> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Tutorial: The First Scan

> From an empty tenant to a typed inventory: install the gateway, create credentials, scan Active Directory and Windows, type unknown systems.

We put a new tenant into operation: one gateway, one Active Directory, the
Windows servers of the domain. At the end the inventory is in *Assets*, and the
systems no module could assign are typed.

**Prerequisites**

* A Windows server or Windows VM in the network with outbound HTTPS. No inbound
  ports are required.
* A domain account that can read Active Directory.
* An account with local administrator rights on the Windows servers.
* A Docusnap365 user with the role *Administrator*.

## 1. Install the gateway

We download the setup under *Scan › Gateways › Download Gateway* and run it on
the Windows server. The setup installs the service and the configuration
application.

In the configuration application we sign in with our Docusnap365 user and
register the gateway for our tenant. After registration the gateway appears
under *Scan › Gateways* with the state *Online*.

<Note>
  A gateway belongs to exactly one tenant. A second tenant needs a second gateway.
</Note>

## 2. Create credentials

Under *Scan › Credentials* we create two entries:

| Entry | Type | Use |
| - | - | - |
| *AD Reader* | *User Account* | domain account for the Active Directory scan |
| *Server Admin* | *User Account* | local administrator for the Windows servers |

Storage mode: *Reusable*. The entries are stored encrypted in the *Vault* and are
available to every job.

<Note>
  An entry with an *Expiry Date* appears under *Action Required* on the dashboard
  before it expires. We set the expiry date to the date the account's password
  expires.
</Note>

## 3. Scan Active Directory

We create the first job: *Scan › Scan Job*, module *Active Directory*.

| Step | Input |
| - | - |
| *Basics* | name *AD Headquarters*, gateway from step 1 |
| *Targets & Authentication* | domain controller as target, credentials *AD Reader* |
| *Scheduling* | *Once*, *Run immediately* |
| *Summary* | check, *Run now* |

The job appears under *Scan › Active*. After the run, *Last Result* shows
*Successful*. *Assets* now lists the domain, users, groups and computer accounts.

<Warning>
  *Successful (no data)* means the job ran but captured nothing. The cause is
  usually the target or the account's permissions. We open the job and read
  *Details of the last scan*.
</Warning>

## 4. Scan Windows servers

The second job captures the servers the Active Directory scan found: module
*Windows (AD)*. The module reads the computer accounts of the domain and scans
the systems behind them.

| Step | Input |
| - | - |
| *Basics* | name *Windows Servers*, gateway from step 1 |
| *Targets & Authentication* | domain from step 3, credentials *Server Admin* |
| *Scheduling* | *Daily*, 02:00 |
| *Summary* | check, *Schedule job* |

For the first run we start the job with *Run now*.

<Note>
  *Windows (AD)* requires a completed Active Directory scan. Without it, the domain
  cannot be selected in the step *Targets & Authentication*.
</Note>

After the run, *Assets* lists the servers with hardware, operating system,
software and services.

## 5. Type unknown systems

The dashboard shows under *Unknown Systems* the number of systems a scan found
but could not assign to a type — printers, switches, devices without Windows.

We open *Scan › Unknown Systems*, select the systems of one type and assign the
type via *Edit entries*. For systems a scan module can capture — switches via
*SNMPv1/v2*, printers via *IP Hosts* — we create another job instead.

<Note>
  A typed system is an asset. It disappears from *Unknown Systems* and appears under
  *Assets*.
</Note>

## Result

* One gateway *Online*
* Two credential entries in the vault
* Two jobs: *AD Headquarters* (once) and *Windows Servers* (daily)
* The inventory under *Assets*, unknown systems typed

## What's next

* Capture further sources: [Scan Modules – Overview](/docs/en/scan/scan-modules)
* Give assets owners and a lifecycle: [Recording ITAM Data](/docs/en/itam/manage-data)
* Monitor jobs and follow up on failures: [Managing Jobs](/docs/en/scan/manage-jobs)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.