and low temperature environments
- PRECISE SHARP THREADS FOR SAFE INSTALLATION:Server rack mounting hardware features deep sharp threads and smooth burr-free surface for secure, safe installation of rack and cabinet equipment
- UNIVERSAL COMPATIBILITY FOR SQUARE-HOLE RACKS:M6 x 16mm rack screws fit standard 10mm square-hole racks and cabinets; ideal for mounting servers, switches, routers and A/V equipment in data centers and workspaces
- TIGHT TOLERANCE MANUFACTURING:Conforms to metric standard with less than 0.01mm average error; compact thread structure ensures tight fit, uniform force distribution and resistance against deformation and slipping
sc-status sc-substatus sc-win32-status
The substatus and Win32 status can distinguish a generic authorization refusal from a client-certificate requirement or another IIS failure. For example, 403.7 points to a required client certificate and 403.16 to an untrusted or invalid certificate in the relevant IIS/Schannel context. A bare 403 0 is generic; investigate authorization and application behavior rather than assuming a folder ACL is at fault. A 401 calls for authentication investigation, while 404 suggests checking the URL, virtual directory, and endpoint configuration; 500 points toward a server or application failure. Treat the actual fields in the affected server’s log as more diagnostic than the abbreviated client-side error.
Use the failure pattern to choose a starting point
| Observed pattern | Start by checking |
|---|---|
| One client fails against otherwise healthy management points | That client’s certificate and identity, Configuration Manager client health, proxy, DNS, site assignment, and boundary-group management-point assignment. |
| Many clients fail against one management point | That server’s IIS configuration, HTTPS binding and certificate, CCM_Incoming physical path and permissions, and management-point role health; compare it with a working peer. |
| Many clients fail against every management point | Site-wide authentication, PKI and certificate changes, policy, or a broader Configuration Manager infrastructure change. |
| Only HTTPS clients fail, or HTTP works while HTTPS fails | Prioritize certificate trust and selection, subject/SAN, EKU, revocation checks, IIS SSL settings, and the HTTPS binding. This pattern makes an authentication or PKI problem more likely than a path-specific failure. |
Also establish what stopped working. CCM_Incoming can receive different client data; a hardware-inventory symptom is not proof that all uploads are affected. On the client, correlate InventoryAgent.log, InventoryProvider.log, InventoryReport.log, CcmMessaging.log, and LocationServices.log. On the management point, inspect MP_Hinv.log for inventory receipt or processing. A transfer accepted by IIS does not prove that the management point or downstream site processing consumed the report.
Confirm the client is contacting the intended management point
On an affected client, review LocationServices.log, CcmMessaging.log, ClientLocation.log where applicable, PolicyAgent.log, and the relevant inventory log. Verify the hostname resolves to the expected server, that the client is assigned to the expected site, and that its boundary group provides the expected management point. Check whether a reverse proxy, load balancer, or stale DNS record changes the destination; compare the IIS client IP with the affected machine.
Rank #2
- Pro Grade – Here is our new Black M6 Rack Screws and Cage Nuts Set [25 x Server Rack Screws, 25 x Cage Rack Nuts, 25 x Washers] used for mounting server racks, enclosures, cabinets, and more.
- Strong & Durable – Our Rack Cage Nuts & Relay Rack Screws for server rack have a high-grade carbon steel construction to prevent stripping. The M6 Cage Nuts and Bolts have also been coated in zinc chromate plating for resistance from corrosion.
- Wide application – Our rack screws & nuts are universally compatible with all square hole racks & cabinets. This makes the rack cage nuts and screws suitable for mounting all server rack hardware, including rack server cabinets, server shelves, A/V device enclosures, and other server mounting procedures.
- Easy to install – Our server rack screws and clip nuts have a Phillip’s truss-head with self-guiding pilot points to allow you to install in no time. The rackmount screws and nuts thread are extra sharp, clean & accurate, offering a smooth & satisfying installation process.
- Essential Bundle – Our Cage nuts & screws m6 set includes all the essential parts for mounting your server equipment. Pack not only includes screws & cage nuts; we have also thrown in additional heavy-duty washers to reduce any marks or scratches when installed. We truly believe our server rack nuts and bolts set is the best in the marketplace and we stand by that. If our cage nut set starts driving you nuts, we’ll FULLY REFUND YOU. So, click “Add to Cart” now and buy with confidence.
Useful basic checks include:
nslookup management-point.example.com
nltest /dsgetdc:example.com
If one management point is suspect, compare the same client workflow with a known-good peer. Configuration Manager’s network ports reference can help validate connectivity assumptions, but basic reachability alone does not establish that an authenticated BITS upload is authorized.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Check HTTPS and client-certificate authentication
For a management point requiring HTTPS or client authentication, confirm that the intended client certificate is present and usable before changing filesystem permissions. Check expiration, revocation status, issuing-chain trust, the Client Authentication Enhanced Key Usage, expected subject or SAN, and private-key availability. Confirm the client trusts the management point’s server certificate and that the management point trusts the client’s issuing CA. If revocation checking is enforced, verify CRL or OCSP access. When multiple certificates are installed, verify Configuration Manager is selecting the appropriate one. Check IIS and Schannel events for certificate-specific failures and compare a failing client with a successful one.
