TechIDManager LAPS Installation on Domain Controller Instructions

This is a subsection of the fourth step from the Install Instructions for TechIDManager.


4.5 TechIDAgent.Windows Domain Controller Install – Shared Account

These instructions explain how to install TechIDAgent, the TechIDManager PAM service, onto a Windows domain controller.

This configuration takes control of one domain account and grants many technicians access to it.

We will use our TechIDAgent.Windows setup utility, which can install TechIDAgent locally or export a PowerShell script to install TechIDAgent on another computer. These written steps are intended to be followed from the domain controller itself.

Important: Only install TechIDAgent on one controller per domain. Installing multiple DC agents on the same domain will cause conflicts.

Should you need assistance installing TechIDAgent, whether with the setup utility or a manual installation, don’t hesitate to contact us for help, or book installation assistance.


What to do
Expected Result
Download TechIDAgent
4.5.1

Download the latest TechIDAgent.Windows from https://techidmanager.com/releases.

TechIDAgent.Windows.X.Y.zip downloaded to the domain controller.


4.5.2

Locate TechIDAgent.Windows.X.Y.zip and extract all files from the archive.

A directory containing the TechIDAgent.Windows.Setup.exe executable.

Configure the Installation
4.5.3

Run TechIDAgent.Windows.Setup.exe.

The TechIDAgent Setup utility opens.


4.5.4

Enter your ClientGuid into the utility.

Any visible error messages disappear.


4.5.5

Click the checkbox on the “Unique Users” tab to disable it, and click the checkbox on the “Shared User” tab to enable it instead.

Enter the local account username you’d like to use, into the Account Username option.

Confirm that the Install tab lists “Unique Technician Accounts” as disabled, and “Shared Account” as enabled.

The Shared User tab contains many options you may want to edit for this installation, such as:

  • Enabling Just-In-Time management of the account
  • Assigning a Friendly Name to the machine

Shared Account is enabled.

Any visible error messages disappear.

Any modified options are listed on the Install tab.

Run the Installation
4.5.6

Click the “RUN SCRIPT LOCALLY” button to install and configure TechIDAgent onto the local domain controller.

If you would like to install onto a remote domain controller, you may instead use the “SAVE SCRIPT” button to export the configuration as a PowerShell script. This script can be run without any prerequisites, as it will download and verify everything it needs.

TechIDAgent installs, configures itself with your ClientGuid and any other options you may have set, and starts itself up.

The domain controller appears in TechIDPortal, on the Agents page, with the chosen account name listed.


Any questions? Need help? Contact support@ruffiansoftware.com or book a White Glove Install.

If you wish to further configure your installation manually, the command-line reference can be found here.