PowerEdge: iDRAC Service Module logs WMI warnings in Windows event log due to ismserviceprovider
Summary: iDRAC Service Module may log WMI warning events in the Windows System event log during registration of "ismserviceprovider"
Symptoms
After installation or service start of iDRAC Service Module (iSM) 3.6 and older the following warning events may be logged in the Windows System event log:
ProviderName : Microsoft-Windows-WMI Id : 63 Message : A provider, ismserviceprovider, has been registered in the Windows Management Instrumentation namespace Root\CIMV2\DCIM to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
If Dell OpenManage Server Administrator (OMSA) is also installed, these events may be logged every five hours.
Cause
iSM installs a WMI provider library to provide the iDRAC Hard Reset and system PowerCycle features. The provider must have LocalSystem privileges to access the iDRAC using the IPMI driver. The warning occurs anytime the DSM iDRAC Service Module service is started, and ismserviceprovider is registered with WMI service. Windows provides this logged warning even though the provider has been fully tested for security by Dell EMC.
If OMSA is also installed, it causes more frequent log warnings. This is due to an OMSA feature that synchronizes the iDRAC clock to the operating system clock every five hours, which cause the iSM to reload its libraries.