| FYI, we 'worked around' this issue, by doing the following: acl { 'C:/ProgramData/Puppetlabs/pxp-agent/etc/pxp-agent.conf': group => 'S-1-5-21-1292428093-179605362-682003330-513', inherit_parent_permissions => false, owner => 'S-1-5-32-544', permissions => [ {'identity' => 'BUILTIN\Administrators', 'rights' => ['mask_specific'], 'mask' => '2032031', 'affects' => 'self_only'}, {'identity' => 'GSM1900\Domain Users', 'rights' => ['write', 'read'], 'affects' => 'self_only'}, {'identity' => 'Everyone', 'rights' => ['mask_specific'], 'mask' => '1179776', 'affects' => 'self_only'}, {'identity' => 'NT AUTHORITY\SYSTEM', 'rights' => ['full'], 'affects' => 'self_only'}], require => File['C:\ProgramData/PuppetLabs/pxp-agent/etc/pxp-agent.conf'], } acl { 'C:\ProgramData/PuppetLabs/puppet/cache/state/package_inventory_enabled': group => 'S-1-5-21-1292428093-179605362-682003330-513', inherit_parent_permissions => false, owner => 'S-1-5-32-544', permissions => [ {'identity' => 'BUILTINAdministrators', 'rights' => ['mask_specific'], 'mask' => '2032031', 'affects' => 'self_only'} , {'identity' => 'GSM1900\Domain Users', 'rights' => ['write', 'read'], 'affects' => 'self_only'} , {'identity' => 'Everyone', 'rights' => ['read'], 'affects' => 'self_only'} , {'identity' => 'NT AUTHORITY\SYSTEM', 'rights' => ['full'], 'affects' => 'self_only'} ], require => File['C:\ProgramData/PuppetLabs/puppet/cache/state/package_inventory_enabled'], } |