Active Directory Domain Target Requirements
Netwrix Enterprise Auditor can execute scans on Active Directory domains. You can configure the Netwrix Activity Monitor to monitor activity on Active Directory domains and make the event data available for Enterprise Auditor Active Directory Activity scans.
Auditing Permissions
The following permission is needed:
- Member of the Domain Administrators group
Some collection jobs do allow for a least privilege model. See the Active Directory Auditing Configuration topic for additional information.
Auditing Port Requirements
Ports vary based on the data collector being used. See the Active Directory Auditing Configuration topic for additional information.
Activity Auditing Permissions
You can also monitor Active Directory domain activity events through Netwrix Threat Prevention. This requires integration between it and Netwrix Activity Monitor to enable access to the data for Enterprise Auditor Active Directory Activity scans. See the Getting Data from NTP for AD Activity Reporting topic for additional information.
Requirements to Deploy the AD Agent on the Domain Controller
The Netwrix Activity Monitor must have an AD Agent deployed on the domain controller you want to monitor. While actively monitoring, the AD Agent generates activity log files stored on the server. The credential used to deploy the AD Agent must have the following permissions on the server:
- Membership in the Domain Administrators group
- READ and WRITE access to the archive location for Archiving feature only
To monitor an Active Directory domain, install the AD Agent on all domain controllers within the domain you want to monitor.
For integration between the Activity Monitor and Enterprise Auditor, the credential used by Enterprise Auditor to read the activity log files must have also have this permission.
Activity Monitor Archive Location
If you archive the activity log files, configurable within the Netwrix Activity Monitor Console, then the credential Enterprise Auditor uses to read the activity log files must also have READ and WRITE permissions on the archive location.
Integration with Enterprise Auditor
See the Active Directory Activity Auditing Configuration topic for target environment requirements.
Activity Auditing Port Requirements
Firewall settings depend on the type of environment being targeted. The following firewall settings are required for communication between the Agent server and the Netwrix Activity Monitor Console:
| Communication Direction | Protocol | Ports | Description |
|---|---|---|---|
| Activity Monitor to Agent Server | TCP | 4498 | Agent Communication |
You need to configure the Windows firewall rules on the Windows server, which require certain inbound rules if the scans run in applet mode. These scans operate over a default port range that you can't specify via an inbound rule. For more information, see the Microsoft Connecting to WMI on a Remote Computer article.
Additional Firewall Rules for Integration between Enterprise Auditor and Activity Monitor
Firewall settings are dependent upon the type of environment being targeted. The following firewall settings are required for communication between the agent server and the Enterprise Auditor Console:
| Communication Direction | Protocol | Ports | Description |
|---|---|---|---|
| Enterprise Auditor to Agent Server | TCP | 445 | SMB, used for Agent Deployment |
| Enterprise Auditor to Agent Server | TCP | Predefined | WMI, used for Agent Deployment |