{"id":158,"date":"2019-05-29T07:05:11","date_gmt":"2019-05-29T07:05:11","guid":{"rendered":"http:\/\/edcint.co.nz\/checkwmiplus\/?post_type=faq&#038;p=158"},"modified":"2019-05-30T00:56:51","modified_gmt":"2019-05-30T00:56:51","slug":"how-do-i-setup-the-windows-user-for-wmic-or-what-permissions-do-i-need","status":"publish","type":"faq","link":"https:\/\/edcint.co.nz\/checkwmiplus\/faq\/how-do-i-setup-the-windows-user-for-wmic-or-what-permissions-do-i-need\/","title":{"rendered":"How do I setup the Windows User for wmic (or what permissions do I need)?"},"content":{"rendered":"<div class=\"field field-name-body field-type-text-with-summary field-label-hidden view-mode-full\">\n<div class=\"field-items\">\n<div class=\"field-item even\">\n<h3>The Easy (Insecure) Way<\/h3>\n<p>Add a new user and add them to the administrators group. Perhaps disable login privileges. Possibly suitable for test environments etc.<\/p>\n<h3>A Better Way<\/h3>\n<p>Scroll about halfway down <a href=\"https:\/\/kb.op5.com\/display\/HOWTOs\/Agentless+Monitoring+of+Windows+using+WMI#AgentlessMonitoringofWindowsusingWMI-ConfigureremoteWMIaccessinWindows\">this page<\/a> to the section titled &#8220;Configure remote WMI access in Windows&#8221;.<\/p>\n<p>**Note that some people report that even after following the above instructions that not all checks work. We have not yet determined a resolution for this problem. Most of the time using an administrators account fixes this problem. If using the administrator account fixes your errors then you almost certainly have a permissions problem.<\/p>\n<p><a href=\"http:\/\/unlockpowershell.wordpress.com\/2009\/11\/20\/script-remote-dcom-wmi-access-for-a-domain-user\/\">This page<\/a> may also be helpful.<\/p>\n<p><cite>The primary relevant content from the op5 site is also available <a href=\"http:\/\/edcint.co.nz\/checkwmiplus\/configure-wmi-in-windows-from-op5\/\">here<\/a><\/cite><\/p>\n<h3>Other Permissions Snippets<\/h3>\n<p>There have been many suggestions scattered around the Internet on how to setup the permissions for wmic access. Some of them have been reproduced here. Its typically going to come down to try various combinations and see what works for you.<\/p>\n<h4>WMI Connection Testing<\/h4>\n<p>This <a href=\"\/checkwmiplus\/download\/wmi-connection-tester\/\">standalone executable<\/a> sometimes gives somewhat more useful error messages to help find the WMI connection\/permission issues:<\/p>\n<h4>Windows Management Infrastructure<\/h4>\n<ul>\n<li>(Start \u2192 Run &#8230;) wmimgmt.msc<\/li>\n<li>Right-click on WMI Control (Local) Properties \u2192<\/li>\n<li>Security<\/li>\n<li>\u2192 Root CIMV2<\/li>\n<li>Security<\/li>\n<li>Add users with the privileges:<\/li>\n<li>Enable Account<\/li>\n<li>Remote Enable<\/li>\n<\/ul>\n<h4>Enabling Remote DCOM<\/h4>\n<ul>\n<li>Add the user (s) in question to the Performance Monitor Users group<\/li>\n<li>Under Services and Applications, bring up the Properties dialog of WMI Control. In the Security tab, highlight the root \/ CIMV2, click Security; add Performance Monitor Users and enable the options: Enable Account and Remote Enable<\/li>\n<li>Run dcomcnfg. At Component Services&gt; Computers&gt; My Computer, in the COM Security tab of the Properties dialog click &#8220;Edit Limits&#8221; for Both Access Permissions and Launch and Activation Permissions. Add Performance Monitor Users and allow remote access, remote launch, and remote activation<\/li>\n<li>Select Windows Management Instrumentation under Component Services&gt; Computers&gt; My Computer&gt; DCOM Config and give Remote Launch and Remote Activation privileges to performance Users Group.<\/li>\n<\/ul>\n<h4>Allowing NTLM<\/h4>\n<p>Run gpedit.msc and configure the following setting:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-196 size-full\" src=\"http:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit.png\" alt=\"Gpedit Screenshot for NTLM configuration\" width=\"1071\" height=\"273\" srcset=\"https:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit.png 1071w, https:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit-300x76.png 300w, https:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit-768x196.png 768w, https:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit-1024x261.png 1024w, https:\/\/edcint.co.nz\/checkwmiplus\/wp-content\/uploads\/2019\/05\/wmic_ntlm_gpedit-769x196.png 769w\" sizes=\"auto, (max-width: 1071px) 100vw, 1071px\" \/><\/p>\n<h4>Forcing NTLMv2<\/h4>\n<p>Add the following command line argument to Check WMI Plus to force the use of NTLMv2:<br \/>\n&#8211;extrawmicarg &#8220;&#8211;option=client ntlmv2 auth=Yes&#8221;<\/p>\n<h4>Make Sure the Account is Active<\/h4>\n<p>Using an administrative command prompt<br \/>\nnet user USERNAME \/active:yes<\/p>\n<h4>Windows Firewall<\/h4>\n<p>Make sure the Windows firewall will allow wmi connections from the Check WMI Plus client.<br \/>\nIf you are not sure if you have a firewall issue, disable the firewall and test. If it works when you disable the firewall but not when the firewall is enabled, then you need to add the correct firewall rule.<\/p>\n<h4>Workgroup and Systems that cannot communicate with their Domain<\/h4>\n<p>There are some reports that you have to disable UAC if you&#8217;re checking against a system that&#8217;s either in a workgroup or cannot communicate to a domain (even if joined).<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"template":"","faq_groups":[3],"class_list":["post-158","faq","type-faq","status-publish","hentry","faq-group-support"],"_links":{"self":[{"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/faqs\/158","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/faqs"}],"about":[{"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/types\/faq"}],"author":[{"embeddable":true,"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/users\/1"}],"wp:attachment":[{"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/media?parent=158"}],"wp:term":[{"taxonomy":"faq-group","embeddable":true,"href":"https:\/\/edcint.co.nz\/checkwmiplus\/wp-json\/wp\/v2\/faq_groups?post=158"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}