Failure to scan inventory manually
Problem
You try to complete inventory scanning manually. However, this fails and you see either one of the following errors on the screen:
- Access Denied
- Scanning Timed Out
Cause
Manual inventory scanning will fail due to either of the following reasons:
Access is denied
This could be due to the following reasons:
- Administrator credentials for a domain do not match or have been changed
- DCOM settings are disabled
- Force Guest feature is enable
Scanning timed out
This could be due to the following reasons:
- Data is blocked by the firewall on the computer on which the Endpoint Central server is installed
- Scanning fails on computers running in remote offices
- Multiple IP addresses have been enabled in the computer in which the Endpoint Central server is installed
- UAC and Remote UAC are enabled in computers in a workgroup setup running on Microsoft Windows Vista or later versions
Resolution
You are required to follow the resolution related to the error message you saw on the screen while trying to complete inventory scanning manually:
- Check if the Administrator credentials for a domain that were specified while defining the Scope of Management (SoM) are valid and have not been changed.
- Enable DCOM settings in all the computers in your network. To enable DCOM settings, follow the steps given below:
- Click start>Run
- Enter dcomcnfg
- Click OK
The dialog box that appears depends on the Windows operating system that is installed in your computer. If you are using Windows NT/2000, you will see the Distributed COM Configuration Properties dialog box on the screen. If you are using Windows XP, you will see the Component Services dialog box on the screen. To access the Properties tab, follow the steps given below:
- Expand Component Services
- Expand Computers
- Right-click on My Computer
- Click Properties
- Click the Default Properties tab
- Select Enable Distributed COM on this computer
- Select an appropriate authentication level
- Select an appropriate impersonation level
You have enabled DCOM settings in the computers in your network.
- Turn off the Force Guestfeature if client computers are part of a workgroup (not part of a Windows Domain). Make the following change in all the client computers:
- Click start>Run
- Enter explorer
- Click OK
- Select Tools>Folder Options
- Click the View tab
- Deselect the option Use simple file sharing
- Click OK
- Unblock firewall ports: Ensure that the following ports are added to the exception list of the firewall in the computer in which the Endpoint Central server is installed
Disabling UAC in the client computers
You are required to disable the UAC feature in all client computers. To disable the UAC feature, follow the steps given below:
- Click start>Settings>Control Panel>User Accounts
- Disable the UAC settings
For Windows 7 and Windows 2008 R2
- Click User Account Control Settings
- Drag and choose the control level to Never Notify
- Click OK
For Windows Vista and Windows 2008
- Click Turn User Account Settings On or Off
- Uncheck the Use User Account Control (UAC) to protect your computer checkbox
- Click OK
- Close the Control Panel window.
This will disable the UAC in the client computer. You need to perform the same steps in all the client computers that has Windows Vista or higher manually.
Disabling Remote User Account Control in the client computers
You are required to disable the Remote UAC feature by changing the registry entry that controls the Remote UAC feature. To disable the Remote UAC feature, follow the steps below:
- Click start>Run
- Enter regedit
- Click OK
- Navigate to HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system
- Right-click on the white space and click New>DWORD Value
- Enter the name LocalAccountTokenFilterPolicyNoteIf this key name is available then right-click on the name>Modify and follow the steps given below.
- Click Modify
- Change the value data to 1
- Click OK
You have disabled the Remote UAC feature.