What are the windows user and group accounts that get created when installing Client Automation?
The only user account that gets created by default is the Canonprv user account. This account gets created on Domain Managers and Scalability Servers. It is used in the OSIM (Operating System Imaging Management) process and only if OSIM is being used in shared mode. If not using OSIM or using OSIM but not using shared mode then it is fine to disable or delete the Canonprv user account.
The Canonprv account can also be recreated if needed in the future by following the steps in this Technical Document:
Windows Groups that are created when installing Client Automation:
Manpc – Created on Domain Managers and Scalability servers. By default it contains the Canonprv account and can be removed if Canonprv is removed.
Sdofflin – Created on Domain Managers, Scalability Servers, and Software Delivery Agent machines. By default it is an empty group where an account can be added for running offline software delivery jobs. If not running offline software delivery jobs this group can be removed. Please see the ITCM_SD_Admin_ENU.pdf located on the Client Auto image\Doc\enu folder for more information about using this group.
The “s” group often gets created on Domain managers, scalability servers and agents. It sometimes gets created during the installation of the software delivery agent and removing it does not cause any problems or remove any functionality.
If CCS (CA Common Services) was installed on the Enterprise or Domain Managers then a group called "TNDUsers" will exist. That group has privileges to CCS in the mdb database. Please see the ITCM_NSM_Admin_ENU.pdf in the Client Auto Image\DOC\enu folder for more information about this account.