The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →This message usually means a Microsoft Configuration Manager client-push prerequisite failed before the client could register. The site server could not establish the remote administrative connection to \PCadmin$. Check the complete ccm.log error code, then test DNS, SMB, credentials, the target’s ADMIN$ share, Windows Firewall, WMI and RPC from the site server that is performing the push.
What \PCadmin$ means
ADMIN$ is a hidden Windows administrative share that normally points to the target computer’s Windows directory. During client push, Configuration Manager uses remote administrative access to copy bootstrap files and start installation. It is not the Configuration Manager client, a Management Point, a Distribution Point or the SMS_SiteCode share.
Reaching the share proves only that the SMB path and authentication worked. WMI, RPC, Service Control Manager access and client-content download are separate stages and can fail afterward. Microsoft lists administrative rights, an available ADMIN$ share, discovery, client source access and the required firewall exceptions as client-push prerequisites (Microsoft prerequisites).
Read the complete ccm.log entry first
On the site server, open:
C:Program FilesMicrosoft Configuration ManagerLogsccm.log
Search around the failure for Failed to connect, admin$, WNetAddConnection2, NetUseAdd, Trying each entry, Machine Account, error and hexadecimal values beginning with 0x. Record the target name, account selected, timestamp and whether the failure occurred at SMB, WMI, IPC$ or service creation.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems#1 Best Overall
The adjacent code is more useful than the generic message:
| Code | Typical indication |
|---|---|
0x80070005 (5) |
Access denied; possible credentials, administrator membership, UAC filtering, WMI or security-policy issue. |
0x80070035 (53) |
Network path not found; investigate name resolution, routing, SMB and firewall. |
0x80070040 (64) |
Network name no longer available. |
0x80070043 (67) |
Network name cannot be found. |
0x800706BA (1722) |
RPC server unavailable. |
0x80070032 (50) |
Request not supported; sometimes associated with unavailable administrative shares. |
After the push reaches the target, use C:WindowsccmsetupLogsccmsetup.log. Until then, a client-side log cannot explain a connection that never reached the computer. Microsoft describes this log workflow in its client-installation guidance and troubleshooting discussion.
Rank #2
Fast diagnostic sequence from the site server
-
Resolve the name and test required ports
Resolve-DnsName PC Test-NetConnection PC -Port 445 Test-NetConnection PC -Port 135Also compare the FQDN:
nslookup PC ping PC ping PC.contoso.comA failed 445 test points to DNS, routing, SMB filtering, segmentation or an offline device. Port 135 is needed for RPC endpoint mapping. Successful TCP tests are necessary, not proof that authentication, dynamic RPC ports or WMI permissions will work.
-
Test the exact share with the exact push account
net use \PCadmin$ /delete net use \PCadmin$ /user:DOMAINSCCMClientPush * dir \PCadmin$ net use \PCadmin$ /deleteUse
\PC.contoso.comadmin$if short-name resolution is suspect. Run this on the site server, not an administrator’s laptop. Remove existing connections first to avoid error 1219. A manual Explorer connection may use cached credentials, a different name or a different source computer.Recommended Free Tools
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
Verify effective administrator rights
Get-LocalGroupMember -Group AdministratorsThe configured push account must be a local administrator on the target, directly or through an approved domain group. Check password, expiration, lockout, disablement, logon hours, “Deny access to this computer from the network” and “Access this computer from the network.” If no push account is configured, Configuration Manager uses the site server’s computer account. Do not substitute the Network Access Account or assume Domain Admin rights are required.
-
Confirm the share and core services
Get-SmbShare -Name ADMIN$ Get-Service LanmanServer, Winmgmt, RpcSs, RpcEptMapperNo
ADMIN$result means the share is missing or cannot be enumerated in that context. Check whether the Server service is stopped and whether Group Policy, a hardening baseline, security software or registry policy disabled automatic administrative shares. Restore a deliberately disabled share only under approved policy; recreating or exposing it is not a universal fix. -
Check firewall rule groups
Get-NetFirewallRule -DisplayGroup 'File and Printer Sharing' | Select-Object DisplayName, Enabled, Profile, Direction, Action Get-NetFirewallRule -DisplayGroup 'Windows Management Instrumentation (WMI)' | Select-Object DisplayName, Enabled, Profile, Direction, ActionFor client push, Microsoft identifies inbound and outbound File and Printer Sharing and inbound Windows Management Instrumentation (WMI) exceptions (firewall requirements). Apply narrowly scoped rules for the correct profiles and source networks. Third-party firewalls, EDR, network ACLs and segmentation appliances can still block traffic.
