Creating a Scanner for Local Accounts¶
The Discovery feature is able to search Windows servers in a pool for local accounts and add them to the relevant safes and/or listeners. Alternatively, the feature can send the accounts to quarantine, which means blocking accounts on the target server.
Note
Before proceeding with creating a scanner, you need to set up:
Secret change policy, secret changer, and Secret verifier can be added later, after saving the scanner.
In order to create a scanner, proceed as follows:
Select > >
Click
Enter scanner’s name.
Select
Windows Local Accountsfrom the Scanner type drop-down list.Optionally, enter scanner’s description.
In the Schedule section, choose a day and time for your scanner to start automatically on a weekly basis. This field is optional, so you can skip this step to start your scan manually anytime.
In Configuration section:
7.1. Select the pool of servers, where scanning will be performed.
7.2. Specify port number in the Port field.
7.3. Provide CA certificate.
7.4. Select Account to be used to connect to the target server.
Note
In order to use one scanner to scan local accounts on multiple Windows servers, an administrator account with exactly the same authentication method must exist on every scanned server.
7.5. Choose previously defined Rules to set the following actions after the scan. Please note that in case more than one rule is added and their actions overlap, the order of the rules is taken into account: the first matching rule will be applied.
8. In Secret Changers section select Secret change policy, Secret changer, and Secret verifier which will be automatically assigned to discovered accounts.
Note
Administrator can predefine secret changer variable values in Secret Changers configuration (refer to the Custom Secret Changers section).
Predefining values is optional. If variable is not defined, it will take value from account that secret changer is assigned to.
Default secret changers don’t have predefined variable values.
Click .
Related topics: