Skip to main content
The DFS scan module captures DFS servers, namespaces, folder targets and their share permissions. It requires a connected gateway.

Captured data

The scan creates assets of these two types: How the detail pages of the types are structured is described in Directory and Network Services.

Setting up the job

The wizard follows the standard path Basics › Targets › Schedule › Summary—see Creating a Scan Job. The Targets step is what sets this module apart. Each row carries the columns Server Name and Credentials. Server Name takes one namespace server per row, as an address or hostname; the column does not accept an address range. Search DFS Servers fills in the servers from Active Directory instead: the dialog asks for the Domain and credentials and adds the DFS servers it finds as rows.
Search DFS Servers finds domain-based DFS servers only if the Namespace Server role is installed on them. Enter standalone namespace servers as rows by hand.
The Credentials column may stay empty. The scan then runs under the gateway’s service account, and that account needs the rights listed under Permissions. An entry in Credentials for all targets applies to every row without an assignment of its own.

Prerequisites

The scan connects to the DFS servers over WMI and to a domain controller over LDAP.

Ports and protocols

Permissions

  • The account is a domain user, entered as DOMAIN\user or user@domain.local.
  • It is a member of the local Administrators group on the namespace servers.
  • It is a member of the local Administrators group on the servers that provide resources for the DFS.

Network requirements

  • The firewall allows the ports above.
  • PowerShell can run on the DFS servers.
  • User Account Control (UAC) is set up for the account’s remote access.
If the folder targets are on servers other than the namespaces, access from the gateway through the namespace server to those servers is a double hop, which Windows does not allow. In that case, scan the DFS directly on the namespace servers with the Discovery-DFS.exe scan script—see Scanning by Script. For DFS this is the recommended way.

Common issues

After it is created, the job appears among the jobs; how you watch and adjust it is in Managing Jobs. How you provide and run the scan scripts and read in their results is in Scanning by Script.