Remote access to endpoints
eyeSight needs remote access to the endpoint's registry service to properly access service pack installations, antivirus installations, and perform other important tasks.
Authentication at the domain level allows the service to make local registry checks while running a remote scan. This allows the service access to additional information in system registry settings that otherwise would not be available. With this information, the service can perform more in-depth vulnerability assessments.
You should create a special domain account that is used by the service for Windows authentication. This domain account needs assigned privileges most suitable for use with the service, not the default privileges. Specifically, the domain account needs privileges that allow read access to remote registries and minimal domain access otherwise.
Remote registry read permissions are controlled by this key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg
Various methods for setting this registry key on target endpoints are available. The available options depend on the Windows version running on the endpoints.
Define domain credentials
Define domain credentials by using one of the following approaches:
Troubleshoot domain credentials
Use these procedures to test and troubleshoot remote access to endpoints.
minute read