RSA IGL Version: V 7.2.x
Modules: Governance
Product Area: Charts, Single Series (Applied to Active Directory Summary Dashboard)
Associated Dashboards & Report:
Time to apply: ~20 minutes
This chart provides key information about AD accounts and their associated users.
The goal of this chart is to understand the risk of potential AD accounts, still owned by a user who is a "leaver"
The chart can be used by Admin/AD Teams to be get better visibility into the risk of accounts and to take action for those which are a risk.
This chart requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
This chart includes a breakdown of all the different accounts within AD and if they are associatd to an active or "leaver" user.
The value are shown as a percentage, however if you move over the Pie chart, it will also show the exact value.
First test this in your query tool (SQLDeveloper, Toad etc..)
(SELECT INFORMATION, TOTAL FROM
(
SELECT
'Terminated Users with Active Accounts' as Information,
count(distinct pACC.ID) as Total
FROM avuser.PV_USER_ACCOUNT_MAPPING pUAM
LEFT JOIN avuser.V_DATA_COLLECTORS vDC
ON pUAM.ADC_ID = vDC.ID
LEFT JOIN avuser.PV_USERS pUSR
ON pUAM.USER_ID = pUSR.ID
LEFT JOIN avuser.PV_ACCOUNT pACC
ON pUAM.ACCOUNT_ID = pACC.ID
WHERE LOWER(vDC.DESCRIPTION) LIKE '%addashboard%'
and pACC.IS_DISABLED = 0
--and pUSR.DELETION_DATE IS NULL
and pUSR.IS_TERMINATED = 'True'
UNION ALL
SELECT
'Active Users with Active Accounts' as Information,
count(distinct pACC.ID) as Total
FROM avuser.PV_USER_ACCOUNT_MAPPING pUAM
LEFT JOIN avuser.V_DATA_COLLECTORS vDC
ON pUAM.ADC_ID = vDC.ID
LEFT JOIN avuser.PV_USERS pUSR
ON pUAM.USER_ID = pUSR.ID
LEFT JOIN avuser.PV_ACCOUNT pACC
ON pUAM.ACCOUNT_ID = pACC.ID
WHERE LOWER(vDC.DESCRIPTION) LIKE '%addashboard%'
and pACC.IS_DISABLED = 0
--and pUSR.DELETION_DATE IS NULL
and pUSR.IS_TERMINATED = 'False')
)
Example of the results:
From RSA IGL Link Community. This chart displays the percentage of accounts owned by active or terminated user for Active Directory.
Note: This chart requires the key word: "addashboard" to be added within the description of the Account Collector.
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first.
If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
There are MANY other "display attributes" you can play with on this screen, so please update and make changes as you see fit.
Dont forget:
Please login, then "Like"
and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.