-
Test WMI separately
Run
wbemteston the site server, choose Connect, enter\PCrootcimv2, authenticate with the push account and enumerate a class. Ifadmin$works but this fails, investigate WMI namespace permissions, RPC, firewall policy or endpoint security—not the SMB share. Microsoft’s WMI testing pattern is also documented for Configuration Manager connectivity (WMI and SMS Provider troubleshooting).Recommended: PC Feels Slow? A Free Scan Shows What's Dragging Windows Down →Recommended: Crashes or Glitches? A Free Driver Scan Usually Finds the Culprit →Recommended: Fix Windows Errors and Clear Junk Files in Minutes - Free Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Fixes by symptom
Access denied or logon failure
- Confirm the account shown in
ccm.logis the account configured under the Configuration Manager console’s current-branch Client Push Installation Properties, Accounts tab. Console wording can vary slightly by release. - Update an expired password, unlock the account and verify that the stored credential is current.
- Check local administrator membership and policies that deny network logon.
- For local accounts, remote UAC token filtering can remove the elevated token. For domain or cross-forest accounts, verify trust, Kerberos/NTLM restrictions and authentication-policy requirements. Any change to remote UAC,
LocalAccountTokenFilterPolicy, NTLM or administrative-share policy is security-sensitive and requires organizational approval.
Network path, name or SMB failure
- Compare short-name and FQDN resolution; repair stale or duplicate DNS records instead of retaining a permanent workaround.
- Confirm the computer is powered on, not asleep, correctly routed and not stale or renamed in discovery data.
- Check TCP 445, File and Printer Sharing rules, network ACLs and the target’s firewall profile.
- Distinguish a missing
ADMIN$share from an existing share that is inaccessible; they have different repair paths.
WMI, RPC or service-creation failure after SMB works
Check Winmgmt, RpcSs, RpcEptMapper, inbound WMI rules, dynamic RPC policy, WMI namespace permissions and EDR events. A later failure while creating or starting the bootstrap service is a Service Control Manager or endpoint-security problem, not proof that ADMIN$ is broken.
Special deployment contexts
- Workgroup computers: client push is not supported; use an installation method suited to workgroup authentication.
- Other forests: required trust and authentication conditions may be absent.
- Internet-only or CMG-connected devices: they may not have inbound connectivity from the site server.
- Hardened endpoints: security baselines can remove administrative shares, local-admin rights or remote-management access.
- Existing broken clients: once transport succeeds, continue with
ccmsetup.log,LocationServices.log, boundaries, content and Management Point diagnostics.
When client push is the wrong method
Client push depends on discovery, remote administrative rights, SMB, WMI and firewall exceptions. For one computer, running ccmsetup.exe locally can separate installation problems from push transport. For broader deployment, Microsoft documents Group Policy, software-update-point-based installation, logon scripts and Intune or Entra-based approaches (installation methods and limitations). Choose the method that matches the device’s trust, network and management model rather than weakening endpoint security to preserve client push.
Prevention checklist
- Use a dedicated, monitored deployment account with only the rights required by the approved design.
- Keep DNS records, computer names, boundaries and content locations accurate.
- Standardize approved File and Printer Sharing and WMI firewall rules across supported client profiles.
- Test from every site server to representative client subnets, including FQDN resolution, ports 445 and 135,
admin$and WMI. - Document exceptions for EDR, segmentation, cross-forest authentication and hardened Windows baselines.
- After each retry, capture the new
ccm.logstage instead of assuming the original SMB symptom remains.
For the distinction between client-push traffic and ordinary client-to-site-system traffic, see Microsoft’s client communication ports documentation. TCP 80 and 443 concern client communication with site systems and may be customized; they do not replace the initial remote-administration prerequisites.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

