Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >
article

KB-30140: Windows Local Account Discovery Failing If Remote Registry Service Not Enabled

Privileged Access Service ,  

19 March,20 at 12:27 AM

Problem: It has been noticed that when trying to add local Windows accounts to the PAS admin portal using a discovery job, some of the accounts are not getting added. Troubleshooting has revealed that the required firewall ports between the Connectors and the systems are open and the discovery account has sufficient administrative permissions over the system that contains the accounts.


Cause: Remote Registry Service has not been enabled. 


Solution: Please ensure that this service is enabled and running on the Windows systems that contain the accounts. The steps to do this are below:



1) Go to Start > Control Panel > Administrative Tools >  and open the Services.msc console:


User-added image




2) Look for the Remote Registry service and ensure the startup type is set to "Automatic" or "Manual" and start the service.


User-added image


3) Try again to run the discovery job and the accounts on that system should now get picked up.


The additional requirements for Port Scanning Discovery jobs to be successful:
 
  • Open firewall.
  • Group Policies.
  • Discovery account must be a local admin.

Note:   One way to achieve this for systems that are joined to Active Directory is to use a discovery account that is a member of Domain Admins.

  • The Centrify Connector that is used for discovery through port scanning must be on version 18.6 or newer. By default, all connectors are used for discovery. Contact Centrify Support to specify the use of specific connectors for discovery.
  • Port scanning requires IPv4 addresses.



 

Still have questions? Click here to log a technical support case, or collaborate with your peers in Centrify's Online Community.