Skip to main content
On Windows the Miru Agent runs as the NT SERVICE\miru-agent virtual account and needs specific file system permissions in the two cases where it touches files on your devices:
  • Configs — writes config instances to disk when it deploys a release
  • Data uploads — reads files to upload them to your bucket
This page covers the agent’s default permissions and how to grant file system access.

Configs

Default config path

During installation, the installer creates %ProgramData%\Miru\configs. The folder is owned by Local System and does not inherit permissions from %ProgramData%. Deploying configs to %ProgramData%\Miru\configs requires no additional configuration to the Miru Agent. However, accessing applications must be granted membership in the Miru Agent Users group, which the installer creates empty. To do so, open PowerShell as administrator and run:
PowerShell
Replace <username> with the actual username
The account must then sign out and back in, or its service must be restarted, before the membership takes effect.

Custom config paths

The Miru Agent also supports writing configs to arbitrary file system paths. Some examples include:
  • C:\ProgramData\MyApp\configs\mobility.json
  • C:\robot\configs\communication.yaml
To enable the agent to write to these paths, grant NT SERVICE\miru-agent modify (M) on the folder that holds the file, with (OI)(CI). Follow the instructions in Granting access to grant the permission.
If the folder does not yet exist, create it yourself and grant access on it. The agent creates a missing folder only when it can create folders in the nearest folder that already exists.

Data uploads

To upload files from disk, the agent reads the files matched by a file rule’s source.glob and streams them to your bucket. You must grant the required permissions outlined below. Otherwise, the agent can’t read the files and they are not uploaded.

Required permissions

NT SERVICE\miru-agent needs read and execute (RX) on the folder the glob matches in, with (OI)(CI). Follow the instructions in Granting access to grant the permission. Uploads are read-only — the agent does not need write access to the source files, unless the rule also deletes them, covered next.

Deleting local files

If a file rule has a retention block, the agent removes each matching file once its retention guarantee ends. Grant delete (D) as well as read and execute (RX) on that folder, with (OI)(CI). Follow the instructions in Granting access to grant the permission.

Granting access

Grant NT SERVICE\miru-agent access with icacls from PowerShell opened as administrator.
Replace C:\path\to\folder with the actual folder path
These grants add access for the agent and leave the folder’s other permissions unchanged. A new folder at the root of C:\, such as C:\robot\configs, inherits modify access for signed-in users, so any local user could change the configs the agent deploys there.

Restricting a config folder

To give a custom config folder the same permissions as the default config path, replace its permissions instead of adding to them:
PowerShell
Replace C:\path\to\folder with the actual folder path
This removes the permissions the folder inherits, so only these accounts keep access.

Granting access before installing

The NT SERVICE\miru-agent account name only resolves once the agent is installed. To grant access earlier, for example in a machine image, use the service’s security identifier instead. sc.exe prints it at any time, including before installation:
PowerShell
Pass the SID to icacls with a * prefix:
PowerShell
Replace C:\path\to\folder with the actual folder path

Removing access

To remove every entry for the agent from a folder:
PowerShell
Replace C:\path\to\folder with the actual folder path
Last modified on October 9, 2026