The Community is now in read-only mode to prepare for the launch of the new Flexera Community. During this time, you will be unable to register, log in, or access customer resources. Click here for more information.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Flexnet agent installation on Domain Controllers

krystel_campos
By
Level 5

Hi , is there a way to get the agent installed or a workaround for DCs, we have tried different agent versions and we cannot get the policy to run since it has no local admin account to get it installed.

(1) Solution

cdubs76
By
Level 6

Krystel,

We worked with our Directory services team on a smiliar situation--and we just provided them the ndtrack.exe and they placed it in a temp folder on the DC and setup a scheduled task to run once a month (or could do on any schedule you wish) to run the ndtrack with desired options and passing the argument of the beacon to upload the inventory to.  Worked like a charm.

View solution in original post

(5) Replies

cdubs76
By
Level 6

Krystel,

We worked with our Directory services team on a smiliar situation--and we just provided them the ndtrack.exe and they placed it in a temp folder on the DC and setup a scheduled task to run once a month (or could do on any schedule you wish) to run the ndtrack with desired options and passing the argument of the beacon to upload the inventory to.  Worked like a charm.

ChrisG
By Level 20 Flexeran
Level 20 Flexeran
I'm not sure I entirely follow what the challenge is here. Most Windows software requires local admin rights to be installed. How do your team normally install software on domain controllers? Is there any reason why that process can't be followed for the FlexNet inventory agent?
(Did my reply solve the question? Click "ACCEPT AS SOLUTION" to help others find answers faster. Liked something? Click "KUDO". Anything expressed here is my own view and not necessarily that of my employer, Flexera.)

Agree with chris. Every DC have domain admin account if local account has been disabled due to security policy. 

 

There must LAPS implementation to retrieve  local admin just in case emergency.

In my case...it was the directory services team didn't want to install the agent.  not that it couldn't be done--they just didn't want to.  My implementation was something to make everyone happy :D.

mag00_75
By Level 8 Champion
Level 8 Champion
Hi
We have a domain controller policy not to install agents, so we resolved it by developing a powershell script that produce virtualisation and software inventory. Then we have an inventory adapter to import it.

For other high security environments we use the core components only, to reduce risks etc