A Microsoft Q&A case describes a related management-point 403 and 0x80070005 symptom in a PKI/authentication context; it illustrates why certificate validation belongs in the diagnosis, not that every matching error has the same cause. See the Q&A case. Do not disable certificate validation or weaken site authentication as a shortcut.
Rank #3
- 【Wide Application】 XOOL M6 Rack Mount Screw Kit is great for mounting your rack server cabinets, server shelves, A/V device enclosures, and more. These M6 cage nuts and screws are universally compatible with all square-hole racks and cabinets. Easily mount your equipment using this convenient kit, which comes with everything you'll need to get the job done. These self-locking cable ties are perfect for computer, appliance and electronic cord organization, wire management and storage.
- 【Superb Quality】 The cage nuts and screws is made of high quality Carbon Steel. The Carbon Steel material features strength and offers good corrosion resistance in bad environment like high temperature, cold weather, and high humidity areas. They have superior rust resistance and the excellent of oxidation resistance, which can ensure long time using and prolong screws and nuts lifespan. Wear resistant feature make the cage nuts and screws more durable and solid.
- 【Standard Metric】 Our M6 screws and cage nuts accord with standardized metric system. And the average error is less than 0.01mm. The screw thread is very sharp, clean and accurate without burr. The compact and force uniform screw thread is not easy to out of shape and slid in the process of rolling and installation. The deep and clear flat cross head can make your working more easily and improve your work efficiency.
- 【Safety and Eco-Friendly】 XOOL M6 screws and cage nuts use high quality Carbon Steel raw material, which is environmental protection and non-poisonous. In the process of using, there are no toxic substances releasing, which will ensure your safety. After heat treating, carbon steel has good mechanical properties of ductility, hardness, yield strength, or impact resistance.
- 【Thoughtful Design】 We add self-locking Nylon cable ties on our package. The CABLE TIES is good for home, office, garage, workshop and more. And the screw is very easy to insert with hand.
Inspect the IIS endpoint and its configuration
On the management point, inspect the CCM_Incoming virtual directory and associated application. Record the existing settings before changing anything, and compare them with a healthy management point or the documented baseline for the same Configuration Manager build and role design.
- Confirm the virtual directory exists and note its actual physical path; do not assume an old installation path applies.
- Review authentication providers, authorization rules, SSL requirements, and inherited server-level settings.
- Check request filtering, BITS upload configuration, and any relevant application-pool assignment and status.
- Look for recent IIS hardening, web.config changes, virtual-directory recreation, or changes made by security tooling.
Microsoft’s BITS documentation notes that uploads can fail if BITS uploads are not enabled on the relevant IIS virtual directory, and that IIS upload-size configuration can affect transfers. Those conditions may produce different signatures; do not conflate them with a 403 access refusal without evidence.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Audit NTFS permissions without broadening access
Inspect the actual physical directory shown in IIS, which can vary by Configuration Manager release and server configuration. For example, if IIS points to C:PathToCCMIncoming, inspect that path and its parent:
Rank #4
- 【UNIVERSAL 19-INCH RACK COMPATIBILITY】No more ill-fitting hardware! Our M6 x 16mm fasteners fit all standard 19-inch SERVER RACKS, network cabinets and data centers—seamless lock-in, zero size guesswork, no return risks for mismatched parts. Perfect for your rack mount setup
- 【DURABLE BLACK ZINC-PLATED BUILD】Fight mild rust and stripping! Our RACK MOUNT HARDWARE features thick BLACK ZINC PLATING on carbon steel—resists wear, bending and indoor/semi-outdoor corrosion for 2+ years. Sturdier than generic flimsy fasteners
- 【50-PACK ALL-IN-ONE CAGE NUTS KIT】No mid-install part runs! Our complete 50-pack of CAGE NUTS includes matching M6 screws, washers + FREE self-locking cable ties—exact parts for rack/cabinet builds, no extra hardware store trips
- 【TOOL-FREE SNAP-ON EASY INSTALL】Skip complex tools and slow builds! Our RACK MOUNT SCREWS pair with snap-on cage nuts (hand-installed)—twist in with a basic Phillips driver, no stripping. Finish your rack setup in 10-15 mins, even for first-timers
- 【MULTI-USE RACK ACCESSORY HARDWARE】Max out your setup versatility! This hardware works for all NETWORK AND SERVER RACK ACCESSORIES—small business racks, office cabinets, home labs, audio racks. Washers prevent scratches, cable ties tidy wiring
icacls "C:PathToCCM"
icacls "C:PathToCCMIncoming"
Check that the directory exists, inheritance is as intended, no explicit Deny entry overrides an allow, and ownership and principals are valid. Look for unresolved SIDs, unexpected changes, or differences from a healthy peer. Recent hardening, antivirus or EDR changes, backup restoration, and permission-cleanup tools can alter ACLs. Do not equate the IIS log’s username with the anonymous IIS identity or infer from the username alone which principal should have access.
