SecurID® Governance & Lifecycle Recipes

SecurID Governance & Lifecycle recipes is a collection of items, to help you get the most out of your product deployment. For example, a useful report with the SQL to implement or a way to achieve some advanced rule processing.

RSA IGL Recipes: Report - AD Admin Group Members

RSA IGL Version: V 7.2.x

Modules: Governance

Product Area: Tabular Reports  (Applied to Active Directory Summary Dashboard)

Associated Dashboard & Chart:

Time to apply: ~20 minutes

Summary

This report provides information about all the members of AD groups, which have been set with a "Classification" of "Admin" (See the chart: RSA IGL Recipes: Chart - AD Admin Groups  for more info on setting this up) 

The goal of this report is to understand the accounts which are members of these admin groups. 

The report can be used by Admin/AD Teams to be understand the risk of membership to the groups. 

This report requires the key word: "addashboard" to be added within the description of the AD Account Collector. 
This key word can be added to more than one Account Collector if required.

pastedImage_6.png

Other useful links

 

Example Image (Click to enlarge)

pastedImage_2.png

 

Key Notes

  • This chart/report/dashboard is supplied "as is" - any modification of this item is done at your own risk. 
  • If you have issues applying this chart/report/dashboard, please comment below for help, DO NOT contact the RSA Support team.
  • If you would like more assistance with this chart/report/dashboard or for help in creating other chart/report/dashboards, then RSA Professional Services (RSA PS) is available to help.
    • Please contact your RSA Account Manager or local RSA Sales Rep or reply below for further assistance.

 

Details

This report includes information about all the accounts and so other key data points, such as if the account is disabled or orphan. 

 

Report SQL

First test this in your query tool (SQLDeveloper, Toad etc..)

(select 
vACM.group_name as "Group Name",
vACM.name as "Account Name",
lower(vACM.EATTR_Account_CAS4) as "Account Status",
CASE
WHEN pACC.IS_DISABLED = '0' THEN 'False'
ELSE 'True'
END AS "Is Disabled?",
case when vACM.ORPHANED_DATE is not null then 'True' else 'False' end as "Orphaned?"
from V_ACCOUNT_GROUPMEMBERSHIP vACM
left join avuser.V_DATA_COLLECTORS vDC
on vDC.id = vACM.ADC_ID
left join avuser.PV_ACCOUNT pACC
on vACM.ID = pACC.ID
where vACM.DELETION_DATE is null
and lower(vDC.DESCRIPTION) like '%addashboard%'
and vACM.EATTR_GROUPS_CAS4 = 'Admin'
ORDER BY vACM.group_name ASC)

 

Example of the results:

pastedImage_5.png

 

Report Implementation

  1. Log into RSA IGL as a user who can create reports. In my example, im using AveksaAdmin
  2. Go to "Reports" / "Tabular"
  3. Select "+ Create Report" button
    pastedImage_5.png
  4. Under the "General Tab" add the following details:
    • Name: AD Admin Group Members
    • Title: AD Admin Group Members
    • Description: From RSA IGL Link Community. This report provides a list of all accounts who are members of Admin Groups. Note: This chart requires the key word: "addashboard" to be added within the description of the Account Collector.
    • Scope: System
    • Page Size: Letter
    • Orientation: Landscape
      pastedImage_6.png

  5. Under the "Query" Tab, copy the SQL from above
  6. In the bottom bar, press the "Style" button. "Slate" is a good recommendation for reports
    pastedImage_14.png
  7. Press the "Preview" button, you should see some results, as per the example image below.
    If you get an error at this stage, please test your SQL in a Query tool, like "SQL Developer" or "SQL Squirrel" to ensure it works first. 
    If it still doesn't work, please share your SQL and a screen shot of the issue below. DO NOT contact RSA Support 
    pastedImage_5.png
  8. Under the "Columns" Tab, please use the configuration shown in the image below
    pastedImage_7.png

  9. Under the "Display Attributes" tab, please use the configuration shown in the image below
    pastedImage_8.png
  10. Nothing has been set on the "Filter", "Grouping & Sorting" or "Schedule and Email" tabs

 

Next Steps

  • Please "hit reply" and share your feedback - we would love to see an image of this working in your environment!
  • Check out the other content found on the RSA IGL Recipes page: RSA Identity Governance & Lifecycle Recipes 

    Thank you! 

 

Dont forget:

Please login, then "Like"  and "Actions/Follow" this page (Top Right), so as to receive updates and be notified if we modify/change items found here, in future.

pastedImage_4.png

Labels (1)
No ratings
Version history
Last update:
‎2020-12-07 09:50 AM
Updated by:
Contributors
Article Dashboard