cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
santokhsingh
Engaged Sweeper
What type of access the lansweeper account requires for Active Directory. I am not comfortable giving domain admin access.
2 REPLIES 2
daem0n647
Engaged Sweeper
I used a simple GPO startup/shutdown script for a custom domain user created with an extremely tough password:

add_username_to_localadmins.cmd
net localgroup LocalAdministratorsGroupLocalisedInYourLanguage /add your.domain.name\username
net localgroup Administrators /add your.domain.name\username


And also I had to manually add them to the servers (not to reboot).

You might also wish to use psexec.exe :
psexec \\* -n 5 -s -d net localgroup Administrators /add your.domain.name\username
Anonymous
Not applicable
It only needs to read AD, I don't have that user as a domain admin either. The LS account must be admin os the server where it runs the service, and administrator of the computers to scan.