Why is the Mid Server Service Account is still being used for scanning the Windows Server Discovery

Selva Arun
Mega Sage
Mega Sage

Why is the Mid Server Service Account is still being used for scanning the Windows Server Discovery evebn after disabling the account. We recently installed new Mid servers and the MID Server Service Account was getting locked out and found that svcservicenowDEV is still being used as a fallback object for some servers. We went from seeing the account log into ~1500+ to just 22 (major improvement) after disabling the WINDOWS MID SERVER credentials. Something else is still utilizing the svcservicenowDEV account though to perform some type of discovery. After investigation, I found that this SVC account is being used for application discovery pattern (mostly IIS and MSSQL), no applicative credentials are set at the moment. I'm not sure why this SVC acount should be used. I'm not able to pin point the reason, where it is being used. Does the above pattern use SVC acount to log on to the device? Kindly help

2 REPLIES 2

Musami2
Tera Contributor

Hello Selva, I've the same issue. How did you revolved it? 

Thank you

Doci1
Kilo Sage

And did you checked credentials table? there is OOB Mid server account with order 99999

Doci1_0-1744360929734.png