NT SERVICE\miru-agent virtual account and needs specific file
system permissions in the two cases where it touches files on your devices:
- Configs — writes config instances to disk when it deploys a release
- Data uploads — reads files to upload them to your bucket
Configs
Default config path
During installation, the installer creates%ProgramData%\Miru\configs. The folder is owned by Local System and does not inherit permissions from %ProgramData%.
Deploying configs to
%ProgramData%\Miru\configs requires no additional configuration to the Miru Agent. However, accessing applications must be granted membership in the Miru Agent Users group, which the installer creates empty.
To do so, open PowerShell as administrator and run:
PowerShell
Replace
<username> with the actual usernameCustom config paths
The Miru Agent also supports writing configs to arbitrary file system paths. Some examples include:C:\ProgramData\MyApp\configs\mobility.jsonC:\robot\configs\communication.yaml
NT SERVICE\miru-agent modify (M) on the folder that holds the file, with (OI)(CI).
Follow the instructions in Granting access to grant the permission.
If the folder does not yet exist, create it yourself and grant access on it. The agent
creates a missing folder only when it can create folders in the nearest folder that
already exists.
Data uploads
To upload files from disk, the agent reads the files matched by a file rule’ssource.glob and streams them to
your bucket.
You must grant the required permissions outlined below. Otherwise, the agent can’t read the files and they are not uploaded.
Required permissions
NT SERVICE\miru-agent needs read and execute (RX) on the folder the glob matches in, with (OI)(CI).
Follow the instructions in Granting access to grant the permission.
Uploads are read-only — the agent does not need write access to the source
files, unless the rule also deletes them, covered next.
Deleting local files
If a file rule has aretention block,
the agent removes each matching file once its retention guarantee ends. Grant delete (D) as well as read and execute (RX) on that folder, with (OI)(CI).
Follow the instructions in Granting access to grant the permission.
Granting access
GrantNT SERVICE\miru-agent access with icacls from PowerShell opened as administrator.
Replace
C:\path\to\folder with the actual folder pathC:\, such as C:\robot\configs, inherits modify access for signed-in users, so any local user could change the configs the agent deploys there.
Restricting a config folder
To give a custom config folder the same permissions as the default config path, replace its permissions instead of adding to them:PowerShell
Replace
C:\path\to\folder with the actual folder pathGranting access before installing
TheNT SERVICE\miru-agent account name only resolves once the agent is installed. To grant access earlier, for example in a machine image, use the service’s security identifier instead. sc.exe prints it at any time, including before installation:
PowerShell
icacls with a * prefix:
PowerShell
Replace
C:\path\to\folder with the actual folder pathRemoving access
To remove every entry for the agent from a folder:PowerShell
Replace
C:\path\to\folder with the actual folder path
