Can Windows devices be fully discovered using only SNMP v2/v3 credentials, or are WMI/WinRM cred req
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi Team,
I'm looking for clarification on Windows Discovery behavior when only SNMP credentials are available.
We have a customer environment where:
- SNMP v2 credentials are configured for Windows servers.
- SNMP v3 credentials are configured for network devices (switches/APs).
- A MID Server has been installed and is communicating successfully.
- We are performing Discovery using ServiceNow Discovery.
While testing a Windows server, we observed the following:
- SNMP v2 authentication was successful.
- ServiceNow was able to retrieve SNMP information, including:
- sysName
- sysDescr
- sysObjectID
- Network/interface details
- Other SNMP OIDs (approximately 165 OIDs returned).
- The device is reachable on UDP 161, and the SNMP credential is validated.
However, Discovery also launches the Windows Classify (WMI) probe and returns:
This led to a question regarding the expected ServiceNow behavior.
Questions
If valid SNMP v2 credentials exist on a Windows server, can ServiceNow perform complete Windows Discovery using only SNMP?
Can Discovery retrieve detailed Windows information such as:
- OS details
- Installed software
- Running services
- Applications
- IIS
- SQL Server
- Hardware inventory
- Disk and memory information
using SNMP alone?
Is a Windows credential (WMI/WinRM) mandatory for complete Windows Server Discovery and CMDB population?
Is the expected behavior that:
- SNMP is only used for basic classification/identification, while
- WMI or WinRM is required for detailed Windows discovery patterns and inventory collection?
Has anyone successfully implemented Windows Discovery using only SNMP without Windows credentials? If so, what level of information was discovered?
Additional Context
In our testing:
- SNMP communication is successful.
- ServiceNow receives SNMP data from the Windows host.
- Discovery still attempts WMI-based classification.
- Detailed Windows discovery does not proceed because no valid Windows credentials are available.
I would like to understand whether this is expected product behavior and whether we should advise the customer that Windows (WMI/WinRM) credentials are required for complete Windows Discovery, even when SNMP v2 is available and functioning.
Any guidance or best practices would be appreciated.
Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
a week ago
Yes, this is expected behaviour from ServiceNow discovery product. SNMP is used to retrieve basic information from a Windows server but it will not provide the same level of discovery as standard Windows credential-based discovery. For complete Windows Discovery ServiceNow requires Windows access using WMI or WinRM/PowerShell with appropriate credentials. ServiceNow recommends WinRM for Windows host discovery.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thursday
Full Windows Discovery, including information about what's installed and running, and what's related to, each device requires running WMI queries and powershell scripts that require windows credentials. I've never seen SNMP used for Windows discovery.
If your security team is pushing back because of the access Discovery needs, there are a few options:
- Call out that they almost certainly have other systems that already have this same access. Monitory and inventory tools like SCCM, Tanium, etc typically require the same level of access as ServiceNow Discovery, and your organization is almost certainly using one or more these tools.
- Discovery can use Windows JEA (Just Enough Access) instead of full admin access, but this will require setup by your windows admins.
- There are other options (using a Windows gMSA account for your Windows Service account on the MID server, for instance) that may be more palatable to security but will still get you the access you need.
