Create and map scanning credentials

Prev Next

Lansweeper Classic uses scanning credentials to remotely access and scan assets on your network. A scanning credential is a username and password combination, or a certificate or key. You can add an unlimited number of scanning credentials, and you manage them in Scanning > Scanning Credentials in the web console.

These assets need a scanning credential to be scanned remotely:

  • Windows, Linux, Unix, and Mac computers
  • VMware, vCenter, and Citrix XenServer servers
  • Network devices with SNMP enabled, such as printers and switches
  • AWS and Azure cloud assets, and Office 365 accounts
  • Devices managed through Intune, VMware Workspace ONE (AirWatch), Google Admin (Chrome OS), or SCCM

Lansweeper also uses Windows credentials to deploy packages to computers.

Agent-scanned computers don't need credentials

You can also scan computers locally with a scanning agent: LsAgent for Windows, Linux, and Mac, or the older LsPush agent for Windows. If you scan your computers only with an agent and don't use deployment, you don't need computer scanning credentials.

How scanning credentials work

To use a scanning credential, you create it and then map it. Mapping tells Lansweeper when to use the credential. For example, if you map a Windows credential to a domain, Lansweeper tries that credential for every Windows computer in that domain.

Global credentials don't need to be mapped. Lansweeper tries a global credential for every asset of its type, after all other credentials of that type have failed.

When Lansweeper scans an asset, it tries credentials in this order:

  1. The credential that last scanned the asset successfully.
  2. The credentials mapped to the asset, in the order they appear in the web console.
  3. The global credential for the asset type.

Create a scanning credential

  1. In the web console, go to Scanning > Scanning Credentials.
  2. In the Credentials tab, select Add new Credential.
  3. Select a credential type.
  4. Enter a Name for the credential, and fill in the fields for the credential type. See Credential types.

Some credential types also create a scanning target automatically. These are listed in the Credential types table.

Credential types

Credential type Used to scan Creates a scanning target
AirWatch Mobile devices enrolled in VMware AirWatch Yes
AWS AWS VPCs and instances No
Azure Azure resource groups and virtual machines No
Chrome OS Chrome OS devices, such as Chromebooks Yes
Citrix Citrix XenServers No
Intune Mobile devices enrolled in Microsoft Intune Yes
Microsoft Cloud Service Office 365 and Intune, through a Microsoft Graph application Optional
Office 365 Office 365 accounts Yes
SCCM Assets in your SCCM server's database Yes
SNMPv1 and SNMPv2 Network devices with SNMPv1 or SNMPv2 enabled No
SNMPv3 Network devices with SNMPv3 enabled No
SSH Linux, Unix, and Mac computers No
SSH certificate Linux and Unix computers No
vCenter vCenter servers No
VMware VMware ESXi servers No
Windows Windows computers and users No

Every credential type has a Name field, where you enter a custom name for the credential. The sections that follow describe the other fields for each type.

AirWatch credentials

Requirements: Read-only access to the REST API in VMware Workspace ONE. See VMware Workspace ONE UEM (powered by AirWatch) scanning requirements.

Field Description
Username Your username in VMware Workspace ONE.
Password The password of your user account.
Server URL Your VMware Workspace ONE server URL.
API key An API key with read access to the REST API in VMware Workspace ONE.

AWS credentials

Requirements: List-only programmatic access to your EC2-VPC environments. See AWS scanning requirements.

Field Description
Access key The access key ID of a user with list access to EC2.
Secret key The secret access key of a user with list access to EC2.

Azure credentials

Requirements: Read-only access to your Azure subscription. You must register an application of the type Web App / API in Microsoft Entra ID (Azure Active Directory), generate a key for it, and assign it the Reader role for your subscription. See Azure scanning requirements.

Field Description
Directory ID Your Microsoft Entra ID (Azure Active Directory) tenant ID.
Application ID The ID of the application with read access to your subscription.
Application password The password or key of the application with read access to your subscription.

Chrome OS credentials

Requirements: Read-only access to the Google Admin SDK API. See Chrome OS scanning requirements.

Field Description
Username The email address of your Google account.
JSON key A JSON key with read access to the Google Admin SDK API.

Citrix credentials

Requirements: Access to XenAPI and permission to run these command groups on your XenServers: delegating, drivers, locate, networking, processes, services, software, and storage. Full root access isn't required. See Citrix scanning requirements.

Field Description
Login Your Citrix login.
Password The password of your Citrix login.

Intune credentials

Requirements: Access to your Intune environment. You must register an application of the type Native in Microsoft Entra ID (Azure Active Directory) and grant it the DeviceManagementManagedDevices.Read.All permission under Microsoft Graph. Your user account must also have access to Intune.

