8 years ago
Read only agent / collector
I know I've brought this up before, but I'd like to bring it up again. LM's requirement that collectors run as local admins (or system) is a GAPING security hole in your product. No amount of cer...
On 2/16/2017 at 9:32 PM, Matthew Dunham said:Hey @Eric Singer -
My apologies -- I didn't realize the state of our documentation for this use-case. I'm working on rewriting, and making sure our Support Engineers are in a position to support this use-case.
Matthew (or other LM'er): looking at the docs as they stand now, it would seem that to use WMI without administrator-level priveledges the guidance is that each monitored windows node must have local security policy changes. Is that correct? Is there any AD-only solution where the service account in use for WMI polling has the minimally required rights to accomplish the basic goals? Is it further complicated when domain controllers are used as the systems running the collector (understand that using domain controllers for collectors is not the best choice, but as an MSP I can only recommend against this and in some cases our hand has been forced). Specifically, we need an account that can poll WMI but cannot execute powershell or other scripts that can modify the environment.