Skip to main content
There are two scan modules for Windows systems. They capture the same thing – the difference is where the targets come from: Both ways can run side by side: the domain over Windows (AD), the exceptions over Windows (IP). The component selection is the same for both. In both cases a connected gateway is required, plus an account allowed to sign in to the target systems.

Path A – Windows (AD)

The wizard shows five steps: Basics › Authentication › Scan Scope › Schedule › Summary Basics, Schedule and Summary are the same for every module – see Creating a Scan Job. Characteristic are the two steps in the middle.

Authentication

The step takes the Domain first and the Windows credentials below it: first it is settled which domain is captured, then which credentials are used. If the domain field is visible, it must be filled. You choose the credentials in a searchable picker. In first position stands the entry that lets the scan run under the gateway service’s account. Above it two rows create a new entry: New credentials… a reusable one, One-time credentials… one that applies to this job only.
Windows (AD) and Active Directory are the two modules where credentials are not enforced: the step can be passed without an entry. Whether the scan then succeeds depends on which account the gateway service runs under in your network. For the first job an explicitly stored account is advisable.
Credentials entered once make the job not restartable later – to run it again they have to be entered afresh through Edit. For a recurring scan it is better to store them as a reusable entry in the Vault.

Scan Scope

The step carries two sections: System Selection and Windows Components. The initial state of System Selection is the full set: by default all Windows systems from Active Directory are scanned, and the selection can optionally be restricted. For a first job that is enough; the step can be passed without an entry. Restrict selection… opens the Select Systems dialog, which searches Active Directory. You can narrow it down through the Filter… field, the Servers Only toggle and the state filters Active and Disabled; Select All takes the set found all at once.
The dialog needs three entries from the previous steps: gateway, domain and credentials. If one is missing, go back to Basics or Authentication.
Servers Only together with the state filter Active limits the selection to active servers; clients and disabled accounts stay out. You add the clients later with a second job.

Path B – Windows (IP)

Here the wizard follows the standard path through the Targets step: one row per target, with the columns IP/Hostname and Credentials. Into the target column may go a single address, a range, a network in CIDR notation (e.g. /24) or a hostname – a whole network therefore fits into one row. The Credentials for all targets picker above the table applies to all rows without their own assignment; per row it can be deviated from. The details are in Creating a Scan Job.

Windows components

With both paths the most extensive option sits in the Windows Components section behind the Customize button: 22 options, 20 of them preselected. Not preselected are Certificates: Root and Browser Extensions.
Leave the preselection untouched for the first job. Afterwards you see in the job summary under Components how many were selected, and can adjust the selection deliberately – adding Certificates: Root for a compliance record, for instance.

Summary

  • Active Directory – captures the directory itself instead of the systems in it. A job of its own, complementing these two.
The job appears in Scan › Active; how you watch and adjust it is in Managing Jobs. You complete the captured systems afterwards with ITAM data.