Use AD for CMDB Discovery

Nilanjan1
Mega Sage

Dear Experts,. 

 

We have some restricted server which are not discoverable through a ServiceNow discovery or through Agent Client Collectors as well (as it cannot be installed) but are open through AD as they are connected through these (On Prem) , is there a way by which I can use AD to allow the MID Servers to work access the AD and run the process of discovery.

 

A quick help is appreciated

 

REgards

Nilanjan

1 ACCEPTED SOLUTION

Hi Nilanjan,

The communication from device to MID is over secure port. The accounts you use will depend on the options available and that may have more questions from your Infra and Security Team. There are options of using a service account or leaving to system. gMSA was not enabled for ACC as far as i know. 

 

You can refer to datasheet if it has any mention for your questions on how secure it is else you will have to reach support to get detailed information around vulnerabilities.

https://www.servicenow.com/standard/resource-center/data-sheet/ds-itom-acc.html

View solution in original post

8 REPLIES 8

pratik0306
Tera Guru

Hi @Nilanjan1 

can you elaborate on 'why they are not discoverable' apart from the agent part which you already mentioned.

What servers are these and if they are connected to AD then what is the difference in these from others?

Thank you Pratik, they are restricted devices and for unknown reasons no installation of Agents is possible. I am seeking information on a infra diagram, to understand how they are placed. I will keep ypi 

@pratik0306  

 

I did discuss with the owners of the AD and Nasuni appliances, thy are way against the installation of the ACC in the servers, however if we can have some responses on how safe ACC is, they can still work through the process of getting it worked out, the other are manual installation, xml upload and API but in these cases we will not have any relationship. Can you suggest something on this ? if you have come across

Hi @Nilanjan1 

There are documents available for ACC which you can refer and share with your Team so they can understand more about it.

 

And why agentless discovery is not feasible? Is it because of the credential usage? and what OS is this- Windows/Linux?