Network Management
WMI polling returns DCOM errors
This article provides a resolution for an issue that generates messages about the svc-orion SID account not being able to activate the DCOM server.
First published date
Last published date
Overview
When an Orion Platform product attempts to access WMI on a remote server (for example, to monitor nodes), error messages similar to the example below appear in the Windows System Event log. The svc-orion account is used for WMI polling.
The server-side authentication level policy does not allow the user RLN\svc-orion SID (S-1-5-21-545522530-1090024521-1238779560-29142) from address 10.250.2.41 to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.
This error is also seen when executing VMAN management action (which uses WMI Commands) migrate VM from with orion web console, the error is logged in Destination Hyper-V host VMMS Event logs. Important thing to note is VM is migrated if you perform the migration from VMM console.
Product section
Cause
Microsoft recently made changes to improve security in the Distributed Component Object Model (DCOM) protocol. These changes were made to improve security, but the initial patches containing the security improvements affected WMI polling.
For more information about the changes that Microsoft made, see KB5004442 (©2021 Microsoft, available at https://support.microsoft.com/, obtained on November 11, 2021).
Resolution
To resolve this issue, install the latest patches on the Microsoft servers that host your primary Orion polling engine and any additional polling engines.
If the issue is during VM migration and the Hyper-V hosts have the above patches installed then and you are running latest version of Solarwinds Orion, it is a bug we are tracking internally. Please report this to Solarwinds technical support.
This is situational. Some clients the issue resolved by updating Microsoft Windows to the latest patches but some are not. If this happen, they need to reach out with the vendor Microsoft.