An older field report associated this signature with missing IUSR permissions on CCM_Incoming and reported hardware-inventory uploads recovering after permissions were restored. That is a case-specific clue, not a current, universal Microsoft ACL prescription. See the historical report. Verify the intended permissions for the installed release and authentication design; do not grant IUSR Full Control by default.
Check domain identity and secure-channel clues
If the IIS record shows a computer-account identity, or the ACL contains an unresolved or unexpectedly unqualified principal, check that the client computer account is enabled and the domain trust is healthy. From a domain-joined client, a secure-channel check is:
Best Value
- Accurate & Durable Design:Our M6 screws and cage nuts are manufactured to strict metric standards with an average tolerance of less than 0.01 mm for accurate fit and reliable performance. The threads are sharp, clean, and burr-free, ensuring smooth installation. The compact, evenly distributed thread design resists deformation and slipping during fastening. A deep, well-defined Phillips head allows for easier operation and improved work efficiency.
- Heavy-Duty & Long-Lasting:Constructed from premium carbon steel with a protective black nickel coating to resist rust and oxidation. Designed to withstand high temperatures, cold weather, and other harsh conditions for reliable, long-term performance.
- Clean & Professional Look:Finished in sleek black nickel to match most rack systems, delivering a clean, organized, and professional appearance inside your cabinet.
- Wide Application:Perfect for server cabinets, rack shelves, and A/V enclosures. Compatible with all standard square-hole racks, this M6 cage nut and screw kit provides secure installation hardware along with durable self-locking cable ties for clean and organized wire management.
- 50-Pack Complete Set – Comes with 50 cage nuts, 50 mounting screws, and 50 black washers. Packaged in a sturdy small box to keep everything organized and easy to store.
Test-ComputerSecureChannel -Verbose
A failed result is relevant evidence, not proof that it caused the upload refusal. A historical forum report described computer-principal entries changing and temporary recovery after resetting an Active Directory computer password, but did not establish a verified root cause. Treat that observation as a lead to investigate identity resolution, stale SIDs, restored snapshots, duplicate accounts, or trust issues—not as a general password-reset fix. See the forum report.
Repair the layer the evidence identifies
- Restore the documented or default permissions appropriate to the same Configuration Manager build and role configuration if the ACL is proven wrong.
- Correct the specific IIS authentication, authorization, SSL, or virtual-directory setting shown to be incorrect.
- Resolve certificate issuance, trust, selection, expiry, or revocation-access problems when IIS or certificate evidence identifies PKI as the failure.
- If the management-point role’s IIS configuration is damaged, repair or reinstall that role using the supported Configuration Manager process rather than reinstalling BITS as a first response.
- After recording and applying a targeted change, restart only the affected components as appropriate, then trigger a controlled client retry and inspect both the IIS record and management-point processing logs.
Avoid copying ACLs from an unrelated server or granting Everyone, Users, or broad Full Control. Do not delete CCM_Incoming while clients may be uploading: queued data or role structure could be affected. A browser request or simple curl GET is not equivalent to the Configuration Manager client’s BITS upload, since it can use different credentials, certificates, headers, and transfer behavior.
Verify the complete upload and processing workflow
On the client, inspect outstanding BITS jobs with an elevated PowerShell session if needed to see jobs owned by another identity:
Get-BitsTransfer -AllUsers
Get-BitsTransfer -AllUsers |
Select-Object JobId, DisplayName, JobState, OwnerAccount, ErrorDescription
Use the result to determine whether a relevant job is retrying, suspended, or failing immediately. Do not delete all BITS jobs as a first response; unrelated transfers may be active. For BITS validation or transfer events, open Event Viewer at Applications and Services Logs → Microsoft → Windows → Bits-Client → Operational, a log Microsoft identifies as useful for certain BITS failures.
Consider the fix verified only when the client’s BITS upload is accepted, the management-point log records receipt, the relevant processing log consumes the report, the client no longer reports repeated transfer failure, and the expected inventory or status appears in the site database after normal processing delay. HTTP success alone confirms transport, not downstream processing.
Common misdiagnoses to avoid
- Reinstalling BITS first: the signature is commonly a refusal at the IIS/management-point boundary; repairing the transport service does not correct a bad authorization rule, certificate, or ACL.
- Granting
IUSRbroad access: one old field case does not establish the correct identity or permissions for every release and security design. - Assuming inventory is lost: failed uploads may retry, and successful receipt may still be followed by processing delay or failure.
- Treating a temporary recovery as a permanent fix: an IIS restart, password reset, snapshot restoration, or role reinstall can change symptoms without resolving the underlying identity, ACL, or certificate issue.
- Ignoring time or load balancing: clock differences can affect certificate validity and Kerberos; a load balancer can send clients to one misconfigured management point and make failures intermittent.
When to escalate
Escalate with a matching IIS record including status, substatus, and Win32 status; the affected client’s correlated Configuration Manager logs; relevant IIS, Schannel, and BITS events; and a comparison against a successful client or management point. Include recent certificate, IIS, role, domain, or security-tool changes. This evidence helps separate a management-point-wide fault from a single-client identity or connectivity issue.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




