Skip to main content

Agent Server Requirements

The Agent server can be physical or virtual. The supported operating systems are:

  • Windows Server 2025
  • Windows Server 2022
  • Windows Server 2019
  • Windows Server 2016

The supported Exchange Servers are:

  • Exchange Server SE
  • Exchange Server 2019
  • Exchange Server 2016
  • Exchange Server 2013
  • Exchange Server 2010

RAM, Cores, and Disk Space

These depend on the amount of activity you expect:

EnvironmentRecommendedMinimum
RAM8+ GB4+ GB
Cores4+ CPU2 CPU
Disk Space50 GB50 GB

The disk space requirement covers the following:

  • Agent Size – 150 MB
  • Agent Queues – If there is a network outage, the agent will cache up to 40 GB of event data
  • Diagnostic Logging – 1 GB

Additional Enterprise Password Enforcer Solution Requirements

You can deploy the Have I Been Pwnd (HIBP) database, an optional feature of the Enterprise Password Enforcer solution, on the server where the Agent resides to improve performance. It requires:

  • Additional 15 GB of disk space to deploy

You can also deploy the HIBP database on some Agent servers while other Agent servers work with the copy installed on the Enterprise Manager server. See the EPE Settings Window topic for additional information.

Additional Server Requirements

The following are additional requirements for the Agent server:

Permissions for Installation

You need the following permission to install the Agent:

  • Membership in the local Administrators group

    note

    Membership in the Domain Administrators group for a domain controller.

Agent Compatibility with Non-Netwrix Security Products

The following products conflict with the agent:

warning

Don't install these products on a server where an agent is deployed. Don't install an agent on a server where these products are installed.

  • Quest Change Auditor (aka Dell ChangeAuditor)
  • PowerBroker Auditor for Active Directory by BeyondTrust

The following products, which protect LSASS, may prevent the agent from injecting into LSASS, and thereby prevent monitoring Active Directory events:

  • Cisco AMP for Endpoints Connector

  • Avast Business Antivirus

    • Specifically the “Avast self-defense module”
note

You can configure these products and other similar products via a whitelist to allow the agent to operate.