Hello @sivakumarm , In the Splunk side you need for the Splunk Supporting Add-on for Active Directory the admin_all_objects capability to read storage passwords. The user has this capability by default. If you want to use the add on with the non-admin user, then you must have this capability added to its profile. in the Microsoft side you only need a domain user (enough to discover the Active Directory) You can find all the informations in the official documentation from Splunk for this add-on: Configure the Splunk Supporting Add-on for Active Directory - Splunk Documentation Regards Den
... View more