Password Discovery Script Requirements
The following Discovery jobs are provided to help discover Local Admin Accounts on your network, and various ‘Windows Resources’ – such as Windows Services, IIS Application Pools and Scheduled Tasks, database accounts, network accounts, etc:
- Active Directory accounts
- Cisco IOS accounts
- Fortigate accounts
- HP H3C accounts
- Juniper Junos accounts
- Linux and MAC accounts
- Microsoft SQL Database accounts
- MariaDB Database accounts
- MySQL Database accounts
- Oracle Database accounts
- PostgreSQL Database accounts
- SonicWALL accounts
- Windows Dependency accounts such as domain accounts used on Windows Services, IIS Application Pools and Windows Scheduled Tasks
- VMWare ESXi accounts
Note 1: Each of the Discovery jobs above have the same System Requirements as their respective Password Reset Scripts.
Note 2: For SQL Server account discoveries, the Privileged Account Credential you are using to perform resets must have the ‘ALTER ANY LOGIN’ permission as minimum. The Privileged Account Credential can be either an SQL Account, or an Active Directory Account - if an Active Directory account, the Username field must be in the format of domain\Username. Your SQL Server must be configured in mixed-mode authentication in order to discover SQL Accounts.
Note 3: For Windows operating systems, Server 2016 and above are supported.
Note 4: The Active Directory ‘Password Reset’ and ‘Account Discovery’ features requires the ‘Remote Server Administration Tools (RSAT)’ to be installed on your Passwordstate web server, or where you have deployed the ‘Remote Site Locations Agent’. On Windows Server Operating Systems, you can install this by running the following PowerShell command (run PowerShell as Admin):
Powershell
Add-WindowsFeature RSAT-AD-PowerShellOpen Ports Requirements
For a full list of open port requirements for Password Resets, you can refer to section ‘Account Discoveries’ in the following document - Open Ports Requirements