NetBlade
Windows Step 3 of 12 ~20 min Beginner

Manage credentials the right way: scope, order, least privilege and rotation

File Windows, SSH and SNMP credentials in NetBlade safely: how they are encrypted, per-site and per-device scope, try order, least privilege and rotation.

Credentials are what turn NetBlade from a list of addresses into an inventory. They are also the most sensitive thing you will give it. This article shows where NetBlade keeps them, how to scope them so each one is tried only where it belongs, how to keep their privileges low, how to change them without breaking your scheduled reads, and what you will see when one is wrong.

Before you start

  • At least one site scanned (Get started).
  • The accounts you plan to use: Windows administrator, Linux user, SNMP community or v3 user.
  • If you use Windows accounts, the PCs prepared as in Prepare your Windows PCs.

1. Know where credentials are stored

Everything NetBlade collects stays in a SQLite database inside the app, on that PC. Passwords, communities and mail server passwords are encrypted with Windows DPAPI for your Windows account on that PC before they reach the database. Three consequences:

  • A copy of the database is of no use to anyone else: without your Windows account on that PC, the secrets cannot be decrypted.
  • Once saved, a password is never shown again, not even to you. Keep the original in your password manager.
  • If another Windows user on the same PC runs NetBlade, or you move to another PC, the saved secrets cannot be read there. The read fails with «the saved password cannot be read on this account», and the fix is to file the credential again.

2. File a credential

  1. Open Credentials and press Add…. The File a credential window opens.
  2. Choose the Protocol: Windows (WMI), Linux / SSH or SNMP.
  3. Fill in the account:
    • Windows: Username as DOMAIN\user or .\Administrator, and the password.
    • SSH: user and password.
    • SNMP: the SNMP version, then the Community for v1 and v2c, or for v3 the User, Authentication (none, MD5, SHA) with its password and Encryption (none, DES, AES) with its password.
  4. Choose Where it applies (step 3 explains the options).
  5. Give it a label that says what it is for, for example “Office A - IT admin”.
  6. Press File.

3. Scope each credential to where it belongs

Every credential applies in one of four ways:

Where it appliesUse it for
AnywhereAn account that genuinely works everywhere you look, such as one domain IT account
One siteA customer’s or an office’s accounts, which must never be tried at another customer
One deviceThe exception: the server with its own local administrator, the NAS with its own community
These scan scopesOnly devices found inside ranges you saved with Keep this scope, for example the switches’ management range

The narrowest always wins, and where a credential does not apply it is not even tried. That second point matters: a password for customer A is never sent to a device at customer B.

For consultants, the rule of thumb is simple: one site per customer, credentials filed for that site. Keep Anywhere for nothing, or for accounts that are yours alone.

Tip: To file a credential for one device, you can also open its card, go to the Credentials tab and use Override for this device, then Save and read this machine. It is filed for that device only and beats the site’s and the app’s.

4. Understand the order credentials are tried in

For each device, NetBlade tries first the credentials filed for it alone, then every other credential that covers it, in the order of the list, and stops at the first one that gets in. It does not try every credential on every device, and it chooses the protocol from what the device has shown:

  1. Windows, where the device has Windows ports open.
  2. SNMP.
  3. SSH, where port 22 is open.

Change the order with Try earlier and Try later. Put first the credential that opens the most machines, so no attempts are wasted on the others, and so a domain account does not get locked out by repeated failures elsewhere in the list.

A device’s Credentials tab shows which credentials will be tried, and in what order. If a device has not shown which protocol it speaks, the tab says so rather than guessing: NetBlade will not spray passwords at it, because that is what an attack looks like. Scan its ports first, or identify it.

5. Keep privileges as low as the task allows

  • Windows: reading needs an administrator; BitLocker and TPM in particular are only readable by one. Use a dedicated account for NetBlade rather than your own, so you can see its logins and disable it without locking yourself out. In a domain, make it a local administrator of the workstations it must read, not a Domain Admin. In a workgroup, give each PC its own strong local administrator password rather than one shared by all.
  • Linux over SSH: an ordinary user is enough. Everything NetBlade reads is readable without sudo. See Linux machines over SSH.
  • SNMP: NetBlade only reads. Give it a read-only community or a read-only v3 user, never a write community. See SNMP.

Note: When no stored Windows credential gets in, NetBlade also tries the Windows account it runs under. In a domain, that works on every PC where you are a local administrator. If you sign in to the NetBlade PC as an administrator of other PCs, keep that in mind.

6. Test before you rely on a credential

  1. On the Credentials page, type an address in Machine to try on the credential’s row.
  2. Press Test.
  3. The LAST TEST column says «Works» or «Failed». A credential never tested says «Never tried».

The test makes the same connection a read does, against that one host, without writing anything to the catalog.

7. Rotate a credential without breaking anything

NetBlade never shows a saved password and has no field to change it on an existing credential. Rotation is done by replacing the credential:

  1. Change the password on the accounts themselves (in Active Directory, on the PCs, on the switch).
  2. In NetBlade, press Add… and file the new credential with the same protocol and scope. Label it with the date, for example “Office A - IT admin (2026-09)”.
  3. Test it against a couple of machines.
  4. Use Try earlier to move it above the old one.
  5. On one PC, press Deep scan and check the card’s read status says «Read … via …».
  6. Delete the old credential.

Tip: Rotate when a technician leaves, when a customer changes provider, and at least on the schedule your customers’ policies require. Putting the month in the label is the simplest way to see, later, how old each credential is.

8. Know what happens when a credential is wrong

  • On a device card, the read status turns to «Read failed»; click it for the reason. NetBlade keeps up to two different reasons when several credentials fail, because a wrong password on one and a refused logon on another are both worth reading.
  • Typical Windows messages: «WMI: logon failure (0x8007052E). Wrong username or password.» and «WMI: access denied (0x80070005)» for a local account blocked by remote UAC.
  • SSH: «SSH refused the connection or the credentials».
  • SNMP: «no answer to an SNMP … request: the agent is off, set to a different version, or expecting another community». With v3, a wrong algorithm choice looks exactly like a device that is switched off.
  • On the Dashboard, «The last seven days» counts machines that became unreadable, so a password changed without telling you shows up there.
  • Scheduled reads mark each device as tried whether it got in or not, so a bad password does not make the agent hammer the device.

Check that it worked

  • LAST TEST says «Works» for each credential you rely on.
  • Device cards say «Read … via …», and the Credentials tab shows which credential was used (“Read with … over …, filed …”).
  • On the Dashboard, the coverage line counts more devices read in depth and the number of credentials on file.

If something goes wrong

  • «no credential applies to this device». Nothing covers it: file one for the device, the site, or everywhere, or widen an existing one with Where it applies….
  • «the saved password cannot be read on this account». The credential was encrypted for another Windows user. File it again as the user who runs NetBlade.
  • A domain account got locked out. Too many failures in a row. Move the credential that opens most machines to the top with Try earlier, narrow the others’ scope, and unlock the account in Active Directory.
  • «The host key is not the one this device showed last time». SSH only: the server was reinstalled or something else answers at its address. See Linux machines over SSH.

Next

Read your network gear next: Switches, printers, NAS and routers over SNMP.

← All how-to guides Feature guide → The product: NetBlade Windows →