Configure Orchestrator for MSCA Inventory
This covers how to grant the Universal Orchestrator service account access to your MSCA and configure it for Remote CA Inventory.
Grant Orchestrator Service Account Permissions
The domain user that the Universal Orchestrator was configured to run as during installation (option #2) needs to be granted access to your MSCA in order to be able to read the certificates from the CA database. For more information, refer to the Command documentation about Grant the Orchestrator Service Account Permissions on the CAs.
Configure Remote CA Inventory
Once the user has been granted permission to the MSCA, the Orchestrator needs to be configured to perform Remote CA Inventory. For more information, refer to the Command documentation about Configure the Universal Orchestrator for Remote CA Management.