Lansweeper Classic uses scanning credentials to remotely access and scan assets on your network. A scanning credential is a username and password combination, or a certificate or key. You can add an unlimited number of scanning credentials, and you manage them in Scanning > Scanning Credentials in the web console.
These assets need a scanning credential to be scanned remotely:
- Windows, Linux, Unix, and Mac computers
- VMware, vCenter, and Citrix XenServer servers
- Network devices with SNMP enabled, such as printers and switches
- AWS and Azure cloud assets, and Office 365 accounts
- Devices managed through Intune, VMware Workspace ONE (AirWatch), Google Admin (Chrome OS), or SCCM
Lansweeper also uses Windows credentials to deploy packages to computers.
How scanning credentials work
To use a scanning credential, you create it and then map it. Mapping tells Lansweeper when to use the credential. For example, if you map a Windows credential to a domain, Lansweeper tries that credential for every Windows computer in that domain.
Global credentials don't need to be mapped. Lansweeper tries a global credential for every asset of its type, after all other credentials of that type have failed.
When Lansweeper scans an asset, it tries credentials in this order:
- The credential that last scanned the asset successfully.
- The credentials mapped to the asset, in the order they appear in the web console.
- The global credential for the asset type.
Create a scanning credential
- In the web console, go to Scanning > Scanning Credentials.
- In the Credentials tab, select Add new Credential.
- Select a credential type.
- Enter a Name for the credential, and fill in the fields for the credential type. See Credential types.
Some credential types also create a scanning target automatically. These are listed in the Credential types table.
Credential types
| Credential type | Used to scan | Creates a scanning target |
|---|---|---|
| AirWatch | Mobile devices enrolled in VMware AirWatch | Yes |
| AWS | AWS VPCs and instances | No |
| Azure | Azure resource groups and virtual machines | No |
| Chrome OS | Chrome OS devices, such as Chromebooks | Yes |
| Citrix | Citrix XenServers | No |
| Intune | Mobile devices enrolled in Microsoft Intune | Yes |
| Microsoft Cloud Service | Office 365 and Intune, through a Microsoft Graph application | Optional |
| Office 365 | Office 365 accounts | Yes |
| SCCM | Assets in your SCCM server's database | Yes |
| SNMPv1 and SNMPv2 | Network devices with SNMPv1 or SNMPv2 enabled | No |
| SNMPv3 | Network devices with SNMPv3 enabled | No |
| SSH | Linux, Unix, and Mac computers | No |
| SSH certificate | Linux and Unix computers | No |
| vCenter | vCenter servers | No |
| VMware | VMware ESXi servers | No |
| Windows | Windows computers and users | No |
Every credential type has a Name field, where you enter a custom name for the credential. The sections that follow describe the other fields for each type.
AirWatch credentials
Requirements: Read-only access to the REST API in VMware Workspace ONE. See VMware Workspace ONE UEM (powered by AirWatch) scanning requirements.
| Field | Description |
|---|---|
| Username | Your username in VMware Workspace ONE. |
| Password | The password of your user account. |
| Server URL | Your VMware Workspace ONE server URL. |
| API key | An API key with read access to the REST API in VMware Workspace ONE. |
AWS credentials
Requirements: List-only programmatic access to your EC2-VPC environments. See AWS scanning requirements.
| Field | Description |
|---|---|
| Access key | The access key ID of a user with list access to EC2. |
| Secret key | The secret access key of a user with list access to EC2. |
Azure credentials
Requirements: Read-only access to your Azure subscription. You must register an application of the type Web App / API in Microsoft Entra ID (Azure Active Directory), generate a key for it, and assign it the Reader role for your subscription. See Azure scanning requirements.
| Field | Description |
|---|---|
| Directory ID | Your Microsoft Entra ID (Azure Active Directory) tenant ID. |
| Application ID | The ID of the application with read access to your subscription. |
| Application password | The password or key of the application with read access to your subscription. |
Chrome OS credentials
Requirements: Read-only access to the Google Admin SDK API. See Chrome OS scanning requirements.
| Field | Description |
|---|---|
| Username | The email address of your Google account. |
| JSON key | A JSON key with read access to the Google Admin SDK API. |
Citrix credentials
Requirements: Access to XenAPI and permission to run these command groups on your XenServers: delegating, drivers, locate, networking, processes, services, software, and storage. Full root access isn't required. See Citrix scanning requirements.
| Field | Description |
|---|---|
| Login | Your Citrix login. |
| Password | The password of your Citrix login. |
Intune credentials
Requirements: Access to your Intune environment. You must register an application of the type Native in Microsoft Entra ID (Azure Active Directory) and grant it the DeviceManagementManagedDevices.Read.All permission under Microsoft Graph. Your user account must also have access to Intune.
| Field | Description |
|---|---|
| Username | A user who can view devices in your Intune environment. |
| Password | The user's password. |
| Application ID | The ID of the application with the DeviceManagementManagedDevices.Read.All permission. |
Microsoft Cloud Service credentials
Requirements: A Microsoft Cloud Services application with the permissions for the data you want to scan:
- Office 365: administrative permissions to inventory all contacts, mailboxes, and ActiveSync devices. A global administrator always has sufficient rights.
