Installing a new version of DeviceLock service via Microsoft Systems Management Server on client computers fails with “Access Denied (5)” error.
The issue indicates that DeviceLock Administrators functionality is active, which means no one but authorized Users (listed in DeviceLock Administrators list) can access DeviceLock Service, and since installation process in Microsoft SMS by default is performed on behalf of SYSTEM account, DeviceLock driver blocks access to its executable file.
1. Disable “DeviceLock Administrators” functionality for the target computer before the upgrade
2. Run SMS installation on behalf of a user account listed in DeviceLock Administrators with full access.