Purpose
This kb article, explains how to configure WinRM to unlock Domotz os monitoring feature on all your windows endpoints from the AD: in a few words, how to launch the enable_winrm_os_monitoring.ps1 script on all your windows endpoint using an Immediate Task.
Instructions
Prerequisites:
- Ensure you have an AD Global group available (e.g. “Remote_WMI_Access”) and an AD user member of that group. Both created for this specific purpose.
If you are not sure on how to create the group, please see here: https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-firewall/create-a-group-account-in-active-directory
- Download this script:
https://github.com/domotz/support_scripts/raw/main/os_monitoring/enable_winrm_os_monitoring.zip
Unzip it in a share the target computers can access, in our example we copied the script in the AD domain NETLOGON share (\domotzlab.com\Netlogon)
- Copy the script in a share the target computers can access, in our example we copied the script in the AD domain NETLOGON share (\\domotzlab.com\Netlogon)
- Open the Group Policy Management console (gpmc.msc)
- expand “Forest: <YOURDOMAIN>” (tree item)
- expand “Domains” (tree item)
- expand “<YOURDOMAIN> ” (tree item)
- select “Group Policy Objects” (tree item)
- right click on “Group Policy Objects” (tree item) and select “New” (menu item)
- Type a name for your GPO, in this example we use ‘DomotzGroupPermissions’
- click on “OK”
- select “DomotzGroupPermissions “
- right click on “DomotzGroupPermissions “
- click on “Edit” (menu item)

Managing Group Policy Objects in a Domain Environment.
1. Open the "Group Policy Objects" management console in the specified domain.
2. Locate and select the policy titled "DomotzGroupPermissions."
3. Right-click to access options such as Edit, GPO Status, Back Up, Restore from Backup, Import Settings, Save Report, Copy, Delete, Rename, and Refresh.
4. Choose the desired action based on your needs, such as editing settings or creating a backup.
- Expand “Preferences” (tree item)
- Expand “Control Panel Settings” (tree item)
- Select “Scheduled Tasks” (tree item)
- right click on “Scheduled Tasks” and select ‘New’
- click on “Immediate Task (At least Windows 7)” (menu item)

Creating an Immediate Task in Group Policy Management
1. In the Group Policy Management Console, navigate to "Computer Configuration" and expand "Preferences."
2. Under "Control Panel Settings," click on "Scheduled Tasks."
3. Right-click on "Scheduled Tasks" and hover over "New."
4. From the dropdown menu, select "Immediate Task (At least Windows 7)" to create an immediate task for systems running Windows 7 or later.

- Type a name for your immediate task
- click on “Change User or Group…” and select the ‘SYSTEM’ account
- check “Run whether user is logged on or not (radio button)”
- check “Run with highest privileges (check box)”

Creating a New Task in Windows Task Scheduler
1. Navigate to the "Actions" tab in the New Task properties window.
2. In the "Action" section, you can create a task. The dropdown is currently disabled.
3. Enter the task name in the "Name" field, here labeled as "DomotzScript."
4. Review the "Author" field to ensure it shows the correct administrator, here it is "DOMOTZLAB\administrator."
5. Optionally, add a description in the "Description" field.
6. Under "Security options," specify the user account for the task under "NT AUTHORITY\SYSTEM."
7. Select "Run whether user is logged on or not" to ensure the task runs at all times.
8. Check "Run with highest privileges" to give the task administrative rights.
9. Adjust the "Configure for" dropdown according to your Windows version, currently set to "Windows Vista or Windows Server 2008."
10. Use the bottom buttons to save or modify the task: "OK," "Cancel," "Apply," or "Help."
- click on “Actions (tab item)”
- click on “New…”
- Verify that ‘Start a Program’ is selected in the drop-down menu.
- click on “Program/script: ” and add the following
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - click on “Add arguments(optional)” and add the following:
-noprofile -executionpolicy bypass -f <YOUR_SHARE_PATH>\enable_winrm_os_monitoring.ps1 -Username <DOMAIN\USER> -GroupName <DOMAIN\GROUP> -LogFilePath c:\Windows\temp
- Note that <DOMAIN\USER> must exist and be a member of <DOMAIN\GROUP>
- Example:
-noprofile -executionpolicy bypass -f \\domotzlab.com\NETLOGON\enable_winrm_os_monitoring.ps1 -Username DOMOTZLAB\DomotzAgent -GroupName DOMOTZLAB\DomotzWinRM -LogFilePath c:\Windows\temp
- click on “OK” on the action

Setting Up a New Task in Windows Task Scheduler
1. In the "New Action" window, select "Start a program" from the "Action" dropdown menu.
2. In the "Settings" section, enter `s\System32\WindowsPowerShell\v1.0\powershell.exe` in the "Program/script" field.
3. In the "Add arguments (optional)" field, enter `zWinRM -LogFilePath c:\Windows\temp`.
4. Click the "OK" button to save the action and proceed.
- click on “OK” on the task

Configuring a Task to Start a Program in DomotzScript Properties
1. Navigate to the "Actions" tab within the DomotzScript Properties window.
2. Ensure the action type "Start a program" is selected in the "Action" column.
3. Verify the program path is specified as "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" in the "Details" column.
4. Click "OK" at the bottom of the window to confirm and save the changes.
- Close the GPO editor
- Link the newly created GPO to the OU containing the computers you want to grant access to the user you selected in #25, the permissions are actually granted to the group, that’s why the user must be a member. You can rant permissions to different users just by adding them to the group.