> For the complete documentation index, see [llms.txt](https://docs.forestall.io/fsprotect/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.forestall.io/fsprotect/dashboard/scan-health.md).

# Scan Health

Scan Health provides an overview of configuration, permission, and connectivity issues that may affect the completeness of an Active Directory scan.

It helps identify whether required scan data was successfully collected and highlights conditions that may cause security checks to return incomplete results.

The page is opened from the heartbeat icon inside the **Finished** badge of a scan on the [Scans](/fsprotect/scans/scans.md) list.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-1927f92972227a078a2bcfd240dd1a554dcbd083%2Fdashboard-scan-health-image-1.png?alt=media" alt=""><figcaption><p>Scan Health</p></figcaption></figure>

### DMSA Read Access

DMSA Read Access shows whether the scan credential can read **Delegated Managed Service Account (dMSA)** objects in domains running Windows Server 2025.

The section displays the number of applicable domains and whether dMSA access was confirmed, not confirmed, or could not be evaluated. Domain-level details also show the detected Windows Server 2025 Domain Controllers, retrieved dMSA objects, and the reason for the result.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-4d7ae6ff3182012b27c0321f61e66343731b06e8%2Fdashboard-scan-health-image-2.png?alt=media" alt=""><figcaption><p><strong>DMSA Read Access</strong></p></figcaption></figure>

### DNS Node Read Access

DNS Node Read Access shows whether the scan credential can read DNS Node objects from the required Active Directory DNS locations.

The section displays results separately for **DomainDnsZones**, **System MicrosoftDNS**, and **ForestDnsZones**, including the search location, number of observed nodes, detected direct read access, enumeration result, and failure reason when available.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-d7c0d2c8296759b4f1a175e8a8952a2d2e4ab5ef%2Fdashboard-scan-health-image-3.png?alt=media" alt=""><figcaption><p><strong>DNS Node Read Access</strong></p></figcaption></figure>

### WSUS Access

WSUS Access shows whether configured WSUS references match servers detected during the scan and whether those servers are reachable.

The section displays configured references, detected servers, reachability status, the GPO where the WSUS setting is defined, and a reason when access cannot be confirmed.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-f972d87b86c20a2bd1771aa48bc9829c0a7e39dc%2Fdashboard-scan-health-image-4.png?alt=media" alt=""><figcaption><p><strong>WSUS Access</strong></p></figcaption></figure>

### Certificate Services

Certificate Services shows whether Certificate Authority and Certificate Template objects were collected successfully and whether the required registry information can be read from Domain Controllers.

The section displays discovered Certificate Authorities and Templates, along with **DC Registry Access** results for the Kdc and Schannel settings used by certificate-related security checks.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-c4b434a13c73e8305091d7cb5a908b2601e7411c%2Fdashboard-scan-health-image-5.png?alt=media" alt=""><figcaption><p><strong>Certificate Services</strong></p></figcaption></figure>

### SMB Share Enumeration

SMB Share Enumeration shows whether SMB share collection was successfully completed for eligible computers.

The section displays the number of eligible computers, successful and unconfirmed enumeration results, total shares observed, and collection failure reasons when available. The computer metrics can be selected to open the corresponding filtered list on the **Computers** page.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-25ef8e539048d3380c13996f8f4da409c2e645e3%2Fdashboard-scan-health-image-6.png?alt=media" alt=""><figcaption><p><strong>SMB Share Enumeration</strong></p></figcaption></figure>

### Local Enumeration Module

#### Local Enumeration Status

Shows whether the **Local Enumeration** module was enabled for the selected scan. When enabled, Forestall ISPM can collect local user, local group, and local administrator information from eligible computers.

#### Network access: Restrict clients allowed to make remote calls to SAM

Shows whether eligible non-Domain Controller computers are covered by the required Remote SAM policy and whether SAM access succeeded during the scan.

The section includes GPO coverage, runtime availability, and failure reasons. Computer metrics can be selected to open the corresponding filtered list on the **Computers** page.

#### Scan Credential Local Administrator

Shows whether local administrator access was observed for the scan credential across eligible computers.

This helps indicate whether the credential has the expected local administrator coverage for local enumeration.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-5daa198ef9e115dfe7955d7ae13a9eef0549b8e7%2Fdashboard-scan-health-image-7.png?alt=media" alt=""><figcaption><p><strong>Local Enumeration Module</strong></p></figcaption></figure>

#### Example 1: DMSA Access Not Confirmed

This example shows a domain where dMSA access could not be confirmed for the scan credential.

No direct dMSA delegation was detected and no dMSA objects were retrieved. This may indicate insufficient read access or that the domain does not contain any dMSA objects. The **Reason** field explains the condition behind the result.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-ca91e3ce58c86d9e9fa1f8e32bfffd7a2230e6b2%2Fdashboard-scan-health-image-8.png?alt=media" alt=""><figcaption><p>DMSA Access Not Confirmed</p></figcaption></figure>

#### Example 2: DMSA Read Access Not Applicable

This example shows an environment where DMSA Read Access evaluation is not applicable because no supported Windows Server 2025 Domain Controller was detected.

The domain is marked as **Not Applicable**, and the **Reason** field explains why DMSA validation was not performed.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-267e28090f0723166e264e66185ad57a7821e27b%2Fdashboard-scan-health-image-9.png?alt=media" alt=""><figcaption><p>DMSA Read Access — Not Applicable</p></figcaption></figure>

#### Example 3: WSUS Access Not Reachable

This example shows a WSUS server that was detected and matched to a configured WSUS reference, but the endpoint could not be reached during the scan.

The **Reachability** result is shown as **Not Reachable**, and the **Reason** field explains the connection issue.

<figure><img src="https://3408039743-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FObpV44hoVkNmo5bFuVVL%2Fuploads%2Fgit-blob-028082755dcbb873b542424817a124196238b272%2Fdashboard-scan-health-image-10.png?alt=media" alt=""><figcaption><p>WSUS Access — Not Reachable</p></figcaption></figure>
