Documentation forSolarWinds Observability SaaS

Configure Kerberos for WMI/WinRM authentication

To use Kerberos authentication for WMI/WinRM monitoring, configure Kerberos at the domain level (disable NTLM, set up SPNs, DNS, forest trusts, and WinRM listeners), then configure your Network Collectors to use it (set up Cortex and add WMI credentials in the correct format).

Configure Kerberos on the domain

Disable NTLM and register a Service Principal Name (SPN)

Kerberos authentication requires that NTLM fallback be disabled and that each polled device have a registered SPN, so devices can be authenticated with Kerberos instead of NTLM.

  • Disable NTLM at the domain level using Group Policy.

  • Register an SPN for each device you want to poll.

For instructions, see Network security: Restrict NTLM Group Policy settings and Setspn in Microsoft's documentation.

Configure the DNS server in the Domain Controller

Kerberos depends on correctly configured forward and reverse DNS lookups to resolve and verify device identities.

Configure forward and reverse lookup zones on your DNS server.

For instructions, see Create a new zone in Microsoft's Windows Server documentation.

Configure trust between Active Directory forests

If the devices you want to poll are in domains that belong to different Active Directory forests, you need to establish trust between those forests before Kerberos authentication will work.

Configure conditional forwarders on each domain controller, then create a two-way forest trust between the domains.

For instructions, see Understanding when to create a shortcut, forest, external, or realm trust in Microsoft's Windows Server documentation.

Configure WinRM listener for Kerberos (optional)

To use Kerberos for WinRM polling, enable Kerberos authentication in the WinRM configuration on both the polling engine and the target machine, then verify the configuration.

For instructions, see Authentication for Remote Connections in Microsoft's documentation.

Configure Network Collectors to use Kerberos

To use Kerberos, make sure the following requirements are met:

  • DNS: Both forward and reverse lookup zones are configured.
  • The SPN is registered.
  • Credentials are entered in the correct domain-qualified form.

Configure Cortex

Cortex's WMI authentication mode setting determines how strictly it enforces Kerberos for WMI polling. Set this to match your environment's requirements, then restart the Cortex service for the change to take effect.

For instructions, see Configure Kerberos for WMI/WinRM authentication in the SolarWinds Platform documentation.

Add WMI credentials in the correct format

Kerberos authentication requires a domain-level account. Always enter credentials in one of these forms:

  • <FullDomainName>\<Username>

  • <Username>@<FullDomainName>