October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
ConfigMgr

List of SCCM/ConfigMgr Management Point IIS Virtual Directories: Paths, Purpose, and Troubleshooting

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A Configuration Manager (formerly SCCM or MEMCM) Management Point (MP) normally creates a group of IIS applications and virtual directories. The names and functions below provide a practical baseline for auditing an MP, but the exact inventory varies by ConfigMgr branch and build, enabled features, authentication mode, co-hosted roles, and installation history. The example paths use an F: drive; your server may use C: or another location.

ConfigMgr setup owns these entries. Inspect them in IIS, but do not manually rename, delete, or recreate them as a first-line fix.

Virtual directory, application, path, and endpoint: what you are looking at

An IIS virtual directory maps a URL path to a physical folder. An IIS application adds an application boundary and usually an application pool. A handler mapping can process a URL dynamically, so an endpoint does not have to correspond to a file on disk. For example, /SMS_MP/.sms_aut can be handled by ConfigMgr even when no .sms_aut file exists. See RootSec’s endpoint analysis.

The names shown in older installation data, such as CcmIncomingVDir or CcmSystemVDir, are installer component names and may not be the friendly names displayed in IIS Manager.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Baseline IIS entries on a ConfigMgr Management Point

The following list is based on the baseline documented by HTMD. Treat it as a comparison starting point, not a universal Microsoft inventory.

IIS entry Example physical path Likely role Typical diagnostic focus
BGB F:Program FilesSMS_CCMSMS_BGB Background channel used for client notification and related MP communication. Client notification and BGB health.
CCM_CLIENT F:Program FilesMicrosoft Configuration ManagerClient Client deployment or client-related resources exposed by the MP. Client content and installation behavior.
CCM_Incoming F:Program FilesMicrosoft Configuration ManagerCCMIncoming Incoming transfer location, including BITS-related traffic. Transfer backlog, BITS jobs, and file processing.
CCM_STS F:Program FilesSMS_CCMCCM_STS ConfigMgr token/service infrastructure. Token and authentication workflows.
CCM_System F:Program FilesSMS_CCMServiceDataSystem Client-management service endpoint and system data. /ccm_system/request processing.
CCM_System_TokenAuth F:Program FilesSMS_CCMServiceDataSystem Token-authenticated system-management endpoint. Token authentication and client requests.
CCM_System_WindowsAuth F:Program FilesSMS_CCMServiceDataSystem Windows-authenticated system-management endpoint. Windows Authentication and authorization.
CMUserService F:Program FilesSMS_CCMCMUserService User-service endpoint for ConfigMgr user-management functions. User-service requests and policy operations.
CMUserService_WindowsAuth F:Program FilesSMS_CCMCMUserServiceWindowsAuth Windows-authenticated user-service endpoint. applicationviewservice.asmx and Windows authentication.
SMS_MP F:Program FilesSMS_CCMSMS_MP Main standard or anonymous MP endpoint. Service location, policy, and MP requests.
SMS_MP_WindowsAuth F:Program FilesSMS_CCMSMS_MP Windows-authenticated MP endpoint. Windows-authenticated MP requests.

Presence depends on release, authentication configuration, installed capabilities, upgrades, repairs, and whether another ConfigMgr role shares the server. SMS_MP and SMS_MP_WindowsAuth may receive requests such as /SMS_MP/.sms_aut and /SMS_MP_WindowsAuth/applicationviewservice.asmx. The authentication behavior is determined by the site’s HTTP, HTTPS, enhanced-HTTP, and client-authentication settings.

What the main groups do

SMS_MP and SMS_MP_WindowsAuth

These are the core MP web applications. They handle MP service-location and policy-related traffic. A successful HTTP response proves only that that request was processed; it does not prove registration, policy retrieval, inventory, or notification are healthy.

CCM_System variants

The standard, token-authenticated, and Windows-authenticated names represent different authentication routes over the system service path. A log entry for /ccm_system/request must be correlated with client and MP health rather than judged in isolation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CCM_Incoming

This location can contain queued or transferred files. A large count is not, by itself, a failure threshold. Check file age, whether the directory is growing, BITS job state, transfer errors, antivirus or backup interference, and the consuming ConfigMgr component. Do not empty it simply because it contains many files. A historical transfer-testing example is documented at this BITS troubleshooting archive.

CCM_CLIENT and BGB

CCM_CLIENT supports client-related resources. BGB supports the background-management channel used for client notification. Their existence alone does not prove those features work.

CMUserService variants

These endpoints support ConfigMgr user-service functions. Availability varies with product version and enabled capabilities; the Windows-authenticated variant uses a separate example folder.

CCM_STS

This entry is associated with token and service infrastructure. Actual use depends on client authentication and site configuration, including cloud-attachment-related features.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to inspect the MP safely

Using IIS Manager

  1. Sign in to the server that hosts the MP.
  2. Open Server Manager, choose Tools, then open Internet Information Services (IIS) Manager.
  3. Expand the server, expand Sites, and select the site used by ConfigMgr, commonly Default Web Site.
  4. Review applications and virtual directories, then open Basic Settings to record each physical path and application pool.

Read-only PowerShell inventory

Import-Module WebAdministration
Get-ChildItem IIS:Sites | Select-Object Name, ID, State, Bindings
Get-Website | ForEach-Object {
    $site = $_
    Get-WebApplication -Site $site.Name |
        Select-Object @{Name='Site';Expression={$site.Name}}, Path, PhysicalPath, ApplicationPool
}

These are inspection examples, not Microsoft-prescribed MP repair commands. Confirm the correct IIS site, site ID, host header, HTTP/HTTPS binding, and certificate before testing an endpoint.

