List off registry keys that can be used to disable components.
Registry keys to disable components:
IMPORTANT NOTE: One warning here if these keys are used without understanding what they do, you can end up disabling subsystems that have unintended consequences. We recommend testing any of these settings carefully before putting the changes into production.
In the information below, "Base License" refers to the standard, non-ADHealth Active Administrator license. Certificate license is a separate license included in the base license. Keys with "no-license" are subsystems that are active for all license types.
All of the values below must be created under the key Subsystems inside of the AFS key. The Subsystems key must be created.
"HKEY_LOCAL_MACHINE\SOFTWARE\Quest\Active Administrator\Settings\AFS\Subsystems"
Setting any of the values below to "1" will disable the associated subsystem.
Listed below are the subsystems that can be turned off, together with their registry value names, and their required license:
• "SmServiceMonitor_Disabled", Base license. Long-lived monitoring thread that checks the status of the other services including. Disabling breaks use of the console and ADS communication in multiple modules.
o ADS service
o Notification service
o Audit Agent service (but only on the local machine)
• "LockedOutAccountWatcher_Disabled", base license. A background worker that periodically checks for locked out accounts for that module. Causes object reference errors when disabled in the Locked Out Accounts module.
• Various certificate-related background services including:
o "CertificateWatcher_Disabled", certificate license. Periodically monitors managed computers for changes in their certificates (added/removed/etc.) in Certificates module.
o "CertificateMonitoredObjectWatcher_Disabled", certificate license. Periodically monitors AD objects (groups & OUs) via which managed computers can be automatically added to Certificates module.
o "CertificateAuthorityWatcher_Disabled", certificate license. Periodically monitors changes to certificate authorities. These authorities can affect the status of existing certificates in Certificates module.
o "CertificateAuthorityBackupScheduler_Disabled", certificate license. Manages the schedule of certificate authority backups in Certificate Authority submodule of Certificates module.
o "CertificateAuthorityCacheManager_Disabled", certificate license. Keeps a cache of the recognized certificate authorities and their statuses so lookups are not necessary each time a certificate's validation chain is checked in Certificates module.
• Various Group-Policy-related background services including:
o "GpoHistoryWatcher_Disabled", base license. Watches for changes to GPOs and performs backups of GPO History items when they change. GPO History submodule of Group Policy module.
o "AdmxPolicySyncScheduler_Disabled", base license. Periodically keeps ADMX files in sync for GPO Backups under Group Policy module.
o "GpoBackupScheduler_Disabled", base license. Manages the backup schedule for GPOs in GPO Backups submodule of Group Policy module.
• "ADSIPCClient_Disabled", no license. The background worker that handles communication between the AFS and ADS services. Also affects Web console communication on pages that load AD health info. Causes ADSIPC errors in web console when disabled.
• "LicenseMonitor_Disabled", no license. Periodically checks for changes in the AA license. Affects updating of the license status under Settings>License Dashboard. We only ever validate licenses on service startup.
• "AccountExpirationWatcher_Disabled", base license. Periodically checks for accounts that have expired for the Expired Accounts submodule of Security & Delegation.
• "DAAgentDeployWatcher_Disabled", ADHealth license. Affects functionality to automatically deploy an AD Health agent to newly-discovered domain controllers in AD health module.
• "DelegationWatcher_Disabled", base license. Periodically watches for changes in Active Template delegation in Active Templates submodule of Security & Delegation module.
• "PurgeArchiveScheduler_Disabled", no license. Manages the schedules for purging archives in multiple modules that support purging.
• "DcDiscoveryNotification_Disabled", base license. Periodically notifies about the discovery of new domain controllers. Multiple modules.
• "InactiveAccounts_Disabled", base license. Periodically monitors AD for inactive user and computer accounts in Inactive Accounts submodule of Security & Delegation.
• "ChangePasswordReminder_Disabled", base license. Periodically monitors AD for accounts that have not changed their passwords
• "ReplicationMonitoring_Disabled", base license. Periodically monitors replication status between domain controllers in Replication Monitor submodule of Active Directory Infrastructure module.
• "ADObjectCounts_Disabled", no license. Periodically counts the number of various classes of objects in active directory for multiple modules.
• "ForestDiscoveryScheduler_Disabled", no license. Periodically scans for newly accessible forests for multiple modules.
• "SnmpNotifications_Disabled", no license. SNMP under Configuration module.
• "ScomNotifications", no license. SCOM under Configuration module.
• "ScomAlertEventProcessing", base license. SCOM under Configuration module.
o "AlertCacheFolderPurge", base license, SCOM under Configuration module.
o "AlertCacheProcessor", base license. SCOM under Configuration module.
• "AuditReportScheduler", no license. Manages the schedules of audit reports in Auditing & Alerting module.
• "CertificateReportScheduler", certificate license. Manages the schedules of certificate-related reports in Certificates module.
• "ADBackupScheduler", base license. Manages the schedules of active directory backups in Recovery module.
• "ConfigurationReportScheduler", no license. Manages the schedules of the Server Configuration report under Settings.
• "ADHealthAgentsPerformanceReportScheduler", ADHealth license. Manages the schedules of the AD Health agent performance report.
• "AssessmentReportScheduler", base license. Manages the schedule of the Assessment report under Settings.
• "AllObjectReportScheduler", base license. Manages the schedule of the All Object report under Settings.
• "DnsMonitoring", base license. Monitors the DNS monitoring feature of DNS Monitoring submodule of DNS module.
• "DefaultAlertImporter", no license. Handles importing alerts or Auditing & Alerting module.
• "DefaultReportImporter", no license. Handles importing reports for Auditing & Alerting module.
• "EventDefinitionImporter", no license. Handles importing event definitions for the Auditing & Alerting module.