<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Alternative authentication method for environments where Primary Site Admin has been disabled to align with Hardening Guidelines published by Esri in ArcGIS Monitor Ideas</title>
    <link>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idi-p/1711731</link>
    <description>&lt;P&gt;Following a malicious attack on our ArcGIS Enterprise environment, we have disabled the primary site admin account that was compromised during the attack.&amp;nbsp; Since we disabled the account, Monitor is no longer reporting metrics on services tied to the server site.&amp;nbsp; I would like to have an alternative authentication method that allows us to keep the primary site admin account disabled to meet the recommendations in Esri's Hardening Guide.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Jul 2026 19:30:41 GMT</pubDate>
    <dc:creator>RachaelWebster13</dc:creator>
    <dc:date>2026-07-01T19:30:41Z</dc:date>
    <item>
      <title>Alternative authentication method for environments where Primary Site Admin has been disabled to align with Hardening Guidelines published by Esri</title>
      <link>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idi-p/1711731</link>
      <description>&lt;P&gt;Following a malicious attack on our ArcGIS Enterprise environment, we have disabled the primary site admin account that was compromised during the attack.&amp;nbsp; Since we disabled the account, Monitor is no longer reporting metrics on services tied to the server site.&amp;nbsp; I would like to have an alternative authentication method that allows us to keep the primary site admin account disabled to meet the recommendations in Esri's Hardening Guide.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 19:30:41 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idi-p/1711731</guid>
      <dc:creator>RachaelWebster13</dc:creator>
      <dc:date>2026-07-01T19:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Alternative authentication method for environments where Primary Site Admin has been disabled to align with Hardening Guidelines published by Esri - Status changed to: Under Consideration</title>
      <link>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idc-p/1712064#M643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/686621"&gt;@RachaelWebster13&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;I'm sorry to hear about the cyber attack that happened to your enterprise GIS.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Yes, we are aware of the security recommendation change(s) in the &lt;EM&gt;ArcGIS Enterprise Hardening Guide&lt;/EM&gt; and we're actively working with the ArcGIS Enterprise Dev team to look at alternate options.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2026 17:25:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idc-p/1712064#M643</guid>
      <dc:creator>DerekLaw</dc:creator>
      <dc:date>2026-07-02T17:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Alternative authentication method for environments where Primary Site Admin has been disabled to align with Hardening Guidelines published by Esri</title>
      <link>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idc-p/1714406#M652</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;I would like Esri to consider one or more of the following improvements in a future ArcGIS Monitor release:&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Allow ArcGIS Server registration using a Portal for ArcGIS administrator account&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;&lt;SPAN&gt;ArcGIS Monitor should support registering and monitoring a federated ArcGIS Server site by using a Portal for ArcGIS administrator account instead of requiring the ArcGIS Server PSA account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This would allow organizations to keep the PSA account disabled while still allowing ArcGIS Monitor to collect the required metrics from the federated server.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Add support for a custom Portal role for ArcGIS Monitor&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;&lt;SPAN&gt;It would be helpful to provide specific privileges in Portal for ArcGIS that can be assigned to a custom role for ArcGIS Monitor.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;This would allow organizations to create a dedicated Monitor service account with only the minimum required privileges, instead of requiring a full Portal administrator or the ArcGIS Server PSA account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Ideally, this custom role would allow ArcGIS Monitor to collect health, performance, service, machine, log, and availability metrics without granting unnecessary administrative permissions.&lt;/SPAN&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN&gt;Provide an ArcGIS Enterprise identity-based option for ArcGIS Data Store registration&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P class=""&gt;&lt;SPAN&gt;ArcGIS Monitor should also provide a supported way to register and monitor ArcGIS Data Store using an ArcGIS Enterprise identity, delegated credential, or Monitor-specific service account model.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This would reduce the need to manage separate native Data Store administrative credentials only for monitoring purposes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This request is especially relevant for organizations with strict security policies where built-in administrator accounts must be disabled, and monitoring tools must use dedicated service accounts with controlled privileges.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2026 14:43:00 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-monitor-ideas/alternative-authentication-method-for-environments/idc-p/1714406#M652</guid>
      <dc:creator>lvargas</dc:creator>
      <dc:date>2026-07-14T14:43:00Z</dc:date>
    </item>
  </channel>
</rss>

