Windows device status: Access denied
The Access denied error indicates that the user account dedicated for log collection does not have the necessary access and permissions to collect logs from the respective devices.
There are two approaches to fixing the error:
- Using a domain admin account
- Using a service account with the necessary privileges
- Using a domain admin account:
- Go to the Settings tab > Configuration > Manage Devices > Windows Devices. Click Update next to the listed device. Enable the Use domain credentials check box, then select Update.
- Go to the Settings > Admin Settings > Domains and Workgroups. Click Update next to the Domain Name. Enter the domain admin credentials, then select Update.
- Using a service account with the necessary privileges:
- Go to Settings > Configuration > Manage Devices > Windows Devices. Click Update next to the listed device. Enable the Use domain credentials check box, then select Update.
- Refer to this guide for step-by-step instructions on configuring a service account.
- You will need the following permissions and privileges to use a service account:
- User groups:
- Event Log Readers
- Distributed COM Users
- User rights to be granted:
- Act as part of the operating system
- Log on as a batch job
- Log on as a service
- Replace a process level token
- Manage Auditing and Security Log Properties
- User permissions to be granted:
- Enable Account
- Remote Enable
- Read Security
- Once you have the necessary privileges, go to Settings > Admin Settings > Domains and Workgroups. Click the update icon in the Actions column. Enter the service account credentials, then select Update.
New to ADSelfService Plus?
Related Articles
Windows device status: RPC server is unavailable
The RPC server is unavailable error will be displayed in the device status field if there isn’t any communication between the EventLog Analyzer server and the respective machine from which the logs should be collected. This lack of communication ...
Does the given credentials of a Windows device have permission for log collection?
Case 1: The account is a local administrator or a domain administrator. The credentials will, by default, have the required permissions. Case 2: The account is a non-admin domain user. Provide the non-admin domain user with the required permissions. ...
What to do if the IIS Site status shows "Failed"?
Troubleshooting: Open the server out log file and search for the exception following the line "New Import File Arrived". a. Exception: "File not found" Probable cause(s) and troubleshooting step(s): Log file was not created for the particular day. ...
Windows: File Integrity Monitoring (FIM) issues
Prerequisites: An agent needs to be deployed on the respective machine. Open the EventLog Analyzer GUI. Go to the Settings tab > Configuration > Manage File Integrity Monitoring. Configure the folders in the machine that should be monitored. Verify ...
Windows Agent runs fine but not collecting the logs
Remote login to the Agent-installed machine ⇾ open "Services.msc" ⇾ ensure that the "ManageEngine EventLog Analyzer agent" service is running. Remote login to the Agent-installed machine ⇾ open a web browser ⇾ ensure that the EventLog Analyzer Web UI ...