TechNote. Contents. Overview. System or Network Requirements. Deployment Considerations



Similar documents
Setup non-admin user to query Domain Controller event log for Windows2003

Configuring WMI on Windows Vista and Windows Server 2008 for Application Performance Monitor

Nagios XI Monitoring Windows Using WMI

Introduction VITAL SIGNS FROM SAVISION / FAQS Savision B.V. savision.com All rights reserved.

To set up Egnyte so employees can log in using SSO, follow the steps below to configure VMware Horizon and Egnyte to work with each other.

Egnyte Single Sign-On (SSO) Installation for OneLogin

OPC Server Machine Configuration

Installing and Configuring Active Directory Agent

Contents. Platform Compatibility. Directory Connector SonicWALL Directory Services Connector 3.1.7

Single Sign-On in SonicOS Enhanced 5.6

Single Sign-On in SonicOS Enhanced 4.0

Configuring User Identification via Active Directory

Release Notes. Contents. Release Purpose. Platform Compatibility. SonicWALL Appliance / Firmware Compatibility. Directory Connector.

Single Sign-On. Document Scope. Single Sign-On

DCOM & Control List Genetec Information Systems Page i Win2003 Service Pack 1

Single Sign-On in SonicOS Enhanced 5.5

Contents. Supported Platforms. Event Viewer. User Identification Using the Domain Controller Security Log. SonicOS

Integrating LANGuardian with Active Directory

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

Configuring SonicWALL TSA on Citrix and Terminal Services Servers

Universal Management Service 2015

DCA Local Print Agent Push Install

E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide. E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide

Active Directory Integration

Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Release Notes. Contents. Release Purpose. Platform Compatibility. SonicWALL Appliance / Firmware Compatibility. Directory Connector.

How To - Implement Clientless Single Sign On Authentication with Active Directory

Web Deployment on Windows 2012 Server. Updated: August 28, 2013

Troubleshooting Guide

Enterprise. Insights. Active Directory Integration: Installation and Setup Guide. v1.0.5

Active Directory Management. Agent Deployment Guide

DANGER indicates that death or severe personal injury will result if proper precautions are not taken.

Latitude NVMS Windows XP SP2 Configuration

Application Note 8: TrendView Recorders DCOM Settings and Firewall Plus DCOM Settings for Trendview Historian Server

SONICWALL SONICOS ENHANCED 5.6 SINGLE SIGN-ON

Windows Firewall must be enabled on each host to allow Remote Administration. This option is not enabled by default

HOW TO CONFIGURE SQL SERVER REPORTING SERVICES IN ORDER TO DEPLOY REPORTING SERVICES REPORTS FOR DYNAMICS GP

Configuring Sponsor Authentication

DCOM Setup. User Manual

Active Directory integration with CloudByte ElastiStor

523 Non-ThinManager Components

Configuring Color Access on the WorkCentre 7120 Using Microsoft Active Directory Customer Tip

SQL Server Setup for Assistant/Pro applications Compliance Information Systems

Active Directory Management. Agent Deployment Guide

How To Upgrade Your Microsoft SQL Server for Accounting CS Version

Microsoft Active Directory Authentication with SonicOS 3.0 Enhanced and SonicOS SC 1.0 (CSM 2100CF)

OneLogin Integration User Guide

Cloud Services ADM. Agent Deployment Guide

How To - Implement Single Sign On Authentication with Active Directory

How To Install An Archive Service On An Exchange Server (For A Free) With A Free Version Of Ios (For Free) On A Windows Xp Or Windows 7 (For Windows) (For An Ubuntu) (

WMI Collecting Windows Logs

PRODUCT WHITE PAPER LABEL ARCHIVE. Adding and Configuring Active Directory Users in LABEL ARCHIVE

SmartConnect User Credentials 2012

F O U N D A T I O N. Using OPC via DCOM with Microsoft Windows XP Service Pack 2. Karl-Heinz Deiretsbacher, Siemens AG

