> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Windows

> Capturing Windows systems – through Active Directory or through targets you enter yourself – and choosing which components are collected.

There are two scan modules for Windows systems. They capture the same thing – the
difference is **where the targets come from**:

| Module | Where the targets come from | What for |
| - | - | - |
| *Windows (AD)* | from Active Directory – one job captures the domain, restrictable in the *Scan Scope* step | domain systems |
| *Windows (IP)* | entered yourself – as IP, range, CIDR or hostname | systems outside the domain, DMZ, workgroups |

Both ways can run side by side: the domain over *Windows (AD)*, the exceptions
over *Windows (IP)*. The component selection is the same for both. In both cases
a connected [gateway](/docs/en/scan/gateway-install) is required, plus an account
allowed to sign in to the target systems.

## Path A – Windows (AD)

The wizard shows five steps:

*Basics* › *Authentication* › *Scan Scope* › *Schedule* › *Summary*

Basics, Schedule and Summary are the same for every module – see
[Creating a Scan Job](/docs/en/scan/create-inventory). Characteristic are the two
steps in the middle.

### Authentication

The step takes the *Domain* first and the Windows credentials below it: first it
is settled which domain is captured, then which credentials are used. If the
domain field is visible, it must be filled.

You choose the credentials in a searchable picker. In first position stands the
entry that lets the scan run under the gateway service's account. Above it two
rows create a new entry: *New credentials…* a reusable one,
*One-time credentials…* one that applies to this job only.

<Note>
  *Windows (AD)* and *Active Directory* are the two modules where credentials are
  **not** enforced: the step can be passed without an entry. Whether the scan then
  succeeds depends on which account the gateway service runs under in your network.
  For the first job an explicitly stored account is advisable.
</Note>

<Warning>
  Credentials entered once make the job **not restartable** later – to run it
  again they have to be entered afresh through *Edit*. For a recurring scan it is
  better to store them as a reusable entry in the *Vault*.
</Warning>

### Scan Scope

The step carries two sections: *System Selection* and *Windows Components*.

The initial state of *System Selection* is the full set: by default all Windows
systems from Active Directory are scanned, and the selection can optionally be
restricted. For a first job that is enough; the step can be passed without an
entry.

*Restrict selection…* opens the *Select Systems* dialog, which searches Active
Directory. You can narrow it down through the *Filter…* field, the
*Servers Only* toggle and the state filters *Active* and *Disabled*;
*Select All* takes the set found all at once.

<Note>
  The dialog needs three entries from the previous steps: gateway, domain and
  credentials. If one is missing, go back to *Basics* or *Authentication*.
</Note>

<Tip>
  *Servers Only* together with the state filter *Active* limits the selection to
  active servers; clients and disabled accounts stay out. You add the clients later
  with a second job.
</Tip>

## Path B – Windows (IP)

Here the wizard follows the standard path through the
*Targets* step: one row per target, with the columns
*IP/Hostname* and *Credentials*. Into the target column may go a single address,
a range, a network in CIDR notation (e.g. /24) or a hostname – a whole network
therefore fits into one row.

The *Credentials for all targets* picker above the table applies to all rows
without their own assignment; per row it can be deviated from. The details are in
[Creating a Scan Job](/docs/en/scan/create-inventory#entering-targets).

## Windows components

With both paths the most extensive option sits in the *Windows Components*
section behind the *Customize* button: 22 options, **20 of them preselected**.
Not preselected are *Certificates: Root* and *Browser Extensions*.

| Component | Preselected |
| - | - |
| *Antivirus & Threat Protection* | yes |
| *BitLocker* | yes |
| *Browser Extensions* | **no** |
| *Certificates: Personal* | yes |
| *Certificates: Root* | **no** |
| *Firewall & Network Protection* | yes |
| *Hardware* | yes |
| *Installed Apps* | yes |
| *Installed Software* | yes |
| *Local Users & Groups* | yes |
| *Optional Features* | yes |
| *Power Options* | yes |
| *Local Printers* | yes |
| *Scheduled Tasks* | yes |
| *Services* | yes |
| *Shares* | yes |
| *Signed Drivers* | yes |
| *SMB Connections* | yes |
| *TPM & UEFI Status* | yes |
| *Update History* | yes |
| *USB Devices* | yes |
| *User Profiles* | yes |

<Tip>
  Leave the preselection untouched for the first job. Afterwards you see in the
  job summary under *Components* how many were selected, and can adjust the
  selection deliberately – adding *Certificates: Root* for a compliance record,
  for instance.
</Tip>

## Summary

| Line | Values |
| - | - |
| *Scope* | only with *Windows (AD)*: *All Windows systems from Active Directory* or *Custom Selection* |
| *Components* | how many of the 22 components are selected |

## Related modules

* [**Active Directory**](/docs/en/scan/active-directory) – captures the directory
  itself instead of the systems in it. A job of its own, complementing these two.

## Related

The job appears in *Scan › Active*; how you watch and adjust it is in
[Managing Jobs](/docs/en/scan/manage-jobs). You complete the captured systems
afterwards with [ITAM data](/docs/en/itam/manage-data).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.