Join the #BuildWithBuildAgent Challenge! Get recognized, earn exclusive swag, and inspire the ServiceNow Community with what you can build using Build Agent.  Join the Challenge.

ACL for Mid Server

John Vo1
Tera Guru

I have an ITIL user trying to do a quick discovery and when he clicks on magnifying glass to select mid server he is getting security constraints. Which ACL do I need to edit for him to see the mid servers?

find_real_file.png

1 ACCEPTED SOLUTION

This was ServiceNow recommendations.   Create a Discover by ip address and update the script and it worked.



find_real_file.png


View solution in original post

21 REPLIES 21

Thanks John.



Best practice: If you don't already have it, create a group for those desktop techs.


Grant the appropriate role to those techs to allow them to read those records.


Chuck,



The reason I don't want to give them roles is we want them limited as possible.   I don't want them being able to mess with the mid servers or discovery schedules.   So can I just add the role to read, write, delete and they should be able scan by ip address using quick discovery?



Thanks,


John


Technically, Quick Discovery creates a schedule (and runs now). I don't think you're going to get where you need to be with a limited approach on the ACLs. Eventually you'll find you need to open those ACLs up as much as the existing roles require.



glennpinto - any thoughts on this one?


Chuck,



I added role ITIL to all ecc_agent ACL and when I try to run quick discovery I get this error.   Mid servers are up and running.


find_real_file.png


To resolve this issue, you have to add the "ITIL" role to the ACL created for the DiscoveryAjax script include.