Field Description
Username A user who can view devices in your Intune environment.
Password The user's password.
Application ID The ID of the application with the DeviceManagementManagedDevices.Read.All permission.

Microsoft Cloud Service credentials

Requirements: A Microsoft Cloud Services application with the permissions for the data you want to scan:

  • Office 365: administrative permissions to inventory all contacts, mailboxes, and ActiveSync devices. A global administrator always has sufficient rights.
  • Intune: the DeviceManagementManagedDevices.Read.All permission under Microsoft Graph, and a user account with access to Intune. See Scan mobile devices through Microsoft Intune.
Field Description
Application ID The application ID you get when you create the Microsoft Graph application in Azure.
Directory ID The directory ID you get when you create the Microsoft Graph application in Azure.
Authentication type A client secret or a certificate thumbprint.
Create target for Select Office 365 v2 or Intune v2 to automatically create the matching scanning target.

Office 365 credentials

Requirements: Administrative permissions to Office 365, to inventory all contacts, mailboxes, and ActiveSync devices. A global administrator always has sufficient rights.

Field Description
Login The email address of a user with administrative permissions to your Office 365 environment.
Password The user's password.

SCCM credentials

Requirements: Local administrative permissions on the SCCM server and, at a minimum, the Read-Only Analyst security role in SCCM's Administrative Users.

Field Description
Username One of these formats: NetBIOS domain name\username or username@yourdomain.local for domain credentials, .\username for local credentials, or username@outlook.com for Microsoft accounts.
Password The password of your user account.
SCCM server The name, IPv4 address, or IPv6 address of an SMS Provider server in your SCCM environment.

SNMPv1 and SNMPv2 credentials

Requirements: Read-only SNMP access to your devices.

Field Description
Community The SNMP community string your devices use. Community strings are case-sensitive. Many devices use public (read-only) and private (read/write) by default, but your devices may use custom strings.
Use SNMP(v1) / Use SNMP(v2) Optional. Clear one of these checkboxes to make Lansweeper try only SNMPv1 or only SNMPv2. Only do this if your devices have trouble processing SNMPv1 or SNMPv2 requests.

SNMPv3 credentials

Requirements: Read-only SNMP access to your devices.

Field Description
Login Your SNMP login.
Password The password of your SNMP login.
Encryption key Required if the authentication type is MD5 or SHA1.
Authentication type None, MD5, or SHA1.
Privacy type None, DES, AES 128, AES 192, AES 256, or Triple DES.
Context Optional. The context name of the SNMPv3 credential.

SSH credentials

Requirements: Access to the uname command (Linux and Unix) or the system_profiler command (Mac). See Linux and Unix agentless scanning requirements and Apple Mac scanning requirements.

Field Description
Login Your SSH login.
Password The password of your SSH login.

SSH certificate credentials

Requirements: Access to the uname command. See Linux and Unix agentless scanning requirements.

Field Description
Login Your login.
Passphrase Your passphrase, if you have one.
Private SSH key Your SSH key. To see sample inputs, hover over the question mark icon next to the field.
Sudo Password Your sudo password.

vCenter credentials

Requirements: Read-only access to your vCenter servers. See vCenter scanning requirements.

Field Description
Login Your vCenter login.
Password The password of your vCenter login.

VMware credentials

Requirements: Read-only access to your ESXi servers.

Field Description
Login Your VMware login.
Password The password of your VMware login.

Windows credentials

Requirements: Administrative permissions on your computers. To scan domain computers and users, you also need read-only access to Active Directory. A domain admin works, but has more permissions than required. See Windows domain scanning requirements and Windows workgroup scanning requirements.

Field Description
Login One of these formats: NetBIOS domain name\username or username@yourdomain.local for domain credentials, .\username for local credentials, or username@outlook.com for Microsoft accounts.
Password The password of your user account.

Map a scanning credential

  1. In the web console, go to Scanning > Scanning Credentials and select Map Credential.
  2. Select what to map the credential to. See Mapping targets.
  3. Select one or more credentials.

Lansweeper tries mapped credentials in the order they appear. To change the order, drag a credential to a new position in the Credentials column.

Mapping targets

Map to What to select or enter
An AWS region Select a region from the dropdown.
An Azure subscription ID Select a subscription ID from the dropdown.
An IP address A single IP address.
An IP range Select a range from the dropdown.
An individual Windows computer NetBIOS domain name\NetBIOS computer name or workgroup name\NetBIOS computer name.
A domain or workgroup The NetBIOS name of the domain, or the name of the workgroup.

The AWS region, Azure subscription ID, and IP range dropdowns list your existing scanning targets. To add more, go to Scanning > Scanning Targets, select Add Scanning Target, and select AWS Region, Azure, or IP Range from the Scanning Type dropdown.