09-23-2019 11:50 AM
On a post from a few years ago Craig responded with the following details on the Config WMI button:
Sets the Windows Audit Policy
Sets permissions When AD User in the Domain Admin Group
Sets required Permissions When AD User Not in Domain Admin Group
Sets permissions to Use DCOM on the Domain Controller
Sets permissions for Access to WMI Root/CIMv2 Name Space
Grants access to the Security Event Log on the AD Domain Controller
The question I have is what permissions are need to run this button? If the service account used for WMI polling is not a member of Domain Admins it won't be able to make the Config WMI call to the DC. My current customer has 68 DCs to get passive ID working on and we don't want to add the service account to domain admins.
We have the service account polling one DC correctly but we had to do all the steps manually to make it work.
Is that config WMI script published anywhere so the customer could look at it and modify it as needed?
Solved! Go to Solution.
09-25-2019 10:06 PM
You are correct that the button requiring a Domain Admin.
The script is not published as we do not support it that way.
09-25-2019 10:06 PM
You are correct that the button requiring a Domain Admin.
The script is not published as we do not support it that way.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide