Aller au contenu principal

AMS User login attempts when installing Acronis Agent

Thread needs solution

Hello, 

Our SOC is notifying us with multiple login using the local AMS User in the management server (windows) when we install agent to a new node, although we do use a domain user during the installation? I have tried to look into the product user guide, could not locate what the user AMS functionality.

thanks!

0 Users found this helpful
frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Contributions: 2
Commentaires: 1727

Hello Shaker.

Welcome to the forum!

Could you please provide us with more details about the error code? What exactly are you trying to install ? A regular agent or a storage node?

Please also check the following KB and user guides to troubleshoot the issue.

https://kb.acronis.com/content/45866

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

- https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

https://www.acronis.com/en-us/support/documentation/AcronisCyberProtect…

Thanks in advance!

What I was pushing is a Windows workstation agent for Windows 10 via the Acronis Cyber Protect 15 Management page, installation user that I have specify is a domain admin user and installation is done perfectly.

What is happening is that during the installation, the local user “AMS User” in the management server is being used somehow and our SOC logs shows the user is doing a brute force attempts to the domain controller, in which the AMS User is not in the domain.

frestogaslorastaswastavewroviwroclolacorashibushurutraciwrubrishabenichikucrijorejenufrilomuwrigaslowrikejawrachosleratiswurelaseriprouobrunoviswosuthitribrepakotritopislivadrauibretisetewrapenuwrapi
Contributions: 2
Commentaires: 1727

Shaker Alsharif wrote:

What I was pushing is a Windows workstation agent for Windows 10 via the Acronis Cyber Protect 15 Management page, installation user that I have specify is a domain admin user and installation is done perfectly.

What is happening is that during the installation, the local user “AMS User” in the management server is being used somehow and our SOC logs shows the user is doing a brute force attempts to the domain controller, in which the AMS User is not in the domain.

Hello Shaker.

The local user must have Admin permissions also since that's a pre-requisite. Please make sure you grant them.

If the issue persists, please raise a ticket with our support attaching screenshots showing the local AMS user has admin permissions https://kb.acronis.com/content/8153

Thanks in advance.