Windows AD (Legacy Version)

Release 1.0

About This Document

The guide outlines the process for applying a Windows Group Policy Object (GPO) to your organization's domain, for the purpose of allowing Epiphany to make remote calls to the local security accounts manager (SAM).

Allowing Epiphany to enumerate users and groups in the local SAM database and Active Directory within your organization's domain will provide you with a qualitative risk based on your permission boundaries and privilege use.

A WMI filter should be applied to the GPO to ensure the policy is only applied to the specific versions of Windows listed below. https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-wmi-filters-for-the-gpo

Version Compatibility

The document applies to the following software versions:​

  • Epiphany: Epiphany Collector version 1.00.003 and later.

  • Windows:

    • Windows 10, version 1607 and later

    • Windows 10, version 1511 with KB 4103198 installed

    • Windows 10, version 1507 with KB 4012606 installed

    • Windows 8.1 with KB 4102219 installed

    • Windows 7 with KB 4012218 installed

  • Windows Server:

    • Windows Server 2019

    • Windows Server 2016

    • Windows Server 2012 R2 with KB 4012219 installed

    • Windows Server 2012 with KB 4012220 installed

    • Windows Server 2008 R2 with KB 4012218 installed

Prerequisites

What is Needed for Integration

To integrate your newly configured dataset into Epiphany, you need to provide the information shown below into Epiphany. The information below will be entered in your Windows AD data source configuration.

  • Data Source Name: The name for the Windows AD data source configuration.

  • Data Source Owner: Your organizational stakeholder for this data source.

  • Data Source Notes: Add additional information about the data source.

  • Username: The Windows AD account username you created.

  • Password: The password for the user account listed above.

  • Domain: Fully qualified domain name (FQDN) of the Windows AD data source domain.

  • Domain Controller: FQDN of the Windows AD data source domain controller.

  • Global Catalog : FQDN of the Windows AD data source global catalog.

Legal Notice

Last updated