Verify paths, pools, and prerequisites

  • Confirm that each configured physical path exists and contains the expected ConfigMgr binaries or data.
  • Check access for the assigned application-pool identity and investigate file locks or security software interference.
  • Review application pools for stopped state, rapid recycling, identity errors, resource exhaustion, and hardening changes that conflict with ConfigMgr.
  • Historical installer evidence includes pools named SMS Management Point Pool, SMS Windows Auth Management Point Pool, CCM Server Framework Pool, and CCM Windows Auth Server Framework Pool. Names and assignments vary by release; do not treat that list as a current universal specification. See historical installation evidence.
  • Check IIS role services, certificates, TLS settings, permissions, and the MP role status in the ConfigMgr console.

Use IIS logs to correlate real requests

Typical IIS logs are under C:inetpublogsLogFilesW3SVC<site-id>. HTMD examples include W3SVC1 and W3SVC2005362426, but the numeric folder is determined by the IIS site ID.

Representative requests include:

  • GET /SMS_MP/.sms_aut
  • GET /CMUserService_WindowsAuth/applicationviewservice.asmx
  • CCM_POST /ccm_system/request

Review timestamp, method, URI, client address, username, status, substatus, Win32 status, duration, and user agent.

Result What it may indicate
200 The specific request returned successfully; it does not establish end-to-end MP health.
401 Authentication challenge or failure.
403 Authorization, request filtering, or endpoint restrictions.
404 Wrong site or binding, missing or disabled endpoint, or misrouting.
500 Server-side application or configuration failure.
Long or repeated durations Possible backend, certificate, database, thread, or network problems.

A complete MP validation workflow

  1. Confirm the role: Verify that the server currently has the Management Point role. IIS names alone can be stale or belong to a co-hosted role.
  2. Confirm site and binding: Match the client protocol, host header, certificate, and site ID. Testing the wrong binding can produce misleading 404, 403, or certificate errors.
  3. Inventory entries: Compare local applications with the baseline while allowing for version, authentication, features, upgrades, and co-hosting.
  4. Validate paths and pools: Check existence, permissions, identities, recycling, and resource use.
  5. Correlate logs: Review IIS logs with the MP installation log, MP control and health logs, and relevant component logs. Log names and locations vary by ConfigMgr version and installation path.
  6. Test from a client: Validate MP location, registration, policy retrieval, inventory upload, application or software-update policy processing, and client notification where applicable. A browser-only test is insufficient.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Common failure modes and safe responses

Missing entry

Possible causes include failed or incomplete role installation, missing IIS prerequisites, manual deletion, failed upgrade or repair, wrong site selection, or permissions and rollback. Confirm role status and logs, then repair or reinstall the MP through ConfigMgr. Do not create a replacement virtual directory by hand.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Incorrect physical path

Drive changes, cloning, migration, stale entries, or manual edits can produce a wrong path. Identify the ConfigMgr installation state and let the supported role installer rebuild the configuration instead of pointing IIS at a similarly named folder.

401, 403, or 500 responses

Check the configured authentication mode, providers, client certificates, authorization rules, request filtering, application-pool identity, TLS, and binding. Disabling authentication or enabling anonymous access indiscriminately can make the problem worse.

Repeated installation failures

Read mpMSI.log, MP setup logs, IIS logs, permissions, WMI, certificate, and prerequisite errors before repeating a reinstall. Repeating the same repair without addressing the underlying failure commonly reproduces it.

Unexpected probing or public exposure

MP URLs can reveal that a server is an MP and may respond differently by authentication mode. Do not publish them directly to the public internet without an approved architecture. Use supported security controls, monitor IIS logs and network controls, and do not attempt to hide an endpoint by renaming it. Endpoint identification is not, by itself, evidence of a specific vulnerability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Co-hosted roles and stale entries

A site system may also host a Distribution Point, Software Update Point, reporting services, or other IIS applications. Not every ConfigMgr-looking entry belongs to the MP. Confirm role assignments in the ConfigMgr console and interpret duplicate or leftover entries in the context of upgrades, repairs, and previous role assignments.

Repair principle

Preserve IIS and ConfigMgr logs before changing anything. The supported authority for MP applications, paths, handlers, and pools is ConfigMgr setup. Use role repair or reinstallation after diagnosing prerequisites, bindings, authentication, certificates, permissions, and component failures; then validate from an actual client.

Frequently Asked Questions

Are these entries present on every Management Point?

No. This is a common baseline. Product build, enabled features, authentication mode, upgrades, repairs, and co-hosted roles can change the inventory.

Why is my path different from the F: example?

The documented F: paths are examples. Verify the actual path in IIS Basic Settings and your ConfigMgr site-system configuration; many installations use C: or another drive.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I delete files from CCM_Incoming?

Do not empty it based only on file count. Correlate file age and growth with BITS, IIS, MP, and component logs, and follow an approved remediation plan.

Why does /SMS_MP/.sms_aut work without a file?

IIS handler mappings can route the URL to ConfigMgr code dynamically, so a matching static file is not required.

What does a 401 or 403 prove?

It identifies an authentication or authorization response for that request, not the single root cause. Check providers, certificates, authorization, filtering, and the requested binding.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.