Hi,
i am not able to do WMI verification while configuring STAS SSO. i successfully linked AD with SOPHOS XG125W but i am not able to do WMI verification. please see below
can anyone help me on this??
This thread was automatically locked due to age.
Hi,
i am not able to do WMI verification while configuring STAS SSO. i successfully linked AD with SOPHOS XG125W but i am not able to do WMI verification. please see below
can anyone help me on this??
If you have local firewall enabled on the workstation(s) by default WMI traffic is blocked. You'll need to create exceptions for WMI comms either directly in Windows Firewall itself or via Group Policy.
CTO, Convergent Information Security Solutions, LLC
https://www.convergesecurity.com
Advice given as posted on this forum does not construe a support relationship or other relationship with Convergent Information Security Solutions, LLC or its subsidiaries. Use the advice given at your own risk.
Hi Asif,
try to re-write the credentials in "General" tab as follows
domain \ administrator
password
Restart the service
have a good day
Michele.
Hi Michele,
this step already done earlier with no luck :(
any other idea ?
Hi Asif,
clear the stas.log or save this file in different folder and restart the service.
The stas.log will be re-create, now check the file and see the wmi result.
The WMI check present in the advanced tab in STAS uses the credentials writed in the tab general, in production the STAS uses the credentials writed in windows service "Sophos Transparent Authentication Suite" for this service use the domain administrator credential and do not select the "local" credentials.
If the check present on STAS does not work does not mean that the wmi check fails.
Michele.
hi Michele,
your idea works !!!! :)
thank for the support but my job is half done. now i can see that WMI verification for my PC is successful.
but when i am putting ip for other PCs connected to same LAN i am getting msg see below
any suggestions ?
I think that the "recommendation" to use Administrator acout is completely false from secuirity point of view. I think it will be better to write "useful" recoomendation how to use NON ADMIN account for this.
I think that the "recommendation" to use Administrator acout is completely false from secuirity point of view. I think it will be better to write "useful" recoomendation how to use NON ADMIN account for this.
I agree about not using the admin account and am having trouble using an AD account I've created and added to logon as service policy and still get this access denied on the STAS service. All of the guides I've been finding don't reveal anything new. Sorry to resurrect an old thread but I am out of leads here and can't get STAS going.