Discovery of Active Directory Domain Controllers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎01-10-2022 03:45 PM
For Discovery of Active Directory Domain Controllers, what level of access does the credential have?
Does this have to be a domain Admin access?
What happens if the security does not allow providing the Admin Access to SNOW?
- Labels:
-
Discovery

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎01-10-2022 08:26 PM
Yes - It needs Domain Admin to run discovery.
It's a windows requirement to have domain admin rights not SN . With Domain Admin rights you can fire commands/scripts for discovery.
if Security do not allow- Create these DCs manually or TRY JEA approach for Domain Controllwer discovery.
Regards
RP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎01-11-2022 10:46 AM
You might also consider using the Agent Client Collector as well if they aren't going to give you credentials.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎10-11-2022 06:53 AM
We are disallowed from having a service account in the domain admin group. The acceptable workaround is that the service account is manually put into the built-in administrator's group on each DC. This gives full access to the host and all running processes for the purpose of discovery but does not in and of itself grant any domain privileges. The only reason this needed any exception at all is that if the credential is compromised that account could logon to a DC and put itself into the domain admin group. But having an account that could elevate itself was much more acceptable than having an elevated account.