Blog : Windows Server Discovery Simple Guide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yesterday
THE FLOW
MID Server -> Network -> Login -> Windows permissions -> WMI -> Discovery data
Discovery stages:
Find server -> Classify -> Authenticate -> Connect via WMI -> Collect data -> Create/update CI
Logging in and being allowed to use WMI are two different things.
An account can log in fine and still be denied WMI/DCOM access.
That is the "No WMI connection" case.
SETUP CHECKLIST
1. Create a dedicated service account
Use a domain account only for Discovery, e.g. svc_servicenow_discovery.
Do not use a personal admin account.
2. Give it permissions on each Windows server (most missed step)
- Add it to these local groups:
Distributed COM Users
Performance Monitor Users
Performance Log Users
- Give it DCOM Remote Launch / Remote Activation rights
- Give it WMI permissions on root\cimv2:
Remote Enable + Execute Methods
Simple way to remember it:
The credential proves WHO you are.
WMI/DCOM permissions decide WHAT you can do.
3. Open the firewall ports (from the MID Server to the target)
- TCP 135 (RPC)
- Dynamic RPC port range
- TCP 5985 / 5986 (WinRM), depending on your Discovery method
Test from the MID Server (PowerShell):
Test-NetConnection <server> -Port 135
Test-NetConnection <server> -Port 5985
If these fail, it is a network/firewall problem. Fix that first.
4. Check the MID Server
It must be able to reach the target servers (subnet routing and
domain visibility). It makes the actual connection to the targets.
5. Add the Windows credential in ServiceNow
Go to Discovery > Credentials and add the service account.
Link it to the correct MID Server, or use credential affinity.
6. Create the Discovery Schedule
Set an IP range (e.g. 10.10.10.1 - 10.10.10.100) or a CI group,
and pair it with the correct MID Server.
You can also use Quick Discovery for a single target.
HOW TO READ THE FAILURE
- Ports 135/5985 fail from the MID Server
-> Check network / firewall
- Ports open, but "no valid credentials"
-> Check credential, affinity, or MID Server pairing
- Ports open, credential OK, DNS fine, but "No WMI connection"
-> Check local DCOM and WMI permissions on the target server
If it fails at classification, check connectivity and authentication first.
If those pass, check the local group membership, DCOM rights, and
root\cimv2 namespace security on the target.
TROUBLESHOOTING
A. BASICS
1. MID Server is Up and Validated.
2. Correct MID Server selected in the Discovery Schedule.
3. Target resolves in DNS from the MID host (nslookup <server>). Try the FQDN.
B. NETWORK (run on the MID Server host)
4. Test-NetConnection <server> -Port 135
5. Test-NetConnection <server> -Port 5985
6. If they fail, check the target's Windows Firewall, network firewalls
and routing between the MID and target subnets.
7. On the target, enable the firewall rules: WMI (DCOM-In), WMI (WMI-In)
and Remote Event Log / RPC if needed.
C. CREDENTIAL
8. Use "Test Credential" in ServiceNow with the right MID Server.
9. Credential is Active and its affinity matches the MID in use.
10. Account is not locked, disabled or expired, and the password is current.
11. Try the DOMAIN\username or username@domain format.
12. Check credential order so a wrong one is not tried first (lockouts).
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Bharat Chavan
