The Community is now in read-only mode to prepare for the launch of the new Flexera Community. During this time, you will be unable to register, log in, or access customer resources. Click here for more information.
Hi Team, We have recently deployed FNMS and integrated the same with SCCM and Vcenter.Now when we are trying to create accounts for different users in FNMS and searching user id in the create account page, we are seeing all the active directory users are available for selection and we can login to FNMS using AD credential.We didn't integrate any domain controller with beacon server, still how active directory data is coming in FNMS?
Also we can see by default some active directory schedule import is running in beacon server where domain controller is showing as current domain with no user id/passoword. The account which we have used for beacon configuration shouldn't have access in domain controller.
Thanks
Suman
‎Oct 17, 2019 01:39 AM
Hi Suman,
The AD queries that the beacon makes don't require privileged credentials to execute. Any domain user can normally run the same queries to "read" the same level of info the beacon collects. So, by default a standard install of the beacon will be primed to collect AD data from the domain it is connected to. If you don't want the beacon to collect AD data it would be best to remove the task, or make sure there is no active schedule for it.
-Murray
‎Oct 17, 2019 01:58 AM
Hi Suman,
The AD queries that the beacon makes don't require privileged credentials to execute. Any domain user can normally run the same queries to "read" the same level of info the beacon collects. So, by default a standard install of the beacon will be primed to collect AD data from the domain it is connected to. If you don't want the beacon to collect AD data it would be best to remove the task, or make sure there is no active schedule for it.
-Murray
‎Oct 17, 2019 01:58 AM
Hi Murray, Thanks for your quick response.As you mentioned that domain user can make normal queries in AD without any specific credential, along with that port 389 was already open from beacon to AD server and thats why beacon started collecting data.In other products we had to explicitly configure these details to fetch AD info.Thats why i was wondering how active directory data is getting synced automatically.
Thanks
Suman
‎Oct 17, 2019 02:16 AM
Hi Suman,
After installation, there is a default Active Directory connection configured in the Beacon UI. However, there is a number of prerequisites for any Beacon for collecting data from Active Directory:
Since you apparently did import data from SCCM sucessfully, could it potentially be that users have been imported from SCCM?
‎Oct 17, 2019 03:26 AM
Hi Elindeman,
Thanks for your response.
We have not configured any valid domain name and its running with "Current domain".Even the connection is running in a schedule and importing active directory data.Please refer attached screenshot.
Regarding SCCM import, i believe only asset users can be imported through this integration.Here i am able to login to FNMS using these AD credential which is not possible if its not connected to AD.
Thanks
Suman
‎Oct 17, 2019 03:41 AM
A couple of clarifications to @statler's comments:
‎Oct 17, 2019 03:43 AM