予定されていた保守を実行中のため、サポートサイトでのフォームの送信が一時的に利用できません。 すぐにサポートが必要な場合は、テクニカルサポートまでお問い合わせください。 ご不便をおかけして申し訳ありません。
オンラインヘルプの参照
登録の完了
サインイン
価格設定をリクエスト
営業担当に連絡
製品バンドルが選択されました。 リクエストにより良く対応できるように、個別の製品を選択していただけますか? *
現在、テクニカル・サポート・エンジニアはお客様のチャットに対応できません。 迅速にサービスを受けられるよう、サービス・リクエスト・フォームを使用して
お客様の説明に基づいて、以下の記事が問題解決に役立つ可能性があります。
Depending on the reports that will be run, you may need to collect data to show nested group memberships. It is more efficient to collect to group members through Active Directory discoveries than using the nested group membership options in individual discoveries of other types. This also helps avoid collecting the same accounts in multiple discoveries. The recommended practice for collecting nested group members is to:
Depending on the reports that will be run, you may need to collect data to show nested group memberships. It is more efficient to collect group members through the Microsoft Entra ID discoveries than using the nested group membership option on the Azure Resource, Exchange Online, or OneDrive discovery.This also helps to avoid collecting the same accounts in multiple discoveries.
The following sections outline the permission requirements for discoveries.
See also:
The following table outlines the permissions required for Enterprise Reporter discoveries.
Active Directory
An account with Active Directory read permissions is required to collect domain information, trusts, sites, domain controllers, and Active Directory computers, users, groups, and organizational units.
The account being a member of the Built-in Domain Users group is sufficient to assign read permissions.
To collect Fine Grained Password Policy and AD object level permissions, Domain Admin is required.
Microsoft Entra ID
An account with Global Reader, Report Reader and Hybrid Identity Administrator Role is required for the discovery target tenant.
The Read permissions are required to collect tenant information, Microsoft Entra users, groups, group members, roles, and service principals.
If additional credentials are being specified to minimize Azure throttling limitations, these credentials must have the same permissions as stated above.
Also refer to credentials required to create and consent to the Enterprise Reporter Microsoft Entra application required for this discovery.
Azure Resource
An identity with read permissions for the discovery target tenant. Read permissions are required for collection of subscription, Resource groups, and resources.
Also refer to credentials required to create and consent to the Enterprise Reporter Azure Resource application required for this discovery.
Computer
An account with local administrator access on the scope computers to collect computer information, local groups and users, printers, services, policies, and event logs.
Exchange
To collect from Exchange targets, the credential account must have a mailbox on the target organization with access to read the permissions on the targets through EWS.
To collect from Exchange 2013, 2016, or Mixed Modes, the credentials must be a member of the Organization Management Group.
To collect from Exchange 2016 or Exchange 2019, the credentials must have an administrator role with an assigned “ApplicationImpersonation” role.
Exchange Online
The Exchange Online uses certificate authentication. To register certificate with the tenant application, use the Tenant Application Manager. See Managing Tenant Applications in the Configuration Manager User Guide.
File Storage Analysis
An account with local administrator access on the scoped computer is required to collect file, folder, share, and home drive analysis data.
For permissions required when collecting NAS devices, see Permissions for Enterprise Reporter discoveries on NAS devices .
Microsoft SQL
An account with local administrator access on the SQL Server is required.
Additionally, the account must have read access to the scoped database to collect database information.
At a minimum, if not using fixed roles, the following SQL permissions are required on the securable object being used for collection.
Microsoft Teams
The user credentials used to collect Microsoft Teams information must have either the Teams Administrator or Global Administrator permissions.
The user must also be a member of each Microsoft Teams group to prevent access denied errors during disk discovery.
Also refer to credentials required to create and consent to the Enterprise Reporter Microsoft Teams application required for this discovery.
In addition for the collection of Microsoft Teams settings and policies certificate authentication is used. To register certificate with the tenant application, use the Tenant Application Manager. See Managing Tenant Applications in the Configuration Manager User Guide.
NTFS
If collecting through the administrator share, an account with local administrator access to the scoped computer is required.
If collecting through a network share, an account with read permissions to the scoped shares is required.
OneDrive
An account with access to the discovery target tenant. Administrator permissions are required for collection of all drives including drive information, configuration settings, files, folders, and permissions. A SharePoint administrator role is recommended.
Additionally, the discovery credentials must have site collection administrator rights to each drive that is being collected.
Also refer to credentials required to create and consent to the Enterprise Reporter OneDrive application required for this discovery.
Registry
An account with local administrator access to the scoped computer is required to collect registry information.
SharePoint Online
An account with access to the discovery target tenant. Administrator permissions are required for collection of all SharePoint Online site collections, including tenant settings and policies, site information, and permissions. A SharePoint administrator role is recommended.
Additionally, the discovery credentials must have site collection administrator rights to each site collection that is being collected. If additional credentials are being specified to minimize Azure throttling limitations, these credentials must have the same permissions as stated above.
Also refer to credentials required to create and consent to the Enterprise Reporter SharePoint Online application required for this discovery.
Quest *product*のオンラインサポートヘルプは、関連会社のサポートサイトで参照できます。「Continue(続行)」をクリックすると、*product*の適切なサポートコンテンツとアシスタンスへ移動します。
The document was helpful.
評価を選択
I easily found the information I needed.
Quest Softwareポータルでは、IE8、9、10のサポートを終了しました。ブラウザを最新バージョンのInternet ExplorerまたはChromeにアップグレードすることをお勧めします。
IE 11へのアップグレード: ここをクリック
Chromeへのアップグレード: ここをクリック
の優れたセルフサービス機能を最大限に活用していただけるよう、IE8、9、10以外のブラウザをぜひご利用ください。