How to configure a Windows Account Domain with a Local Administrator Account

  • 7017863
  • 20-Jul-2016
  • 20-Jul-2016

Environment

NetIQ Privileged Account Manager
NetIQ Privileged User Manager
Microsoft Windows Server

Situation

How to configure a Windows Account Domain with a Local Administrator Account
How to setup Direct-RDP, RDP-Relay, Credential Provider to work with a local admin account on Windows
Windows Local Account (non-domain/ldap account)

Resolution

Create a Local Account Domain for Windows Systems in the Enterprise Credential Vault with the following configuration:
Name: windows-agent-name\computer-name
Note: windows-agent-name is according to the Agent Name reported in the Hosts Console of the Administration Console. Computer-name is the Windows system name.
Type: LDAP
Profile: Windows Active Directory
LDAP URL: leave as default (blank)
Base DN: leave as default (blank)
Scope: leave as default (blank)
Account: <local user name>
User DN: <local user name>
Password: <password>

The above Account Domain can be used when creating a rule in Command Control for privileged access. Please refer to documentation for specific details regarding this configuration.