RSA IGL Version: V 7.2.x
Modules: Governance
Product Area: Tabular Reports (Applied to Active Directory Summary Dashboard)
Associated Dashboard & Chart:
Time to apply: ~20 minutes
This report provides information about all the members of AD groups, which have been set with a "Classification" of "Admin" (See the chart: RSA IGL Recipes: Chart - AD Admin Groups for more info on setting this up)
The goal of this report is to understand the accounts which are members of these admin groups.
The report can be used by Admin/AD Teams to be understand the risk of membership to the groups.
This report requires the key word: "addashboard" to be added within the description of the AD Account Collector.
This key word can be added to more than one Account Collector if required.
This report includes information about all the accounts and so other key data points, such as if the account is disabled or orphan.
First test this in your query tool (SQLDeveloper, Toad etc..)
(select
vACM.group_name as "Group Name",
vACM.name as "Account Name",
lower(vACM.EATTR_Account_CAS4) as "Account Status",
CASE
WHEN pACC.IS_DISABLED = '0' THEN 'False'
ELSE 'True'
END AS "Is Disabled?",
case when vACM.ORPHANED_DATE is not null then 'True' else 'False' end as "Orphaned?"
from V_ACCOUNT_GROUPMEMBERSHIP vACM
left join avuser.V_DATA_COLLECTORS vDC
on vDC.id = vACM.ADC_ID
left join avuser.PV_ACCOUNT pACC
on vACM.ID = pACC.ID
where vACM.DELETION_DATE is null
and lower(vDC.DESCRIPTION) like '%addashboard%'
and vACM.EATTR_GROUPS_CAS4 = 'Admin'
ORDER BY vACM.group_name ASC)
Example of the results:
If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first.
If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support
Dont forget:
Please login, then "Like"
and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.