Report showing anywhere a specific group is detected

Running on version 3.2.1.11

we have Active directory, computer, and  NTFS discoveries running

Essentially i need a full access report by specific ad group.

i don't see any reports that seem to offer this

The intended purpose is to allow us to audit permissions granted to an AD group to plan for the migration of both the group, and the targeted resources into new domains.

Fields, i'd be happy with just group name, and location permissioned either local server group or in ntfs permissions.  If possible support for any access from any discovery would be extremely useful as well.

As well, it would be amazing when management asks to know "what does this ad group do" to be able to quickly respond with a report, as today, I'm not aware of any other options in the market to do this.

Most likely consumption will be via CSV file, however report displays will be useful for visualizing the information.

Parents Reply Children
  • this isn't what i asked for really, this is purely filesystem permissions.

    it is a bit helpful, but doesn't really provide the complete picture.

    the ask/need/requirement is to simply provide an ad group, and have a report display "all" permissions seen across "any" discovery, on any computer/resource/sql database/any other type of discovery that has been run.

    literally looking for a report that i can plug a group into, and see "all" permissions "everywhere" that quest has discovered.

    if a single report can't work across the different discovery types, then individual reports for each discovery type would be useful.  again, this is being looked at for doing active directory migrations and clean-up to try and identify where ad groups have been provisioned.

  • Thanks again for the explanation. As you mentioned that you are running AD, NTFS and Computer discoveries, this report is created for Share (computer) and NTFS permissions for the AD groups. 

    Combining all the permissions from all the discoveries will impact the performance of the report so we created report only for the discoveries you are running.
     
    We have out-of-box permissions reports for each discoveries, could you please confirm if that can fulfill you requirement?
    Computer -> Permissions -> Share Permissions
    Microsoft SQL Server -> Permissions -> Account Permissions for SQL Database Objects
    NTFS -> Permissions -> File Permissions   *** for path parameter, you can enter (Asterisk) '*' to indicate all path
    NTFS -> Permissions -> Folder Permissions  *** for path parameter, you can enter (Asterisk) '*' to indicate all path
    Note: In the account parameter, you can mentioned the AD group.
     
    Thanks
    Naureen
  • well, the asterisk processes did work for basic information.

    i'd still be very interested in a general report across any/all discoveries for a one stop audit shop for any specific ad group without having to run 4 or 5 seperate reports to attempt to find info.

  • Hello,

    Thank you for this feedback and I will log an enhancement request for this type of report to be added to our report library in a future release.   Unfortunately we will not be able to create this report at this time, as the development is working on a future release. 

    Thank you,

    Angela Freeman, Sr. Development Manager, Enterprise Reporter 

    & Michael Keenan, Sr. Product Manager, Enterprise Reporter