The Change Auditor foreign forest agent needs to authenticate the primary forest in which the Change Auditor coordinator is hosted on behalf of the account which has the Change Auditor Agents AD security group membership.
Such account may have the read-only permissions which is sufficient under the regular normal circumstances.
However, in certain cases such authentication effort may fall under a restrictive policy which entirely depends on the particular configuration of the given scenario.
By default, there are no such restrictive policies.
However, need to keep such in mind and verify in case the following errors appear in the Change Auditor agent logs.
- in the "AgentServiceProxy.Log.nptlog" log file on the C.A. Agent: "xxx Exception: The server has rejected the client credentials. xxx Exception: The logon attempt failed",
- on the C.A. Coord. Server in the Security event log: #4625 "An account failed to log on." with "logon type” 3 and "Account Name" the foreign agent credential
When deploying agents in the foreign forest, the agents use the foreign agent credential / account to reach back into the forest where the Change Auditor Coordinator server is hosted.
That account does not require any specific privileges, just needs to be a member of the "ChangeAuditor Agents - InstallName" AD security group.
However, some customers implement hardening GPOs and tiered servers usually create GPOs with specific groups set on either "Access this computer from the network" or "Deny access to this computer from the network".
In such scenario, the Foreign Agent Credential account should be added to the policy setting.
The policy settings can be found under "Computer Configuration|Policies|Windows Settings|Security Settings|Local Policies|User Rights Assignment".