Last updated: 2026-01-08
``` Supported OS Windows 10 User Requirements for installation Local System Account permissions Files and Folders permission FreshServiceScan Permission issues ```
Supported OS
Prerequisite: .Net Framework 4.8 or above
User Requirements for Installation
Role required for installation: Administrator user (or) user from Domain Administrator group.
The probe can be installed in any location in the machine. However, it requires Administrator access privilege to scan the network devices seamlessly. The Administrator user should have the following permissions:
Local System Account permissions
The probe consists of a UI and a background service called FreshServiceScan.The Local System Account will run the service and needs the following permissions:
By default, these permissions are enabled for the Administrator account and Local System Account. If any access is denied during the installation of the probe, check for the following permissions:
As mentioned earlier, the Folder in which the Discovery Probe is to be installed requires read, write and execute privileges for the Local System Account and Administrator account. Here's how the permission screen would look like:

Steps to grant permission:
``` Note: If the above permissions are missing, the Probe cannot start the system service FreshServiceScan while freshly installing the Probe or during the auto-update. ```
FreshServiceScan Service settings and recommendations


FreshServiceScan Permission issues
In some environments, if the Local System Account doesn't have permission to access the remote machine that is going to be scanned.
- If a machine can be scanned from the probe window directly (individual DeviceScan) but fails to scan via IP Range/Domain scan and throws an Access Denied error. This is the issue that needs to be fixed.
- As a workaround, configure an Administrator account in the FreshServiceScan so that the account will have permission on the remote machine. That will solve the issue, but upon auto upgrade, the account will be automatically changed to a Local System Account.
- So our recommendation is to give the remote access permission for the Local System Account to fix this permanently.
Firewall / Network Access:
Windows agent will communicate with the freshservice to sync the discovered data and update the version.
So the URL that needs to be exempted in the firewall are:
Domain whitelisting
If a firewall policy or proxy is enabled in the environment, it is important to whitelist specific domains based on regions.
| Region | US | EUC | AU | IND |
| Domain Name to be whitelisted | discovery-us.freshservice.com | discovery-euc.freshservice.com | discovery-au.freshservice.com | discovery-ind.freshservice.com |