Overview of Change Auditor for SharePoint
Change Auditor for SharePoint enables faster, easier and more secure Microsoft® SharePoint®, SharePoint Online and OneDrive for Business auditing. It tracks, audits, reports and alerts on changes to SharePoint farms, servers, sites, users, permissions and more — all in real time.
Change Auditor for SharePoint translates events into simple terms and stores data in one centralized and secure database. It also generates intelligent, in-depth reports to protect against policy violations, delivering the SharePoint and OneDrive for Business reporting data you need to pass your next audit.
Stores audit data in one centralized and secure database, providing the necessary separation of duties (SoD) between SharePoint administrators and security staff tasked with monitoring.
Audit SharePoint, SharePoint Online and OneDrive for Business environments. Change Auditor provides a single, correlated view of activity across these hybrid environments, ensuring visibility of all changes taking place in your environment whether on-premises or in the cloud.
Tracks changes to SharePoint server configurations and security changes that involve SharePoint users, permissions, farms, servers, site collections, lists and documents, which protects against system performance issues and unwanted security gaps.
Tracks user and administrator activity with detailed information including who, what, when, where, which workstation–and why for change events, plus original and current values for all changes.
Narrows searches from multiple SharePoint farms, servers and sites by event type, data range, user account and objects, enabling administrators to quickly pinpoint the source of the problem while eliminating the “noise” from safe, routine events.
Correlate disparate IT data from numerous systems and devices into an interactive search engine for fast security incident response and forensic analysis. Include user entitlements and activity, event trends, suspicious patterns and more with rich visualizations and event timelines.
Provides instant, one-click access to all information on the change you're viewing and all related events, such as what other changes came from specific users and workstations, eliminating additional guesswork and unknown security concerns.
Provides preconfigured and customizable reports that satisfy auditor requests so that administrators can get back to their regular jobs quickly.
Easily integrate with SIEM solutions to forward Change Auditor events to Splunk, HP Arcsight or IBM QRadar. Additionally, Change Auditor integrates with Quest InTrust for long-term 20:1 compressed event storage and aggregation of native or third-party logs to reduce storage costs on SIEM forwarding and create a highly-compressed log repository.
Configures access so auditors can run searches and reports without making any configuration changes to the application, and without requiring the assistance and time of the administrator.
Sends critical change and pattern alerts to email and mobile devices to prompt immediate action, enabling you to respond faster to threats even while you're not on site.
Enables the viewing, highlighting and filtering of change events and the relation of other events over the course of time in chronological order across your Windows environment for better understanding and forensic analysis of those events and trends.
Searches from anywhere using a web browser and creates targeted dashboard reports to provide upper management and auditors with access to the information they need without having to understand architecture or administration.
There are specific system requirements for the Change Auditor coordinator (server-side), Change Auditor client (client-side), Change Auditor agent (server-side), and the Change Auditor workstation and web client (optional components). For a full list of system requirements and required permissions for all components and target systems that can be audited by Change Auditor please refer to the Change Auditor Installation Guide.
The Change Auditor coordinator is responsible for fulfilling client and agent requests and for generating alerts.
Quad core Intel® Core™ i7 equivalent or better
Minimum: 8 GB RAM or better
Recommended: 32 GB RAM or better
SQL databases supported up to the following versions:
NOTE: Change Auditor supports SQL AlwaysOn Availability Groups and SQL Clusters.
Installation platforms (x64) supported up to the following versions:
NOTE: Microsoft Windows Data Access Components (MDAC) must be enabled. (MDAC is part of the operating system and enabled by default.)
For the best performance, Quest strongly recommends:
NOTE: Do NOT pre-allocate a fixed size for the Change Auditor database.
In addition, the following software/configuration is required:
Additional Account Coordinator minimum permissions required, please see Change Auditor Installation Guide .
Enable faster, easier and more secure Microsoft SharePoint auditing
Audit all events related to file activity and permissions on your FluidFS NAS devices.
Streamline Active Directory security and Group Policy Management
In this new report from the Information Security Community on LinkedIn, you will learn how your peers are approaching cybersecurity in the era of cloud, including the latest trends and benchmarks to gauge how your own organization stacks up.
This eBook provides solutions to stop insider threats, manage privileged accounts, simplify GPO management and administration.
NIST cybersecurity framework enables organizations to create a secure environment. Learn how to apply this framework to your AD and Microsoft environment.
This white paper explains the key provisions of GDPR and why organizations need to take action today to achieve compliance before May 25, 2018, when steep penalties for non-compliance take effect.
This white paper discusses best practices to prevent healthcare data breaches — focused on implementing appropriate strategies, policies, processes, training and cybersecurity defenses — that can mitigate much of the risk that healthcare organizations fac
Ensure security, compliance and control of AD and Azure AD.
Audit all events related to file activity and permissions on your EMC NAS devices.
Document all critical group, mailbox and public/private changes to Exchange
Simplify and refine LDAP query data
Audit all events related to file activity and permissions on your NetApp NAS devices.
Track, audit and receive reports on all Windows File Server real-time system changes
Ensure the security, compliance and control of event activity of VMware vCenter Servers
Self-service tools will help you to install, configure and troubleshoot your product.
Find the right level of support to accommodate the unique needs of your organization.
Search from a wide range of available service offerings delivered onsite or remote to best suit your needs.