Windows Permissions
The non-administrative accounts must have access to DNS and DHCP services to read
service data for synchronizing with BlueCat Overlay for Microsoft. You can configure
these roles based on the requirements of your organization and how you are using
BlueCat Overlay for Microsoft. Non-administrative accounts can be members of the
following groups:
- Remote Management User
- Member of DNS user group
- Member of DHCP user group
This list of users groups is not exhaustive. You can configure user permissions using Built-In user groups or custom groups that allows the users to perform the necessary tasks.
Configuring Negotiate Authentication
Microsoft Overlay uses Negotiate Authentication as the default method of authenticating users.
- As an Administrator of the Windows server, navigate to .
- Set the Disallow Negotiate Authentication value to Disable for WinRM Service.
- Click OK on all open dialogue boxes.
- Navigate to .
- Expand Local Users and Groups.
- Expand Groups.
- Double-click the Remote Management Users group.
- Click Add.
- Enter the name of the user to be added to the Remote Management Users group.
- Click OK on all open dialogue boxes.
Configuring Windows Management Interface (WMI) namespace access for non-administrative users
- As an Administrator of the Windows server, navigate to .
- Expand Services and Applications, right-click WMI Control and select Properties. A new Window opens.
- Click the Security tab.
- Select Root and click the Security button. A new window opens.
- Click the Advanced button. A new window opens.
- Click the Add button under the Permission tab. A new window opens.
- Click select a principal and search for the user account that caused the error.
- Within applies to, select this namespace and subnamespace.
- For the permission, check the Execute Methods, Enable Accounts, and Remote Enable fields.
- Click Accept on all open dialogue boxes.
- Restart WMI services by performing the following:
- As an Administrator of the Windows server, navigate to .
- Expand Services and Applications and click Services.
- Navigate to and right-click Windows Management Instrumentation.
- Click Restart.
For a list of additional errors that might be encountered while using BlueCat Overlay for Microsoft, refer to Troubleshooting.