Managing Microsoft Active Directory Scanner
The Microsoft Active Directory (AD) Scanner retrieves information from Active Directory and provides visibility into directory objects, users, groups, computers, and organizational units. The scanner supports different scan types that allow either a targeted scan of selected objects or a comprehensive inventory of the Active Directory environment.
Use the Microsoft Active Directory Scanner to discover and monitor Active Directory assets for visibility and analysis.
Limitations
- The Domain Controller (DC) must have sufficient permissions to query LDAP.
-
Passwords cannot contain the following special characters:
, > & ' " \ / - To view deleted objects, the Active Directory Recycle Bin must be enabled.
- Querying a Load Balancer is not supported. Queries must be sent directly to the Domain Controller. For more information, see sk184794.
Organization Distributed Scan
Organization Distributed Scan is enabled by default. Its configured settings are available in the Endpoint Settings view > Default Scanner.
Each Endpoint client sends its path to the Security Management Server.
By default, each Endpoint client sends its path every 120 minutes. In this method, only devices with Endpoint Security installed report their paths, other devices with do not report their information.
Full Active Directory Sync
In a Full Active Directory Sync, one Endpoint client is defined as the Active Directory scanner. The scanner collects information from Active Directory and sends it to the Security Management Server.
To configure the AD scanner:
-
From the left navigation panel, click Asset Management.
-
In the left pane, click Computers.
-
From the top toolbar, click
(General Actions) and click
Directory Scanner.
The Scanner window opens.
-
Configure the scanner settings.
Section Required Information Connect from computer -
Computer name - Select a computer as the AD scanner.
AD Login details -
User name (AD) - Enter the user name to access the Active Directory.
-
Domain name - Enter the Active Directory domain.
-
Password (AD) - Enter the password to access the Active Directory.
AD Connection -
Domain controller - Enter the name of the Domain controller.
-
Port - Enter the listening port number on the Domain controller.
-
Use SSL communication (recommended) - Select this option to use SSL communication between the scanner and the Domain controller.
-
LDAP Path - The address of the scanned directory server.
-
Search filter - Enter search criteria to sync only matching directory entries. For more information, see LDAP syntax.
-
Sync AD every - Specify the time interval in minutes for the system to initiate the scan. Supported range is 5 (min) to 240 (max) minutes.
Note:-
If you set a value outside the supported range (for example 4 or 241), the system resets the value to the closest threshold value.
-
The recommended time interval is 120 minutes.
-
-
Results
When you create a new AD scanner, the organization directory scan is automatically disabled.
To see information on your activated AD scanners, go to the Endpoint Settings view.
You can also open the AD scanner configuration pop-up from Endpoint Settings > AD Scanners > Default Scanner > Setup full Active Directory sync.