RSA IGL Version: V 7.2.x
Modules: Governance
Product Area: Tabular Reports (Applied to Active Directory Summary Dashboard)
Associated Dashboard:
Time to apply: ~20 minutes
This report provides information about all the orphan accounts within AD.
The goal of this report is to understand which all the orphan accounts are. We have also included "last login date" information, to help understand any potential risk associated with these orphan accounts.
The report can be used by Admin/AD Teams to be understand the risk of orphan accounts. Those which are being used to login, should have an associated owner set.
This report requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
This report includes a full list of all AD accounts, which are owned by an "is_terminated" = true, user.
First test this in your query tool (SQLDeveloper, Toad etc..)
(SELECT
pUSR.USER_ID as "User ID",
pUSR.FIRST_NAME||' '||pUSR.LAST_NAME as "Full Name",
pACC.NAME as "Account Name",
pACC.CAS3 as "Unique Name"
FROM avuser.PV_USER_ACCOUNT_MAPPING pUAM
LEFT JOIN avuser.V_DATA_COLLECTORS vDC
ON pUAM.ADC_ID = vDC.ID
LEFT JOIN avuser.PV_USERS pUSR
ON pUAM.USER_ID = pUSR.ID
LEFT JOIN avuser.PV_ACCOUNT pACC
ON pUAM.ACCOUNT_ID = pACC.ID
WHERE LOWER(vDC.DESCRIPTION) LIKE '%addashboard%'
and pACC.IS_DISABLED = 0
and pUSR.IS_TERMINATED = 'True')
Example of the results:
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first.
If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
Dont forget:
Please login, then "Like"
and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.