3 Replies Latest reply: Dec 12, 2017 12:55 PM by tiabbott RSS

Passive ID with AD without installing the agent on every DC or using WMI


If you want to do PassiveID but due to various reasons, we cannot install the agent onto DCs or employ the WMI. We do have a member windows log server that the DC's send all their logs to.  Can we install the agent onto that member server to review the centralized DC's logs for PassiveID.  If not, I know that there is an option to use SPAN on Kerberos messages and syslog via MSAD DHCP.  What have you used or recommended when installing the agent onto DC's or using WMI is not an option for Passive ID?