Discovering Windows Hosts with Powershell - Documentation for Bmc Discovery 23.1
Windows Host Discovery by Using Powershellpowershell Discovery Requires a Valid Powershell Credential for the Host to Be Discovered. Bmc Discovery Looks for...
Windows host discovery by using PowerShell
PowerShell discovery requires a valid PowerShell credential for the host to be discovered. BMC Discovery looks for open PowerShell ports on the target host. If open PowerShell ports are available, BMC Discovery attempts to connect to the PowerShell API over https and uses the PowerShell credential to log in.
This can all be accomplished from the appliance, without the need for a Windows proxy or a BMC Discovery Outpost. PowerShell discovery always tries to use a valid PowerShell credential directly from the appliance, before attempting discovery from BMC Discovery Outpost or proxy.
PowerShell can be used over HTTP, and the content returned is encrypted. Using HTTP with Basic authentication would make it possible for credentials to be compromised. We recommend you use NTLM (Negotiate) authentication.
Must Read
PowerShell discovery from Windows proxies and BMC Discovery Outposts
When you use a PowerShell credential for discovery and one of the following events occurs, discovery proceeds through a BMC Discovery Outpost or a BMC Discovery Windows AD proxy:
- The scope or IP access of the appliance does not permit the appliance to scan the IP address.
- Discovery using PowerShell fails.
For PowerShell discovery, the BMC Discovery Windows AD proxy does not issue discovery commands and return processed results. It acts as a proxy, simply forwarding the PowerShell commands to be run on the target host, and returning the raw results to the BMC Discovery appliance or BMC Discovery Outpost that initiated the scan.
When you use discovery in Record/Playback mode for PowerShell discovery, this is done in the Windows AD proxy.
Credential proxies are not used for PowerShell discovery. Credential proxies are given a credential from BMC Discovery or BMC Discovery Outpost and they would simply repeat the discovery attempt by using the credential that has already failed.
For Windows discovery, PowerShell is now the preferred method of discovering Windows hosts, if a PowerShell credential is available, it is used in preference to any other Windows credential. Where a PowerShell credential is not available, the BMC Discovery Outpost or proxy runs the PowerShell commands using the existing Windows AD credentials, and falls back to trying WMI and RemQuery if a PowerShell request fails. Many PowerShell commands access WMI objects, so it is important that WMI is available and can be used by PowerShell.
The order of precedence for Windows discovery methods is:
- Powershell > WMI > RemQuery > SNMP
The information returned from a Windows host by PowerShell is the same as existing Windows discovery methods, it is simply another access method.
PowerShell cmdlets
PowerShell commands are referred to as cmdlets. When additional software is installed on a Windows host, such as Exchange, often additional Exchange-related cmdlets are installed into PowerShell on that host, and are available to PowerShell discovery. However, additional cmdlets might require additional permissions.