Community FAQ
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Markus_G
Engaged Sweeper

Hi all

Is it possible to use Lansweeper Deployment to install and update software on domain controllers without giving the scanning account domain admin permissions?

I use Lansweeper Deployment to keep Notepad++ updated on our servers. Works like a charm, except on domain controllers. DCs don't have local users and groups, so I'm unable to add our scanning account to the (non-existent) local administrators group on DCs. And promoting the scanning account to domain admin is not an option.

According to this KB article, the scanning credential must have access to administrative share C$ on the target computer, which is not the case on DCs.

Any ideas on a solution?

Kind regards,
Markus

2 REPLIES 2
Markus_G
Engaged Sweeper

Hi David,

Thank you for confirming that I didn't miss anything obvious. I'll continue to update our DCs manually.

Hopefully this post will help someone else find the answer to this question I was looking for.

DavidPK
Lansweeper Tech Support
Lansweeper Tech Support

Hi Markus, 

 

Thank you for your inquiry regarding software deployment to domain controllers using Lansweeper Deployment.
 

Unfortunately, due to the fundamental Microsoft Windows security restrictions on domain controllers, there is no direct workaround to deploy software via Lansweeper Deployment without elevated privileges. As you noted, access to the C$ administrative share is required, and domain controllers strictly limit this access.

 

Deployment Packages

Share topics/ issues related to deployment packages. Please use/rely on content with caution as it is publicly generated.

New to Lansweeper?

Try Lansweeper For Free

Experience Lansweeper with your own data.
Sign up now for a 14-day free trial.

Try Now