<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What priviledge need user-id agent user to work with WMI? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42810#M31419</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We need to know the priviledge minimum to the user-id user to work with the WMI probes and it can't look the security log of DC.&lt;/P&gt;&lt;P&gt;The problem is that on the security log appears one user of application siteadvisor that is installed on every PC of domain.&lt;/P&gt;&lt;P&gt;Then, when we execute the Get All on User-Id Agent, the 90% of IP addresses are assigned to the same username, but if we execute the " wmic /node:remotecomputer computersystem get username" with administrator domain user command we obtain the correct user logged on the PC.&lt;/P&gt;&lt;P&gt;If you know any other solution a this problem, I'm opened to hear.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 May 2011 08:08:54 GMT</pubDate>
    <dc:creator>jvmartin</dc:creator>
    <dc:date>2011-05-26T08:08:54Z</dc:date>
    <item>
      <title>What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42810#M31419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We need to know the priviledge minimum to the user-id user to work with the WMI probes and it can't look the security log of DC.&lt;/P&gt;&lt;P&gt;The problem is that on the security log appears one user of application siteadvisor that is installed on every PC of domain.&lt;/P&gt;&lt;P&gt;Then, when we execute the Get All on User-Id Agent, the 90% of IP addresses are assigned to the same username, but if we execute the " wmic /node:remotecomputer computersystem get username" with administrator domain user command we obtain the correct user logged on the PC.&lt;/P&gt;&lt;P&gt;If you know any other solution a this problem, I'm opened to hear.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 08:08:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42810#M31419</guid>
      <dc:creator>jvmartin</dc:creator>
      <dc:date>2011-05-26T08:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42811#M31420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest that you ignore the siteadvisor user. You can do this by creating a file in the Pan Agent installation folder named:&lt;/P&gt;&lt;P&gt;ignore_user_list.txt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this file you would put one user per line for each user that you wish the Pan Agent to ignore. For example:&lt;/P&gt;&lt;P&gt;siteadvisor&lt;/P&gt;&lt;P&gt;administrator&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: do not prepend the domain name!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you have created this file you must re-start the Pan Agent service. The service only reads this file when it starts up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 13:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42811#M31420</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-05-26T13:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42812#M31421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this very same problem. But if I ignore the administrator user, then the administrator can never have permits to go to Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What can I do in this case???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 09:02:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42812#M31421</guid>
      <dc:creator>ronieto</dc:creator>
      <dc:date>2011-06-09T09:02:39Z</dc:date>
    </item>
    <item>
      <title>Re: What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42813#M31422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can create a new AD account that has the relevant rights and ignore this system account.&amp;nbsp; Or you could enable captive portal for unknown users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 09:22:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42813#M31422</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-06-09T09:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42814#M31423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, how is it possible that we get the same user on so many IPs? Shouldn´t this be fixed already?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 10:46:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/42814#M31423</guid>
      <dc:creator>ronieto</dc:creator>
      <dc:date>2011-06-09T10:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: What priviledge need user-id agent user to work with WMI?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/176858#M55242</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You should a&lt;/SPAN&gt;&lt;SPAN&gt;dd the USER-ID account to the "Remote Desktop Users"&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;From Microsoft Documentation&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Connecting to WMI remotely requires that you first configure the Windows Firewall on the server to allow this. Incorrect Windows Firewall settings are usually identified by receiving the&amp;nbsp;"RPC Server Unavailable"&amp;nbsp;error message when trying to remotely connect to the VisualSVN Server using the management console.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Windows Firewall configuration should be done locally on the server by the user with administrator rights. While Windows Firewall can be configured via the Control Panel, you may find it easier to use the the&amp;nbsp;netsh&amp;nbsp;utility at the command prompt. Appropriate command lines are as follows:&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;For Windows XP/Windows Server 2003:&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;netsh firewall set service RemoteAdmin enable&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;For Windows Vista/Windows Server 2008 (note that command line should be executed in the&amp;nbsp;&lt;EM&gt;elevated&lt;/EM&gt;&amp;nbsp;command prompt):&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;netsh advfirewall firewall set rule group="windows management instrumentation (wmi)" new enable=yes&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note that in a non-domain environment, granted permissions can be filtered-down by User Account Control (UAC) (set it to 1)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Sep 2017 14:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-priviledge-need-user-id-agent-user-to-work-with-wmi/m-p/176858#M55242</guid>
      <dc:creator>dbatrankov</dc:creator>
      <dc:date>2017-09-17T14:06:42Z</dc:date>
    </item>
  </channel>
</rss>

