Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Div

Home / Installation and Configuration GuideConnecting to Directory SystemsLocal Windows Servers / Current: Configuring Windows Management Instrumentation

Configuring Windows Management Instrumentation

Microsoft's Windows Management Instrumentation (WMI) are conditions that consolidate the management of devices in a Microsoft Windows Network. Implementing WMI enables you to manage local and remote Microsoft Windows computers from a central server. EmpowerID uses WMI to manage windows services, application pools and file shares. This document provides instructions on how to configure WMI for use with EmpowerID.

Perform these procedures on any Microsoft Windows Servers that you wish to use to manage local users and groups.To assign Distributed Component Object Model (DCOM) permission

  1. Open Dcomcnfg.exe.
  2. From the Console Root tree, navigate to Component Service > Computers > My Computer.
  3. Right-click My Computer and select Properties from the context menu.



  4. From the My Computer Properties window that opens, click the COM Security tab.
  5. In the Access Permissions pane, click Edit Limits.
  6. From the Access Permission window that appears, ensure the Everyone user group has Local Access and Remote Access permissions.



  7. Close the Access Permission window.
  8. Back in the My Computer Properties window, click Edit Limit in the Launch and Activation Permissions pane.
  9. From the Launch and Activation Permission window that appears, ensure the Everyone user group has both the Local Launch and Local Activation permissions.



  10. Close the Launch and Activation Permission window and then close the My Computer Properties window.
  11. Back in Component Services (Dcomcnfg.exe), expand My Computer and click the DCOM Config node.
  12. Right-click Windows Management and Instrumentation and click Properties.




  13. From the Windows Management and Instrumentation Properties window that appears, click the Security tab.



  14. From the Launch and Activation Permissions pane, click the Edit button.
  15. From the Launch and Activation Permissions window that appears, ensure that the proxy account on the local machine has Local Launch, Remote Launch, Local Activation and Remote Activation permissions allowed.



  16. Click OK to close the Launch and Activation Permission window.
  17. Back in the Security tab of the Windows Management and Instrumentation Properties window, ensure that Use Default is selected for Access Permissions.
  18. From the Security tab of the Windows Management and Instrumentation Properties window, click the Edit button in the Configuration Permissions pane.
  19. In the Change Configuration Permission window that appears, ensure that the proxy account on the local machine has Full Control, Read and Special permissions allowed.

To assign permission for the user to the WMI namespace

  1. From the Start menu, open WmiMgmt.msc.



  2. Right-click WMI Control and select Properties.
  3. On the Security tab, select Root and click the Security button.



  4. Ensure that the Authenticated Users group has Execute Methods, Provider Right, and Enable Account allowed.



  5. Ensure that the Administrators group has all permissions.

To verify WMI impersonation rights

  1. From the Start menu, type Run.
  2. In the Run dialog that appears, type gpedit.msc and click OK.
  3. Under Local Computer Policy, expand Computer Configuration, then Windows Settings.
  4. Expand Security Settings, then Local Policies, and click User Rights Assignment.



  5. Double-click Impersonate a client after authentication and verify that the Service account is granted rights.

Additional Steps for Users on Microsoft Windows XP Only


Info

Users who are operating the Windows XP OS must complete additional steps. The following link points to a support topic by Microsoft on how to set security in Windows XP Professional that is installed in a Workgroup.

https://support.microsoft.com/en-us/help/290403/how-to-set-security-in-windows-xp-professional-that-is-installed-in-a-workgroup



Info
iconfalse
titleRelated Content






Div
stylefloat: left; position: fixed; top: 105px; padding: 5px;
idtoc
classtopicTOC


Div
stylemargin-left: 40px; margin-bottom: 40px;

Live Search
spaceKeyE2D
placeholderSearch the documentation
typepage


Div
stylefont-size: 1rem; margin-bottom: -45px; margin-left: 40px;text-transform: uppercase;

On this page



Table of Contents
maxLevel2
stylenone