- Intune: the
DeviceManagementManagedDevices.Read.Allpermission under Microsoft Graph, and a user account with access to Intune. See Scan mobile devices through Microsoft Intune.
| Field | Description |
|---|---|
| Application ID | The application ID you get when you create the Microsoft Graph application in Azure. |
| Directory ID | The directory ID you get when you create the Microsoft Graph application in Azure. |
| Authentication type | A client secret or a certificate thumbprint. |
| Create target for | Select Office 365 v2 or Intune v2 to automatically create the matching scanning target. |
Office 365 credentials
Requirements: Administrative permissions to Office 365, to inventory all contacts, mailboxes, and ActiveSync devices. A global administrator always has sufficient rights.
| Field | Description |
|---|---|
| Login | The email address of a user with administrative permissions to your Office 365 environment. |
| Password | The user's password. |
SCCM credentials
Requirements: Local administrative permissions on the SCCM server and, at a minimum, the Read-Only Analyst security role in SCCM's Administrative Users.
| Field | Description |
|---|---|
| Username | One of these formats: NetBIOS domain name\username or username@yourdomain.local for domain credentials, .\username for local credentials, or username@outlook.com for Microsoft accounts. |
| Password | The password of your user account. |
| SCCM server | The name, IPv4 address, or IPv6 address of an SMS Provider server in your SCCM environment. |
SNMPv1 and SNMPv2 credentials
Requirements: Read-only SNMP access to your devices.
| Field | Description |
|---|---|
| Community | The SNMP community string your devices use. Community strings are case-sensitive. Many devices use public (read-only) and private (read/write) by default, but your devices may use custom strings. |
| Use SNMP(v1) / Use SNMP(v2) | Optional. Clear one of these checkboxes to make Lansweeper try only SNMPv1 or only SNMPv2. Only do this if your devices have trouble processing SNMPv1 or SNMPv2 requests. |
SNMPv3 credentials
Requirements: Read-only SNMP access to your devices.
| Field | Description |
|---|---|
| Login | Your SNMP login. |
| Password | The password of your SNMP login. |
| Encryption key | Required if the authentication type is MD5 or SHA1. |
| Authentication type | None, MD5, or SHA1. |
| Privacy type | None, DES, AES 128, AES 192, AES 256, or Triple DES. |
| Context | Optional. The context name of the SNMPv3 credential. |
SSH credentials
Requirements: Access to the uname command (Linux and Unix) or the system_profiler command (Mac). See Linux and Unix agentless scanning requirements and Apple Mac scanning requirements.
| Field | Description |
|---|---|
| Login | Your SSH login. |
| Password | The password of your SSH login. |
SSH certificate credentials
Requirements: Access to the uname command. See Linux and Unix agentless scanning requirements.
| Field | Description |
|---|---|
| Login | Your login. |
| Passphrase | Your passphrase, if you have one. |
| Private SSH key | Your SSH key. To see sample inputs, hover over the question mark icon next to the field. |
| Sudo Password | Your sudo password. |
vCenter credentials
Requirements: Read-only access to your vCenter servers. See vCenter scanning requirements.
| Field | Description |
|---|---|
| Login | Your vCenter login. |
| Password | The password of your vCenter login. |
VMware credentials
Requirements: Read-only access to your ESXi servers.
| Field | Description |
|---|---|
| Login | Your VMware login. |
| Password | The password of your VMware login. |
Windows credentials
Requirements: Administrative permissions on your computers. To scan domain computers and users, you also need read-only access to Active Directory. A domain admin works, but has more permissions than required. See Windows domain scanning requirements and Windows workgroup scanning requirements.
| Field | Description |
|---|---|
| Login | One of these formats: NetBIOS domain name\username or username@yourdomain.local for domain credentials, .\username for local credentials, or username@outlook.com for Microsoft accounts. |
| Password | The password of your user account. |
Map a scanning credential
- In the web console, go to Scanning > Scanning Credentials and select Map Credential.
- Select what to map the credential to. See Mapping targets.
- Select one or more credentials.
Lansweeper tries mapped credentials in the order they appear. To change the order, drag a credential to a new position in the Credentials column.
Mapping targets
| Map to | What to select or enter |
|---|---|
| An AWS region | Select a region from the dropdown. |
| An Azure subscription ID | Select a subscription ID from the dropdown. |
| An IP address | A single IP address. |
| An IP range | Select a range from the dropdown. |
| An individual Windows computer | NetBIOS domain name\NetBIOS computer name or workgroup name\NetBIOS computer name. |
| A domain or workgroup | The NetBIOS name of the domain, or the name of the workgroup. |
The AWS region, Azure subscription ID, and IP range dropdowns list your existing scanning targets. To add more, go to Scanning > Scanning Targets, select Add Scanning Target, and select AWS Region, Azure, or IP Range from the Scanning Type dropdown.