The Zurich release has arrived! Interested in new features and functionalities? Click here for more

why does windows credentials need to be a part of local admin group on windows host for discovery

supriyarajp
Tera Contributor

In our project, we are going to do IP based discovery for citrix worker machines using IP subnet but we would need a domain user which will then needs to be a part of local domain group on the target windows hosts. Thought it will be a non interactive account but we are unable to get approval for this approach. is there any other way we can do this

7 REPLIES 7

Shreya Jain1
Tera Guru

We need local admin for Application Dependency Mapping. Discovery runs a command called 'netstat' to check all TCP connections incoming and outgoing from device. 

netstat command is allowed to run with admin user. 

RawelS
Tera Expert

Another way is to use JEA (Just Enough Administration). Below mentioned is the documentation link.

https://www.servicenow.com/docs/bundle/yokohama-it-operations-management/page/product/discovery/conc...

 

Shubham_Jain
Mega Sage

@supriyarajp This would help you to read the registry and config file related data. 

 

Refer this: Windows discovery without 'domain admin' or 'local admin' privileges ? - Support and Troubleshooting

✔️ If this solves your issue, please mark it as Correct.


✔️ If you found it helpful, please mark it as Helpful.



Shubham Jain


@supriyarajp  Hope my response was useful. 

✔️ If this solves your issue, please mark it as Correct.


✔️ If you found it helpful, please mark it as Helpful.



Shubham Jain