Configure required and unauthorized services and ports in scan reports
The topic covers how to configure required and unauthorized services or ports in Qualys scan reports using scan templates and related QIDs.
If you want to configure specific services or ports as required or unauthorized, they must appear in Qualys scan reports when those services or ports are detected or missing.
For example, you may want to flag HTTP services as unauthorized and display them in the generated scan report.
Problem
You may observe the following:
- Unauthorized services or ports do not appear automatically in raw scan results.
- Expected QIDs are only visible in generated scan reports.
- HTTP or other services are detected on assets. But no unauthorized service findings are displayed unless the report template is configured correctly.
Cause
Required and unauthorized services or ports are report-based configurations and are not generated directly from raw scan data.
These findings appear only when:
- Services or ports are configured in the scan template.
- The related QIDs are included in the report configuration.
The following QIDs are used for these detections:
- QID 38175: Unauthorized Service Detected
- QID 82043: Unauthorized Open Port Detected
- QID 38228: Required Service Not Detected
- QID 82051: Required Port Not Detected
Solution
Configure the required or unauthorized services and ports in the scan report template.
To configure unauthorized services:
- In the VM module, click the Reports tab > Templates.
- Click New > Scan Template > QID Based Template.
.png)
- In the Services and Ports tab, select the required service from Available Services and add it to Unauthorized Services.
- Click Save to save the scan template configuration.
Example: Add http as an unauthorized service.
- Go to the Filter tab > Select Custom and add the related QID in the list
For example, add QID 38175. You may add multiple QIDs, as required for the report. - Click Save.
.png)
- Generate the scan report using the configured template.
If the HTTP service is detected on the host, QID 38175 appears in the generated scan report.
.png)
Additional Notes
You can use this configuration to:
- Detect unauthorized services running in the environment.
- Identify required services or ports that are missing.
- Enforce internal security baselines and compliance policies.
- Monitor unexpected open ports across assets.
Both services and ports can be configured independently as:
- Required
- Unauthorized
If the QIDs do not appear in the report after configuration, contact Qualys Support for further assistance.