Credential-less Discovery is an initial visibility technique, not full infrastructure discovery. It can identify responsive IPs and exposed ports from the MID Server's network position. Trusted OS, software, process and relationship data normally requires authenticated access.
01MID Server
02Approved targets
03Discovery results
| Phase | Evidence | Next action |
|---|---|---|
| Network scan | Responsive IPs | Review coverage |
| Port scan | Open ports | Select credentials |
| Authenticated | OS, software, process | Create or update CI |
01
What the scan can prove
| Observation | Can infer | Cannot safely claim |
|---|---|---|
| TCP 22 open | An SSH service may be reachable | Exact Linux version or installed software |
| TCP 443 open | A TLS-enabled service responds | The application and its ownership |
| ICMP response | Host responds to ICMP from this path | Complete device configuration |
| No response | Nothing visible from this scan path | The device does not exist |
02
Implementation steps
- 01Obtain approval for the MID Server source, target CIDR ranges, ports, schedule and expected traffic.
- 02Validate that the selected MID Server is Up and can reach the target network.
- 03Create a small Discovery Schedule for a controlled lab subnet before using a large range.
- 04Run the schedule and inspect Discovery Status, device results and ECC Queue activity.
- 05Compare detected IPs and ports with a known inventory sample.
- 06Add least-privilege Windows, SSH, SNMP or cloud credentials for the next discovery phase.
- 07Review classification, identification and relationship results before expanding coverage.
03
Troubleshooting path
| Symptom | Check first | Evidence |
|---|---|---|
| Nothing discovered | MID route and firewall | MID host can reach target range |
| Ports missing | Network ACL or host firewall | Approved probe traffic reaches target |
| IP found but not classified | Port evidence and classifiers | Discovery log and classifier match |
| Credential failure | Credential type and scope | Credential test and Discovery log |
| Duplicate CI | Identification attributes | IRE result and identifier entries |
04
Safe operating boundaries
- Do not scan unapproved address ranges.
- Avoid aggressive schedules during peak business hours.
- Separate MID Servers by network zone when routing and security require it.
- Treat open ports as evidence to investigate, not final CI classification.
- Monitor ECC Queue processing and Discovery errors after every rollout wave.
05
Definition of done
A successful pilot is not simply a list of responding addresses. The pilot should demonstrate approved network reachability, predictable scan duration, explainable results, known credential gaps and a path to accurate CIs through authenticated discovery.
| Measure | Pilot target |
|---|---|
| Known IP coverage | Compared with approved sample |
| Credential success | Failures classified by reason |
| CI quality | No uncontrolled duplicates |
| Schedule impact | Within agreed network window |
| Ownership | Errors have a named resolver group |
Continue practical learning.
Explore more articlesExplore more implementation-focused ServiceNow and architecture guides.