Software Portal Link Sharing Remains Active or Bypassed After Disabling SWPAllowCrossMachinesRequest
search cancel

Software Portal Link Sharing Remains Active or Bypassed After Disabling SWPAllowCrossMachinesRequest

book

Article ID: 447908

calendar_today

Updated On:

Products

IT Management Suite Software Management Solution

Issue/Introduction

You may receive reports that users can still access the Software Portal using shared or bookmarked URLs even after setting the SWPAllowCrossMachinesRequest value to False (or removing the line entirely) in the core configuration.

When link sharing is disabled, the expected behavior is that the SMP Server (Symantec Management Platform or NS server) should strictly validate the MachineGuid parameter in the URL string for every request. If a link originally generated for "User A" on "Machine A" is opened by "User B" on "Machine B," access should be denied. However, endpoints that previously accessed a shared link may continue to load the "Applications" and "My Requests" applets without re-evaluation.

Environment

 

IT Management Suite (ITMS) 8.7.3 and later

Symantec Management Platform (SMP) Console

Software Management Solution / Software Portal

 

Cause

This issue occurs primarily because of aggressive client-side browser caching. When a user opens a shared Software Portal link, the browser caches the session validation and page components. Even if an administrator changes the SWPAllowCrossMachinesRequest core setting to False to block cross-machine requests, the target client browser relies on its local cache instead of forcing the Notification Server to re-authenticate the MachineGuid token.

In IT Management Suite (ITMS) 8.7.3 and later, cross-machine link sharing is disabled by default via an integrated security update. If link sharing was previously permitted, modifying the core setting requires client-side cache remediation to take immediate effect.

 

Primary Cause: Local browser cache on the client machine bypasses the SMP Server's validation check. The browser loads the cached page state instead of sending a fresh request string to the NS for re-evaluation.

Secondary Factor: Misconfiguration or failure to save changes within the Symantec Management Console core settings page, leaving the underlying value active.

 

Resolution

IMPORTANT: Always test core setting modifications first in a non-production or staging environment. Changing this value to False will immediately prevent users from accessing the portal via manually shared or bookmarked URLs that do not originate from their local agent.

Step-by-Step Troubleshooting & Resolution

Remediation Workflow

StageActionTarget System
1Enforce Core Setting RestrictionsSMP Server (SMP Console)
2Clear Local Session CacheAffected Client Endpoints
3Verify Official Access Entry PointsAffected Client Endpoints

Step 1: Re-enabling Link Sharing Restrictions on the Notification Server

  1. Open the Symantec Management Console.

  2. Navigate to the Core Settings page by clicking Settings > All Settings > Notification Server > Core Settings (see Updating Core Settings in ITMS 8.5 and later).

  3. Locate the configuration key: SWPAllowCrossMachinesRequest.

  4. Change the value to False.

    (Note: Do not delete the line entirely, as the system may default to legacy behavior depending on minor version revisions).

  5. Click Save Changes.

Step 2: Clearing the Client Browser Cache

If a client machine bypasses the restriction:

  1. Open the web browser used to access the Software Portal on the client machine.

  2. Clear the browser's cached images, files, and hosted app data.

  3. Close and reopen the browser.

  4. Attempt to load the shared URL again. The page should now fail to authenticate and deny access.

Step 3: Verification of Secure Access

Once link sharing is successfully restricted, users must launch the Software Portal exclusively through official entry points. These entry points ensure the correct MachineGuid and user tokens are passed to the SMP Server securely:

  1. System Tray: Right-click the Symantec Management Agent tray icon and select Software Portal.

  2. Desktop: Double-click the official Software Portal shortcut icon.

  3. Start Menu: Navigate to the Symantec folder and click the Software Portal shortcut.

Additional Information

Software Portal shows error: 'Software Portal must be accessed via the desktop link' after upgrading to 8.7.3.