Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This message usually means a Microsoft Configuration Manager client-push prerequisite failed before the client could register. The site server could not establish the remote administrative connection to \PCadmin$. Check the complete ccm.log error code, then test DNS, SMB, credentials, the target’s ADMIN$ share, Windows Firewall, WMI and RPC from the site server that is performing the push.

What \PCadmin$ means

ADMIN$ is a hidden Windows administrative share that normally points to the target computer’s Windows directory. During client push, Configuration Manager uses remote administrative access to copy bootstrap files and start installation. It is not the Configuration Manager client, a Management Point, a Distribution Point or the SMS_SiteCode share.

Reaching the share proves only that the SMB path and authentication worked. WMI, RPC, Service Control Manager access and client-content download are separate stages and can fail afterward. Microsoft lists administrative rights, an available ADMIN$ share, discovery, client source access and the required firewall exceptions as client-push prerequisites (Microsoft prerequisites).

Read the complete ccm.log entry first

On the site server, open:

C:Program FilesMicrosoft Configuration ManagerLogsccm.log

Search around the failure for Failed to connect, admin$, WNetAddConnection2, NetUseAdd, Trying each entry, Machine Account, error and hexadecimal values beginning with 0x. Record the target name, account selected, timestamp and whether the failure occurred at SMB, WMI, IPC$ or service creation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The adjacent code is more useful than the generic message:

Code Typical indication
0x80070005 (5) Access denied; possible credentials, administrator membership, UAC filtering, WMI or security-policy issue.
0x80070035 (53) Network path not found; investigate name resolution, routing, SMB and firewall.
0x80070040 (64) Network name no longer available.
0x80070043 (67) Network name cannot be found.
0x800706BA (1722) RPC server unavailable.
0x80070032 (50) Request not supported; sometimes associated with unavailable administrative shares.

After the push reaches the target, use C:WindowsccmsetupLogsccmsetup.log. Until then, a client-side log cannot explain a connection that never reached the computer. Microsoft describes this log workflow in its client-installation guidance and troubleshooting discussion.

Fast diagnostic sequence from the site server

  1. Resolve the name and test required ports

    Resolve-DnsName PC
    Test-NetConnection PC -Port 445
    Test-NetConnection PC -Port 135

    Also compare the FQDN:

    nslookup PC
    ping PC
    ping PC.contoso.com

    A failed 445 test points to DNS, routing, SMB filtering, segmentation or an offline device. Port 135 is needed for RPC endpoint mapping. Successful TCP tests are necessary, not proof that authentication, dynamic RPC ports or WMI permissions will work.

  2. Test the exact share with the exact push account

    net use \PCadmin$ /delete
    net use \PCadmin$ /user:DOMAINSCCMClientPush *
    dir \PCadmin$
    net use \PCadmin$ /delete

    Use \PC.contoso.comadmin$ if short-name resolution is suspect. Run this on the site server, not an administrator’s laptop. Remove existing connections first to avoid error 1219. A manual Explorer connection may use cached credentials, a different name or a different source computer.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Verify effective administrator rights

    Get-LocalGroupMember -Group Administrators

    The configured push account must be a local administrator on the target, directly or through an approved domain group. Check password, expiration, lockout, disablement, logon hours, “Deny access to this computer from the network” and “Access this computer from the network.” If no push account is configured, Configuration Manager uses the site server’s computer account. Do not substitute the Network Access Account or assume Domain Admin rights are required.

  4. Confirm the share and core services

    Get-SmbShare -Name ADMIN$
    Get-Service LanmanServer, Winmgmt, RpcSs, RpcEptMapper

    No ADMIN$ result means the share is missing or cannot be enumerated in that context. Check whether the Server service is stopped and whether Group Policy, a hardening baseline, security software or registry policy disabled automatic administrative shares. Restore a deliberately disabled share only under approved policy; recreating or exposing it is not a universal fix.

