Version: V 7.2.x
Modules: Governance
Product Area: Tabular Reports (Applied to Active Directory Summary Dashboard)
Associated Dashboard:
- RSA IGL Recipes : Dashboard - Active Directory (AD) Summary
- RSA IGL Recipes: Chart - AD Orphan Account Summary
Time to apply: ~20 minutes
Summary
This report provides information about all the orphan accounts within AD.
The goal of this report is to understand which all the orphan accounts are. We have also included "last login date" information, to help understand any potential risk associated with these orphan accounts.
The report can be used by Admin/AD Teams to be understand the risk of orphan accounts. Those which are being used to login, should have an associated owner set.
This report requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
Example Image (Click to enlarge)
Key Notes
- This chart/report/dashboard is supplied "as is" - any modification of this item is done at your own risk.
- If you have issues applying this chart/report/dashboard, please comment below for help, DO NOT contact the RSA Support team.
- If you would like more assistance with this chart/report/dashboard or for help in creating other chart/report/dashboards, then RSA Professional Services (RSA PS) is available to help.
- Please contact your RSA Account Manager or local RSA Sales Rep or reply below for further assistance.
Details
This report includes a full list of all AD orphan accounts, along with their last-login time and when they were made orphan.
Report SQL
First test this in your query tool (SQLDeveloper, Toad etc..)
(SELECT pACC.NAME as "Account Name", pACC.CAS3 AS "Account DN", pACC.LAST_LOGIN_DATE as "Last Login Date", pACC.ORPHANED_DATE as "Orphaned Date" FROM avuser.PV_ACCOUNT pACC LEFT JOIN avuser.V_DATA_COLLECTORS vDC ON pACC.ADC_ID = vDC.ID WHERE lower(vDC.DESCRIPTION) like '%addashboard%' AND ORPHANED_DATE IS NULL AND DELETION_DATE IS NULL ORDER BY pACC.NAME ASC)
Example of the results:
Report Implementation
- Log into RSA IGL as a user who can create reports. In my example, im using AveksaAdmin
- Go to "Reports" / "Tabular"
- Select "+ Create Report" button
- Under the "General Tab" add the following details:
- Name: AD Orphan Accounts
- Title: AD Orphan Accounts
- Description: From RSA IGL Link Community. This report provides information on all orphan accounts in AD. Note: This chart requires the key word: "addashboard" to be added within the description of the Account Collector.
- Scope: System
- Page Size: Letter
- Orientation: Landscape
- Under the "Query" Tab, copy the SQL from above
- In the bottom bar, press the "Style" button. "Slate" is a good recommendation for reports
- Press the "Preview" button, you should see some results, as per the example image below.
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first. If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
- Under the "Columns" Tab, please use the configuration shown in the image below
- Under the "Display Attributes" tab, please use the configuration shown in the image below
- Nothing has been set on the "Filter", "Grouping & Sorting" or "Schedule and Email" tabs
Related Articles
Workflow error: The work item count of XX exceeds the maximum limit of 10 in RSA RSA Via Lifecycle and Governance 23Number of Views Creating a RADIUS monitoring account for Citrix NetScaler in RSA Authentication Manager 8.x 94Number of Views Active Directory AFX Connector Create Account capability fails when skip certificate validation in RSA Identity Governance… 397Number of Views Resetting Password for LDAP Directory Server User in the Cloud Console Fails With Error “Unable to reset password! Please … 89Number of Views RSA Governance & Lifecycle 8.0.0 Administrators Guide 727Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Troubleshooting RSA MFA Agent for Microsoft Windows RSA Release Notes for RSA Authentication Manager 8.8 RSA Release Notes: Cloud Access Service and RSA Authenticators