NT Authentication Configuration Guide

Installation Troubleshooting Guide

Windows Server 2012 Directory Partition Containers- A Walk Through

Configuring EPM System for SAML2-based Federation Services SSO

Oracle Enterprise Manager

Deploying BitDefender Client Security and BitDefender Windows Server Solutions

SonicWALL CDP 5.0 Microsoft Exchange User Mailbox Backup and Restore

Active Directory Self-Service FAQ

Centralized Mac Home Directories On Windows Servers: Using Windows To Serve The Mac

This Deployment Guide is intended for administrators in charge of planning, implementing and

NAS 206 Using NAS with Windows Active Directory

AVG Business SSO Connecting to Active Directory

SOA Software API Gateway Appliance 7.1.x Administration Guide

Enabling Kerberos SSO in IBM Cognos Express on Windows Server 2008

System Administration and Log Management

Oracle Enterprise Manager. Description. Versions Supported

Upgrading User-ID. Tech Note PAN-OS , Palo Alto Networks, Inc.

Nexio Connectus with Nexio G-Scribe

BMC Performance Manager Windows Security White Paper DCOM / WMI

External Authentication with Citrix Secure Gateway - Presentation server Authenticating Users Using SecurAccess Server by SecurEnvoy

NETWRIX ACCOUNT LOCKOUT EXAMINER

CTERA Cloud Onramp for IBM Tivoli Storage Manager

FireSIGHT User Agent Configuration Guide

Instructions: Configuring Outlook 2003 with Exchange 2010 on the FIUMail

This document summarizes the steps of deploying ActiveVOS on oracle Weblogic Platform.

Setting up DCOM for Windows XP. Research

RSA Security Analytics

Kepware Technologies Remote OPC DA Quick Start Guide (DCOM)

UNCLASSIFIED DISABLING USB STORAGE DEVICES THROUGH GROUP POLICY

SQL Server Mirroring. Introduction. Setting up the databases for Mirroring

NETASQ SSO Agent Installation and deployment

NetBeat NAC Version 9.2 Build 4 Release Notes

PriveonLabs Research. Cisco Security Agent Protection Series:

MAPILab Reports for Hardware and Software Inventory Installation Guide. Document version 1.0

WMI syslog management of Windows AD Server V 1.1.2

Network Detective. Security Assessment Module Using the New Network Detective User Interface Quick Start Guide

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

Owner of the content within this article is Written by Marc Grote

Configuring Single Sign-On. Installing the SonicWALL SSO Agent

AN-022 Protégé Client / Server DCOM Configuration Windows XP SP2

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

Sage ERP Accpac 6.0A. SageCRM 7.0 I Integration Guide

E-Notebook SQL13.0 Desktop Migration and Upgrade Guide

3 Setting up Databases on a Microsoft SQL 7.0 Server

Insight Video Net. LLC. CMS 2.0. Quick Installation Guide

Transcription:

Network Security Read Domain Security Logs Contents Overview... 1 System or Network Requirements... 1 Deployment Considerations... 1 Configuring Non-Administrator Accounts for WMI Remote Access... 2 Glossary of Terms... 11 Overview The SonicWALL Directory Services Connector and the Single Sign-On Agent are used to identify users who are logged in to the Windows domain. In previous releases, the SSO Agent could be configured to use either WMI or NetAPI to communicate with user workstations for user identification, by using the Domain administrator account. In SonicWALL Directory Services Connector 3.4.55, a new Query Source option to use the Domain Controller Security Log is available, which does not require use of the Domain administrator account. This option still requires read access to the security log, but this can be accomplished for a non-admin account by using the method described in this technote. System or Network Requirements The following is a list of system or network requirements: Microsoft Windows Server 2003 or 2008 Deployment Considerations Consider the following when configuring non-administrator accounts for WMI remote access: Try the following configuration scenarios first, before configuring a non-administrator account for WMI remote access: o o If you are using a Single Sign-On (SSO) solution with the Query Source as a Domain Controller Security Log, you need to configure the Domain Admin or equivalent account with SSO. If the Domain Admin account is not available, configure a Domain User that has local admin privileges on the configured Domain Controller machine. A normal account can be used for WMI remote access and restricted with no login access, but needs certain read only rights to access the WMI repository remotely. The Distributed Component Object Model (DCOM) is used to execute the WMI queries. The Performance Monitor Users group has permissions for monitoring the Windows Security Event Logs on the Domain Controller (DC).

