You may receive reports that users can still access the Software Portal using shared or bookmarked URLs even after setting the SWPAllowCrossMachinesRequest value to False (or removing the line entirely) in the core configuration.
When link sharing is disabled, the expected behavior is that the SMP Server (Symantec Management Platform or NS server) should strictly validate the MachineGuid parameter in the URL string for every request. If a link originally generated for "User A" on "Machine A" is opened by "User B" on "Machine B," access should be denied. However, endpoints that previously accessed a shared link may continue to load the "Applications" and "My Requests" applets without re-evaluation.
IT Management Suite (ITMS) 8.7.3 and later
Symantec Management Platform (SMP) Console
Software Management Solution / Software Portal
This issue occurs primarily because of aggressive client-side browser caching. When a user opens a shared Software Portal link, the browser caches the session validation and page components. Even if an administrator changes the SWPAllowCrossMachinesRequest core setting to False to block cross-machine requests, the target client browser relies on its local cache instead of forcing the Notification Server to re-authenticate the MachineGuid token.
In IT Management Suite (ITMS) 8.7.3 and later, cross-machine link sharing is disabled by default via an integrated security update. If link sharing was previously permitted, modifying the core setting requires client-side cache remediation to take immediate effect.
Primary Cause: Local browser cache on the client machine bypasses the SMP Server's validation check. The browser loads the cached page state instead of sending a fresh request string to the NS for re-evaluation.
Secondary Factor: Misconfiguration or failure to save changes within the Symantec Management Console core settings page, leaving the underlying value active.
IMPORTANT: Always test core setting modifications first in a non-production or staging environment. Changing this value to False will immediately prevent users from accessing the portal via manually shared or bookmarked URLs that do not originate from their local agent.
| Stage | Action | Target System |
| 1 | Enforce Core Setting Restrictions | SMP Server (SMP Console) |
| 2 | Clear Local Session Cache | Affected Client Endpoints |
| 3 | Verify Official Access Entry Points | Affected Client Endpoints |
Open the Symantec Management Console.
Navigate to the Core Settings page by clicking Settings > All Settings > Notification Server > Core Settings (see Updating Core Settings in ITMS 8.5 and later).
Locate the configuration key: SWPAllowCrossMachinesRequest.
Change the value to False.
(Note: Do not delete the line entirely, as the system may default to legacy behavior depending on minor version revisions).
Click Save Changes.
If a client machine bypasses the restriction:
Open the web browser used to access the Software Portal on the client machine.
Clear the browser's cached images, files, and hosted app data.
Close and reopen the browser.
Attempt to load the shared URL again. The page should now fail to authenticate and deny access.
Once link sharing is successfully restricted, users must launch the Software Portal exclusively through official entry points. These entry points ensure the correct MachineGuid and user tokens are passed to the SMP Server securely:
System Tray: Right-click the Symantec Management Agent tray icon and select Software Portal.
Desktop: Double-click the official Software Portal shortcut icon.
Start Menu: Navigate to the Symantec folder and click the Software Portal shortcut.