# Failure to scan inventory manually ## Problem You try to complete inventory scanning manually. However, this fails and you see either one of the following errors on the screen: - Access Denied - Scanning Timed Out **Note:** While the resolution provided in this article will help you solve problems that you are facing while trying to complete inventory scanning manually, it could fail again due to various reasons. Therefore, it is recommended that you use the Scheduled [Inventory Scanning](https://www.manageengine.com/products/desktop-central/help/inventory/inventory-management-how-to.html#inventory-management-how-to1) feature, to complete this task. ## Cause Manual inventory scanning will fail due to either of the following reasons: **Access is denied** This could be due to the following reasons: - Administrator credentials for a domain do not match or have been changed - DCOM settings are disabled - Force Guest feature is enable **Scanning timed out** This could be due to the following reasons: - Data is blocked by the firewall on the computer on which the Endpoint Central server is installed - Scanning fails on computers running in remote offices - Multiple IP addresses have been enabled in the computer in which the Endpoint Central server is installed - UAC and Remote UAC are enabled in computers in a workgroup setup running on Microsoft Windows Vista or later versions ## Resolution You are required to follow the resolution related to the error message you saw on the screen while trying to complete inventory scanning manually: **Access Denied** - Check if the Administrator credentials for a domain that were specified while defining the Scope of Management (SoM) are valid and have not been changed. - Enable DCOM settings in all the computers in your network. To enable DCOM settings, follow the steps given below: 1. Click **start** > **Run** 2. Enter **dcomcnfg** 3. Click **OK** The dialog box that appears depends on the Windows operating system that is installed in your computer. If you are using Windows NT/2000, you will see the Distributed COM Configuration Properties dialog box on the screen. If you are using Windows XP, you will see the Component Services dialog box on the screen. To access the Properties tab, follow the steps given below: a. Expand **Component Services** b. Expand **Computers** c. Right-click on **My Computer** d. Click **Properties** 4. Click the **Default Properties** tab 5. Select Enable Distributed COM on this computer 6. Select an appropriate authentication level 7. Select an appropriate impersonation level You have enabled DCOM settings in the computers in your network. - Turn off the **Force Guest** feature if client computers are part of a workgroup (not part of a Windows Domain). Make the following change in all the client computers: 1. Click **start** > **Run** 2. Enter explorer 3. Click **OK** 4. Select **Tools** > **Folder Options** 5. Click the **View** tab 6. Deselect the option **Use simple file sharing** 7. Click **OK** **Scanning Timed Out** - Unblock firewall ports: Ensure that the following ports are added to the exception list of the firewall in the computer in which the Endpoint Central server is installed ### Disabling UAC in the client computers You are required to disable the UAC feature in all client computers. To disable the UAC feature, follow the steps given below: 1. Click **start > Settings > Control Panel > User Accounts** 2. Disable the UAC settings ### For Windows 7 and Windows 2008 R2 1. Click **User Account Control Settings** 2. Drag and choose the control level to **Never Notify** 3. Click **OK** ### For Windows Vista and Windows 2008 1. Click **Turn User Account Settings On or Off** 2. Uncheck the **Use User Account Control (UAC)** to protect your computer checkbox 3. Click **OK** 3. Close the Control Panel window. This will disable the UAC in the client computer. You need to perform the same steps in all the client computers that has Windows Vista or higher manually. ### Disabling Remote User Account Control in the client computers You are required to disable the Remote UAC feature by changing the registry entry that controls the Remote UAC feature. To disable the Remote UAC feature, follow the steps below: 1. Click **start > Run** 2. Enter regedit 3. Click **OK** 4. Navigate to **HKEY_LOCAL_MACHINE** \ **SOFTWARE** \ **Microsoft** \ **Windows** \ **CurrentVersion** \ **Policies** \ **system** 5. Right-click on the white space and click **New > DWORD Value** 6. Enter the name **LocalAccountTokenFilterPolicy** **Note:** If this key name is available then right-click on the name > Modify and follow the steps given below. 7. Click **Modify** 8. Change the value data to 1 9. Click **OK** You have disabled the Remote UAC feature.