Logged in user:
- To install, it must have administrator access on the local computer.
- To create the Enterprise Reporter database, the logged in user (Windows Auth) or SQL account must have rights to create databases, logins and groups on the SQL server.
- Must have rights to create groups in Active Directory
- Must be able to enumerate the targets during scope selection, unless alternate credentials are provided for the discovery.
Enterprise Reporter service account:
- It must have Login as service right on the machine that its being installed.
- It will be automatically granted Read and Write permissions on the Enterprise Reporter database (Windows Auth.)
- If the server is configured to use SQL authentication, the SQL credentials will be used to access the database not the service account.
- Must be able to write to the Admin$ share to deploy the node (local admin rights)
Node credentials:
-Read access on all targets.
-OR Local administrator access to the target computer (depending on the discovery)
-Local administrator access to the host computer – provide job status, errors, statistics and logs.
-Read and Write access to the Enterprise Reporter database.
-If you use SQL authentication to connect to the database, you must manually permission the SQL user (adding them to role Discovery_Admin_Role (recommended) or by permissioning specific tables in the database.
-Read and Write access to the shared data location.
-If required, you can configure alternate credentials for specific discoveries.
Discovery credentials (Alternate credentials):
-Read access to all targets of the discovery.
-OR Local administrator access to the target computer (depending on the discovery)
Service accounts for managed computer (Access Explorer):
- Needs sysadmin rights on the SQL server in order to create the database. Once the database is created, the service account can be granted dbowner rights on the database alone.
- The database has to be created using the wizard.
- Full Administrator rights are required on the Netapp filer / EMC
- Local Administrator rights for managed computers (recommended).
- Able to do group expansion and SID resolution for managed accounts and their membership (Domain Admin recommended).
- Please review the following KB article for the minimum permissions to run Quest Access Manager (https://support.quest.com/SolutionDetail.aspx?id=SOL81018 )
© 2024 Quest Software Inc. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy Cookie Preference Center