Discovery Failing at Windows Classification Despite Existing Discovery Service Account Permissions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
Hi All,
I would like some clarification on the expected behavior for ServiceNow Discovery when discovering new Windows SQL Servers.
Current Database Discovery:
We are now implementing SQL Server Discovery and plan to reuse the same Windows service account using Windows Authentication.
The DBA team has already:
- Granted the required SQL access (VIEW SERVER STATE)
- Provided a list of non-production SQL Servers for testing
Issue
When I run Quick Discovery against one of the pilot SQL servers, Discovery fails during the Windows Classification phase
Could not find any valid credentials to authenticate the target for type [Windows]
Active, couldn't classify: No WMI connectionFrom the WMI Runner logs:
- ServiceNow successfully finds and attempts the Windows credential
- All credential attempts fail authentication
- TCP 135 is open
- WinRM (5985) is open
- DNS resolution is successful
My Question
My understanding was that since the Windows Discovery service account already has the required permissions, I should only need to grant the additional SQL permissions for Database Discovery.
However, based on the behavior, it appears that the SQL pilot servers may require the same Windows Discovery onboarding/configuration to be applied individually on those servers.
Could someone clarify:
- Are permissions such as DCOM, WMI namespace access, Distributed COM Users, Performance Monitor Users, etc., typically configured on each target server?
- If a service account already works for Windows Discovery on one set of servers, should it automatically work on other Windows servers?
Any guidance would be appreciated.
Thanks in advance.
