This section defines all of the components that comprise an Access Explorer deployment.
• |
• |
To ensure that the Access Explorer service can install agents successfully, the Security Explorer® server needs domain user credentials with sufficient access. Access Explorer uses the concept of a managed domain, which is an association of service accounts (user credentials) to Active Directory® domains. When a new service account is added in the configuration, it is automatically granted the required Log On as a Service local user right on the Security Explorer server. This managed domain service account is used to install the agents. Local agents run as Local System and remote agents run as the service account specified during their installation.
For more information, see Adding managed domains.
To register a forest, add the forest to Access Explorer. See Adding forests. When you add a forest, you must provide a service account with sufficient permissions to perform all Access Explorer configuration tasks. If the application needs to resolve a SID or expand group membership from that forest, it will use the associated service account.
When you add a managed domain and the associated Active Directory® forest is not yet registered, the Security Explorer Server will automatically add the forest and use the domain service account credentials as the forest credentials.
A managed computer is any network object that can host resources such as files, folders, and shares. Currently supported resources include Windows® computers, Windows® clusters, and certain network attached storage (NAS) devices. When the user adds a managed computer, Configuration Manager deploys an Access Explorer agent to scan that computer. The agent may be installed on the computer (local agent) or it may be installed on another computer (remote agent). Detailed access information is maintained on the agent computer, only sending general access information to the server.
© ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center