Configuring Non-Administrator Accounts for WMI Remote Access The best configuration procedure is to create/allow a user, and then add the user to the DCOM Users and Performance Monitor Users groups. The DCOM Users group already has remote access rights to the DCOM and the Performance Monitor Users group already has rights to read the performance counts. To configure nonadministrator accounts for WMI remote access, perform the steps in the following sections: Configuring the Domain Controller... 2 Configuring Windows Firewall... 7 Configuring the DCOM Access... 8 Updating Registry Settings for Windows 2003 and 2008... 10 Configuring the Domain Controller Perform the following steps on the Domain Controller: Note: This configuration example uses TestDomainUser as the username. 1. Create a normal (non-administrative) user. 2

2. Add the user to the Performance Monitor Users and DCOM Users groups. 3. Open the wmimgmt.msc window. 4. Select WMI Control (Local) from the left panel. 5. Select the Properties. 3

6. In the Properties window, select the Security tab. 7. Select the Root file, then click the Security button. 8. In the Enter the Object Names panel, enter the Performance Monitor Users group. 4

9. In the Security for Root window, enable the Executive Methods, Enable Account, and Remote Enable checkboxes. 10. Click the Advanced button. 11. Select the Performance Monitor Users group, then click the Edit button. 5

12. In the Apply Onto: field, click the drop-down list and select This namespace and subnamespaces. This allows read-only access to the whole WMI tree. 6

Configuring the Windows Firewall If the firewall blocks the remote WMI access, perform the following configuration steps on the Windows Firewall: 1. Navigate to the Windows Control Panel. 2. Click the Windows Firewall link. 3. In the left panel, select the Allow a program or feature through Windows Firewall option. 4. Navigate to Component Services > Computers > My Computer, then select Properties. 5. Select the Windows Management Instrumentation checkbox, then select the Domain and Home/Work (Private) checkboxes. 7

Configuring the DCOM Access If the predefined DCOM Users group is not used, perform the following configuration steps for DCOM access: 1. Start the dcomcnfg.exe. 2. Open Component Services > Computers > My Computer. 3. Select the Properties. 4. Click the COM Security tab. 5. In the Launch and Activate Permissions panel, click the Edit Limits button. 8

6. In the Group or User Names panel select Distributed COM Users. 7. In the Permissions for Distributed COM Users panel, select all the Allow checkboxes. 9

Updating Registry Settings for Windows 2003 and 2008 To read the Security Event Log you need to update the registry settings for Windows. Perform the following configuration steps to update your registry settings: Caution: Be very careful when changing the registry settings on your Domain Controller. Be sure to make a backup copy of the registry before making any changes. Windows 2003 1. Locate the Security Event Log Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security 2. Locate the original value of the CustomSD: O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG)(A;;0xf0005;;;SY)(A;;0x5;;;BA) 3. Insert the new value into the CustomSD: O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG)(A;;0xf0005;;;SY)(A;;0x5;;;BA)(A;;0x1;;;AU) Windows 2008 1. Configure WMI remote access (if not already completed in the previous sections). 2. Add the Event Log Readers group to the user account. 3. Add the TestDomainUser to the Event Log Readers group. 10

Glossary of Terms DCOM Distributed Component Object Model DC Domain Controller SSO Single Sign-On WMI Windows Management Instrumentation Last updated: 1/20/2012 11