---
title: "Prerequisites for Microsoft Services Discovery"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1694597671/Prerequisites%20for%20Microsoft%20Services%20Discovery"
format: markdown
---
Before configuring the Universal DDI Agent for Microsoft, ensure that you have the following required permissions, access to management tools and open ports on your Microsoft Server(s).

> ℹ️ If you only need read access, the account just requires read-only permissions without DNS/DHCP admin access.

## Administrative Privileges

- Must be a Domain Administrator or have delegated permissions to manage Group Policy, DNS, and WMI configurations.
- Must have Local Administrator rights on each server (Domain Controller or Member Server) hosting DNS.
- Must have Administrator rights on the Infoblox Agent host (client machine) to configure CredSSP and modify local Group Policy.

> ℹ️ Administrative Privileges (domain account) are only needed for configuring discovery services initially. The accounts for network discovery sync, only need DNS/DHCP rights.

## Access to Management Tools

- **Active Directory Users and Computers (ADUC)**: for managing accounts and groups.
- **ADSIEdit.msc**: for editing AD-integrated DNS zone permissions (Domain Controllers only).
- **wmimgmt.msc**: for configuring WMI permissions.
- **gpedit.msc or Group Policy Management Console (GPMC)**: for editing local or domain Group Policies.
- **Regedit**: for updating local registry permissions for DNS Server configuration.
- **PowerShell**: Run as administrator; to execute administrative commands.

## Network and Connectivity Requirements

- For DNS and DHCP use cases, TCP 5985 (WinRM HTTP) and 5986 (WinRM HTTPS) must be open between the Infoblox Agent host and all DNS and DHCP servers.
- All systems must be in the same Active Directory Forest. Management of multiple forests from a single Infoblox Agent is not supported.
- Time synchronization between client and DNS servers must be within 5 minutes.

> ⚠️ You cannot use a duplicate provider account ID scoped for the same account. This restriction is applicable to both DNS and DHCP objects.

## Supported Microsoft Versions

All currently supported Microsoft Windows Server versions are supported. For more information, see *[Windows Server Release Information](https://learn.microsoft.com/en-us/windows/release-health/windows-server-release-info#:~:text=Windows%20Server%202025%20is%20the,Updates%20API%20in%20Microsoft%20Graph.)**.*

Depending on the requirements your workflow may change. Perform one or many of the following configuration as per your requirements:

> Macro (children)