Click here to shrink
Click here to expand Click here to expand

Prerequisites

Important: Complete all prerequisite checks before deploying the agent. Missing prerequisites are the most common cause of installation failures.

Requirements summary

# Requirement Details
1 ADAudit Plus Any version, installed and accessible via the web console
2 License No specific license required—agent is included in all editions
3 Target OS Windows Vista+ (client) or Windows Server 2008+ (server). See Supported operating systems
4 .NET Framework 4.5 or higher on the target machine. See .NET Framework
5 Disk space Minimum 2GB for installation + 2-10GB for EventData cache
6 Privileges Domain Admin for console-based install; Local System for agent runtime. See Privileges required
7 Network Outbound HTTPS on port 8555 from agent to server (or NAT gateway). See Network and firewall
8 Antivirus Exclusions required for agent directory, executables, and ports. See Antivirus exclusions
9 Time sync NTP or domain controller time synchronization recommended

Supported endpoint environments

The ADAudit Plus agent can be installed on:

Environment Supported
Physical machines Desktops and servers
Persistent VDI Full Clone VMs (VMware Horizon, Citrix Virtual Apps and Desktops)
Non-persistent VDI Linked Clone VMs
Cloud desktops Azure Virtual Desktop (AVD), other cloud-hosted Windows VMs

Supported operating systems

Client operating systems

  • Windows 11
  • Windows 10
  • Windows 8/8.1
  • Windows 7
  • Windows Vista

Server operating systems

  • Windows Server 2022
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012/2012 R2
  • Windows Server 2008/2008 R2

Note: Both 64-bit and 32-bit architectures are supported where applicable.

Disk space and EventData directory

Component Size Notes
Agent installation 2GB minimum Fixed installation path: C:\Program Files\ManageEngine\ADAudit Plus Agent\
EventData directory 2GB default (configurable up to 10GB) Local cache for audit events when the server is unreachable

How EventData works:

  • When the agent cannot forward data to the ADAudit Plus server (network disruption, server downtime), events are cached locally in the EventData directory.
  • When connectivity is restored, cached events are forwarded to the server.
  • Increasing the EventData size allows the agent to hold data longer during outages, preventing data loss if older security logs are overwritten on the endpoint.

Important: When the EventData directory reaches its size limit, the agent stops collecting new data but continues running and attempting to send cached data to the server. Once data is forwarded and space is freed, collection resumes automatically.

To configure EventData directory size:

  • Log in to the ADAudit Plus web console.
  • Navigate to AdminAgent SettingsEvent Data SettingsMaximum Size of EventData Directory.
  • Enter the desired size and click Save.

Note: If increasing beyond 2GB, ensure the total disk space accommodates both the agent installation and the EventData directory. Example: 2GB (agent) + 5GB (EventData) = 7GB total.

.NET Framework

The ADAudit Plus agent requires .NET Framework 4.5 or higher.

OS .NET 4.5 Status
Windows Server 2012+/Windows 8+ Included by default
Windows Server 2008/2008 R2/Windows 7 Manual installation required

Download: .NET Framework

To verify the installed .NET Framework version:

  • On the target machine, navigate to %windir%\Microsoft.NET\Framework.
  • Look for folders starting with v4.0 or higher.

Note: The agent will not function correctly if the required .NET Framework version is missing.

Privileges required

For agent installation (from ADAudit Plus console)

The Domain Data Collection Account (configured in Domain SettingsModify Credentials) must be a member of the Domain Admins group. This account is used for:

  • Agent installation and uninstallation (from the web console)
  • Agent upgrade (from the web console)
  • Start/Stop agent service (remote)
  • Push-based configuration sync

Note: If the agent is deployed via GPO, Intune, SCCM, or Endpoint Central, Domain Admin privileges are not required because the agent is installed locally and communicates with the server over HTTPS.

For agent runtime (on the endpoint)

The ADAudit Plus agent runs as a Windows service under the Local System account. No additional privileges are required for event collection, forwarding, or status communication.

ADAudit Plus Service Account

The account used to run the ADAudit Plus server service (visible under ServicesManageEngine ADAudit PlusLog On tab) does not need Domain Admin privileges and does not affect agent installation or communication.

Antivirus exclusions

To ensure uninterrupted agent operation, add the following exclusions to your antivirus/endpoint protection software:

Directories

Exclude Location
Agent installation directory C:\Program Files\ManageEngine\ADAudit Plus Agent\

Executables

Exclude Where Purpose
ADAuditPlusAgent.exe Agent machine Event collection and forwarding
AgentService.exe Agent machine Agent Windows service
recomsvc.exe Agent machine (target) Used during agent installation/uninstallation
remcom.exe ADAudit Plus server Used during remote agent installation
remoteExec.exe ADAudit Plus server Used during remote agent installation

Ports

Port Protocol Purpose
TCP 8555 HTTPS Primary agent-to-server communication
TCP 8081 HTTP Fallback (product web port)
TCP 8444 HTTPS Fallback (product web port)

Note: Failure to exclude these directories, executables, or ports may result in delayed event collection, blocked communication, or failed agent installation.

Network and firewall

Scenario 1: Direct Connection (No NAT)

Agent —— HTTPS (8555) ——→ ADAudit Plus Server

Rule Direction Port Protocol
Agent machine Outbound 8555 HTTPS
ADAudit Plus server Inbound 8555 HTTPS

Scenario 2: With NAT gateway

Agent —— HTTPS (NAT port) ——→ NAT Gateway —— 8555/8444 ——→ ADAudit Plus Server

Rule Direction Port Protocol
Agent machine Outbound to NAT FQDN NAT port (e.g., 10555) HTTPS
NAT gateway Inbound NAT port HTTPS
NAT gateway Outbound to ADAudit Plus server 8555, 8444 HTTPS
ADAudit Plus server Inbound 8555, 8444 HTTPS

Important (NAT): When NAT is configured, the agent must connect using the NAT FQDN and NAT port—not the internal ADAudit Plus server hostname or IP.

Server-to-agent ports (RPC—optional)

Required only if managing agents directly from the ADAudit Plus console:

Port Purpose Direction
TCP 135 RPC Endpoint Mapper Server → Agent
TCP 49152-65535 RPC Dynamic Ports Server → Agent

Note: No inbound rules are required on agent machines for HTTPS-only deployments.

Time synchronization

Ensure all endpoints and the ADAudit Plus server have accurate and synchronized time. Correct time is critical for:

  • Proper auditing and event timestamping
  • Correlating logs across systems
  • Agent-server authentication

Tip: Use NTP or domain controller time synchronization.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try OnboardPro

     

On this page

Copyright © 2020, ZOHO Corp. All Rights Reserved.

Get download link