Skip to main content
Four scan modules capture the services that hold a network together. Each creates the service as its own asset — not as a section on the server it runs on.

Active Directory

The scan creates three types: the directory itself, plus users and groups as independent assets.
A directory account and its counterpart in Entra ID remain two separate assets. A dedicated type records that both mean the same person — see Cloud and Identity.

DNS

Created by Windows DNS. Three groups: Service Configuration (server overview, recursion behavior, security settings, forwarders, root hints, zone delegations), Zones (primary and secondary zones), and Statistics.

DHCP

Created by Windows DHCP. Five groups, following the structure of the service itself: General, IPv4 Settings (network adapters, high availability, policies, classes, option definitions), IPv4 Scopes, IPv4 Scope Exclusions, and IPv4 Server Statistics.

DFS

Created by DFS, in two types: DFS Domain for the domain-based namespace — with namespaces, DFS servers, folder targets and access rights, plus its own Replication group (replication groups, memberships, connections, replicated folders) — and DFS Standalone for the stand-alone namespace, without replication and without participating servers.
The Access Rights area carries the permissions per folder and target. For evaluating file-system and share permissions as a whole, the NTFS Security scan is responsible — see Storage, Backup, Permissions.

NTFS

The NTFS Security type is created by the scan module of the same name, but carries no view of its own. You evaluate a share’s permission structure in File System. Credentials and target details for Active Directory are under Active Directory, for the other modules in the Scan Reference. What the databases on these servers hold is described under Databases.