RSA IGL Version: V 7.2.x
Modules: Governance
Product Area: Charts, Single Series (Applied to Active Directory Summary Dashboard)
Associated Dashboard & Report:
Time to apply: ~20 minutes
This chart provides key information flagged AD "Admin" Groups.
The goal of this chart is to understand who has access to admin groups.
The chart can be used by Admin/AD Teams to monitor the access to key "admin" group in AD.
This chart requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
This chart includes a breakdown of all the different accounts within AD and if they are associatd to an active or "leaver" user.
The value are shown as a percentage, however if you move over the Pie chart, it will also show the exact value.
First test this in your query tool (SQLDeveloper, Toad etc..)
(SELECT
GROUPNAME,
TOTALMEMBERS
FROM
(
select --v3
GroupName,
case when t1.TotalMembers is null then CAST('0' AS number(20))
else t1.TotalMembers
end as TotalMembers
from avuser.V_ALL_GROUPS vAG
left join -- Counts total members
(
select distinct
vAG.Name AS GroupName,
CAS3 AS ExternalId,
count(*) as TotalMembers
from avuser.V_ALL_GROUPS vAG
left join avuser.V_GRP_MEMBERSHIPS vGM
on vGM.GROUP_ID = vAG.id
left join avuser.V_DATA_COLLECTORS vDC
on vDC.id = vAG.adc_id
where vAG.DELETION_DATE is null
and lower(vDC.DESCRIPTION) like '%addashboard%'
and vAG.cas4 = 'Admin'
group by vAG.Name, cas3
) t1
on t1.GroupName = vAG.name
left join avuser.V_DATA_COLLECTORS vDC
on vDC.id = vAG.adc_id
where vAG.DELETION_DATE is null
and lower(vDC.DESCRIPTION) like '%addashboard%'
and vAG.cas4 = 'Admin'
order by GROUPNAME ASC))
Example of the results:
From RSA IGL Link Community. This chart displays all groups flagged as Classification = "admin" and their total members.
Note: This chart requires the key word: "addashboard" to be added within the description of the Account Collector.
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first.
If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
There are MANY other "display attributes" you can play with on this screen, so please update and make changes as you see fit.
Dont forget:
Please login, then "Like"
and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.