App Control: How To Check If The Service Account Has Correct Active Directory Permissions
search cancel

App Control: How To Check If The Service Account Has Correct Active Directory Permissions

book

Article ID: 288379

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

To verify if the App Control service account has the correct permissions needed to query all Active Directory domains and subdomain in the forest where AD users reside

Environment

  • App Control Server: All Supported Versions
  • Microsoft Windows: All Supported Versions

Resolution

  1. Login to the server system hosting the App Control app with the AD service account used by App Control services
    • To find it > Open Services.msc > CB App Control Server > Log On As
  2. Download and run Microsoft AD Explorer
  3. Within AD Explorer enter:
    • Connect to: <Domain Name>
    • User: <Service Account>
  4. To confirm permissions:
    • If the connection and browsing the OUs where the AD users reside succeeds then the permissions are correct
    • If the connection fails, then this means that permissions are not correct and need to be addressed by an Active Directory admin