Skip to main content

Active Directory Domain Target Requirements

Netwrix Enterprise Auditor can execute scans on Active Directory domains. You can configure the Netwrix Activity Monitor to monitor activity on Active Directory domains and make the event data available for Enterprise Auditor Active Directory Activity scans.

Auditing Permissions

The following permission is needed:

  • Member of the Domain Administrators group

Some collection jobs do allow for a least privilege model. See the Active Directory Auditing Configuration topic for additional information.

Auditing Port Requirements

Ports vary based on the data collector being used. See the Active Directory Auditing Configuration topic for additional information.

Activity Auditing Permissions

note

You can also monitor Active Directory domain activity events through Netwrix Threat Prevention. This requires integration between it and Netwrix Activity Monitor to enable access to the data for Enterprise Auditor Active Directory Activity scans. See the Getting Data from NTP for AD Activity Reporting topic for additional information.

Requirements to Deploy the AD Agent on the Domain Controller

The Netwrix Activity Monitor must have an AD Agent deployed on the domain controller you want to monitor. While actively monitoring, the AD Agent generates activity log files stored on the server. The credential used to deploy the AD Agent must have the following permissions on the server:

  • Membership in the Domain Administrators group
  • READ and WRITE access to the archive location for Archiving feature only
note

To monitor an Active Directory domain, install the AD Agent on all domain controllers within the domain you want to monitor.

For integration between the Activity Monitor and Enterprise Auditor, the credential used by Enterprise Auditor to read the activity log files must have also have this permission.

Activity Monitor Archive Location

If you archive the activity log files, configurable within the Netwrix Activity Monitor Console, then the credential Enterprise Auditor uses to read the activity log files must also have READ and WRITE permissions on the archive location.

Integration with Enterprise Auditor

See the Active Directory Activity Auditing Configuration topic for target environment requirements.

Activity Auditing Port Requirements

Firewall settings depend on the type of environment being targeted. The following firewall settings are required for communication between the Agent server and the Netwrix Activity Monitor Console:

Communication DirectionProtocolPortsDescription
Activity Monitor to Agent ServerTCP4498Agent Communication

You need to configure the Windows firewall rules on the Windows server, which require certain inbound rules if the scans run in applet mode. These scans operate over a default port range that you can't specify via an inbound rule. For more information, see the Microsoft Connecting to WMI on a Remote Computer article.

Additional Firewall Rules for Integration between Enterprise Auditor and Activity Monitor

Firewall settings are dependent upon the type of environment being targeted. The following firewall settings are required for communication between the agent server and the Enterprise Auditor Console:

Communication DirectionProtocolPortsDescription
Enterprise Auditor to Agent ServerTCP445SMB, used for Agent Deployment
Enterprise Auditor to Agent ServerTCPPredefinedWMI, used for Agent Deployment