This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

How to setup ARM to only scan certain Domain Controllers in my Domain and not all of them?

Because of my my organization structure, the service account used to manage ARM does not have Domain admin permissions however it has elevated privileges, because of this, ARM fails to connect to Domain controllers located outside of our local site, This has caused some alerts within our network security team since they see ARM trying and retrying to connect to those domain controllers without success. They has asked if is possible to setup ARM to see and scan only specified domain controllers by editing the server Host file. 

Will appreciate any answer or Idea you can provide to deal with this? 

  • Hi Chris,

    usually ARM scanner is not collaborating with a specific DC. It uses the DC which is provided by the operating system. Please ensure that the default DC is set properly in the environment of the ARM server host or in the ARM collector if you use one. Due to the fact that you have more than one sites I think you will have one or more local DCs anyhow. It would be really unusual and not intended to get in contact with a non local-DC.

    Hope this helps

    Norbert