PDF

Active Directory Integration

It makes agentless Windows monitoring much easier.

Server Integration

NetCrunch runs on Windows Server and needs to integrate with Active Directory in order to properly access other Windows machines in the domain.

Starting from Windows 2003, every newer Windows Server version takes security settings to a higher level. This makes it impossible to access Windows machines without explicitly setting access rights.

When installing on a Server in Active Directory
  • The default option is to run the program on the local system account (which makes easy accessing local resources and communication between server components) and set up default credentials, common profile, or credentials for each machine (it's easy, as you can use multi-selection to do it). The only drawback is that it might trigger a security warning on some server systems, as the process running under the local system account first attaches as a machine object (machines are separate objects in AD), then logs in with the given credentials.

  • You can run NetCrunch Server services on a domain account that is a member of the local Administrator group of each monitored computer (including the server running NetCrunch Server). Sometimes it's a good solution, but it can also be hard or impossible to configure. It requires modifying AD security policies (remember, they need time to replicate).

Setting Active Directory account for the NetCrunch will give you:
  • Proper security settings to remotely access performance data (Remote Registry, WMI, CIM).
  • Access to AD information about computers and their systems.

You will still be able to access other Windows machines by giving local credentials for them, but it means that you have to input the necessary settings for each of them individually

User Accounts Integration

NetCrunch can use Active Directory user accounts as NetCrunch users. This allows keeping single passwords and makes management easier.

All you need to do is tick the Active Directory User checkbox when adding a new user. The username should be in the format: <Domain>\.

Managing NetCrunch Users through Active Directory Groups

You can manage access to NetCrunch by assigning access profiles to Active Directory groups.

A member of such a group can log in to NetCrunch with AD credentials and will receive the NetCrunch account automatically. NetCrunch will assign an access profile according to the group setting.

If the user is a member of multiple AD groups, he will receive his profile according to the order of the groups.

active directoryadad groupsgroupsintegration