  5. Check firewall rule groups

    Get-NetFirewallRule -DisplayGroup 'File and Printer Sharing' |
      Select-Object DisplayName, Enabled, Profile, Direction, Action
    
    Get-NetFirewallRule -DisplayGroup 'Windows Management Instrumentation (WMI)' |
      Select-Object DisplayName, Enabled, Profile, Direction, Action

    For client push, Microsoft identifies inbound and outbound File and Printer Sharing and inbound Windows Management Instrumentation (WMI) exceptions (firewall requirements). Apply narrowly scoped rules for the correct profiles and source networks. Third-party firewalls, EDR, network ACLs and segmentation appliances can still block traffic.

  6. Test WMI separately

    Run wbemtest on the site server, choose Connect, enter \PCrootcimv2, authenticate with the push account and enumerate a class. If admin$ works but this fails, investigate WMI namespace permissions, RPC, firewall policy or endpoint security—not the SMB share. Microsoft’s WMI testing pattern is also documented for Configuration Manager connectivity (WMI and SMS Provider troubleshooting).

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Fixes by symptom

Access denied or logon failure

  • Confirm the account shown in ccm.log is the account configured under the Configuration Manager console’s current-branch Client Push Installation Properties, Accounts tab. Console wording can vary slightly by release.
  • Update an expired password, unlock the account and verify that the stored credential is current.
  • Check local administrator membership and policies that deny network logon.
  • For local accounts, remote UAC token filtering can remove the elevated token. For domain or cross-forest accounts, verify trust, Kerberos/NTLM restrictions and authentication-policy requirements. Any change to remote UAC, LocalAccountTokenFilterPolicy, NTLM or administrative-share policy is security-sensitive and requires organizational approval.

Network path, name or SMB failure

  • Compare short-name and FQDN resolution; repair stale or duplicate DNS records instead of retaining a permanent workaround.
  • Confirm the computer is powered on, not asleep, correctly routed and not stale or renamed in discovery data.
  • Check TCP 445, File and Printer Sharing rules, network ACLs and the target’s firewall profile.
  • Distinguish a missing ADMIN$ share from an existing share that is inaccessible; they have different repair paths.

WMI, RPC or service-creation failure after SMB works

Check Winmgmt, RpcSs, RpcEptMapper, inbound WMI rules, dynamic RPC policy, WMI namespace permissions and EDR events. A later failure while creating or starting the bootstrap service is a Service Control Manager or endpoint-security problem, not proof that ADMIN$ is broken.

Special deployment contexts

  • Workgroup computers: client push is not supported; use an installation method suited to workgroup authentication.
  • Other forests: required trust and authentication conditions may be absent.
  • Internet-only or CMG-connected devices: they may not have inbound connectivity from the site server.
  • Hardened endpoints: security baselines can remove administrative shares, local-admin rights or remote-management access.
  • Existing broken clients: once transport succeeds, continue with ccmsetup.log, LocationServices.log, boundaries, content and Management Point diagnostics.

When client push is the wrong method

Client push depends on discovery, remote administrative rights, SMB, WMI and firewall exceptions. For one computer, running ccmsetup.exe locally can separate installation problems from push transport. For broader deployment, Microsoft documents Group Policy, software-update-point-based installation, logon scripts and Intune or Entra-based approaches (installation methods and limitations). Choose the method that matches the device’s trust, network and management model rather than weakening endpoint security to preserve client push.

Prevention checklist

  • Use a dedicated, monitored deployment account with only the rights required by the approved design.
  • Keep DNS records, computer names, boundaries and content locations accurate.
  • Standardize approved File and Printer Sharing and WMI firewall rules across supported client profiles.
  • Test from every site server to representative client subnets, including FQDN resolution, ports 445 and 135, admin$ and WMI.
  • Document exceptions for EDR, segmentation, cross-forest authentication and hardened Windows baselines.
  • After each retry, capture the new ccm.log stage instead of assuming the original SMB symptom remains.

For the distinction between client-push traffic and ordinary client-to-site-system traffic, see Microsoft’s client communication ports documentation. TCP 80 and 443 concern client communication with site systems and may be customized; they do not replace the initial remote-administration prerequisites.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.