Set to use privileges LocalSystem (not Domain) for working agents locally installed

Isn't that too much permissions...?

If I install the agent manually, I have to have administrator privileges on the device. By installing, I forwarded the control to the GFI OneGuard server to which the agent connects during the installation.

I use the appropriate permissions to log in to the GFI OneGuard Server Administration portal or I will not get into it. If I enter a command here, I would say that it is sufficiently verified.

If the GFI Agent is running on a device with the ' Local system ' permission, it can do anything on the device without any problems. The GFI OneGuard and Kaspersky services also runs with a ' Local system ' permission, they can also do everything.

I would like to make GFI OneGuard had the opportunity to operate without using Domain Credentials.

I think you might have solved the installation problems. Plus, you would have allowed to use GFI OneGuard also on devices that are not domain member in the Active Directory. And it may not be required for each such device to enter the GFI server OneGuard permissions.

Petr Salfický shared this idea


