RSA IGL Version: V 7.2.x
Modules: Governance
Product Area: Charts, Single Series (Applied to Active Directory Summary Dashboard)
Associated Dashboards:
Time to apply: ~20 minutes
This chart provides key information about the User Account Control (UAC) status for al AD accounts.
The goal of this chart is to understand the risk of potential accounts within AD.
The chart can be used by Admin/AD Teams to be get better visibility into the risk of accounts, eg. those which are set to be "enabled, password not required"
This chart requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
This chart includes a breakdown of all the different "User Account Control" values, for all AD accounts.
The value are shown as a percentage, however if you move over the Pie chart, it will also show the exact value.
First test this in your query tool (SQLDeveloper, Toad etc..)
(
select
decode
(pA.STATUS,
'NORMAL_ACCOUNT','Enabled Accounts', --512
'ACCOUNTDISABLE,NORMAL_ACCOUNT','Disabled Accounts', --514
'PASSWD_NOTREQD,NORMAL_ACCOUNT','Enabled, Password Not Required', --544
'ACCOUNTDISABLE,PASSWD_NOTREQD,aNORMAL_ACCOUNT','Disabled, Password Not Required', --546
'NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD','Enabled, Password Doesnt Expire', --66048
'ACCOUNTDISABLE,NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD','Disabled, Password Doesnt Expire', --66050
'PASSWD_NOTREQD,NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD','Enabled, Password Doesnt Expire and Not Required', --66080
'ACCOUNTDISABLE,PASSWD_NOTREQD,NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD','Disabled, Password Doesnt Expire and Not Required', --66082
'NORMAL_ACCOUNT,SMARTCARD_REQUIRED','Enabled, Smartcard Required', --262656
'ACCOUNTDISABLE,NORMAL_ACCOUNT,SMARTCARD_REQUIRED','Disabled, Smartcard Required', --262658
'NORMAL_ACCOUNT,SMARTCARD_REQUIRED','Enabled, Smartcard Required, Password Not Required', --262688
'262690','Disabled, Smartcard Required, Password Not Required', --262690
'328192','Enabled, Smartcard Required, Password Doesnt Expire', --328192
'328194','Disabled, Smartcard Required, Password Doesnt Expire', --328194
'328224','Enabled, Smartcard Required, Password Doesnt Expire and Not Required', --328224
'328226','Disabled, Smartcard Required, Password Doesnt Expire and Not Required', --328226
'PASSWD_NOTREQD,INTERDOMAIN_TRUST_ACCOUNT','System Domain Account', --xxx
'NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD,TRUSTED_FOR_DELEGATION','Service Account, Trusted for Delegation, Kerberos', --xxx
'NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD,TRUSTED_TO_AUTH_FOR_DELEGATION','Service Account, Trusted Auth Delegation, Kerberos', --xxx
'NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD,TRUSTED_FOR_DELEGATION,DONT_REQ_PREAUTH','Service Account, Trusted for Delegation, No Kerberos', --xxx
'ACCOUNTDISABLE,NORMAL_ACCOUNT,DONT_EXPIRE_PASSWORD,TRUSTED_TO_AUTH_FOR_DELEGATION','Disabled, Service Account, Trusted Auth Delegation, Kerberos', --xxx
'NORMAL_ACCOUNT,DONT_REQ_PREAUTH','Enabled, No Kerberos' --xxx
) AS "Account Status",
Count(distinct pA.NAME) as "Total Count"
from avuser.PV_ACCOUNT pA, avuser.V_DATA_COLLECTORS vDC
where pA.IS_DISABLED = 0
and pA.ADC_ID = vDC.ID
and LOWER(vDC.DESCRIPTION) LIKE '%addashboard%'
group by pA.STATUS
)
Example of the results:
From RSA IGL Link Community. This chart displays the percentage of orphan and non-orphan accounts against the primary Active Directory.
Note: This chart requires the key word: "addashboard" to be added within the description of the Account Collector.
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first.
If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
There are MANY other "display attributes" you can play with on this screen, so please update and make changes as you see fit.
Dont forget:
Please login, then "Like"
and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.