One of our customers has a requirement to monitor their Domain Controllers but are very hesitant to allow any sort of local credentials. I've been reviewing the template that's in the trial of SAM and it lists the prereqs as 1, local admin; 2, enable WinRM; 3, some auditing on different events.
My question is, do these prerequisites still apply if we use the SW agent on the domain controllers?
And if not,
I know you need admin rights to install the agent, but do you still need admin rights to monitor using the agent? Even then I suppose we could give the agent to the customer to install on our behalf and never even have to worry about creds.
I do see some of the monitors in the template only have a fetching method of WMI or RPC - does that somehow depend on whether or not you have the template set to agent or agentless?
Please bear with me as I'm a SAM newbie and we haven't even purchased the SAM module yet. We will get professional training once the purchase is made but until then I'm at the mercy of the trial software!
Thanks you.