Hello, my name is Neil Belfour. I'm one of the solution architects here at Quest Software. Today, we're going to do one of our Skills 101 sessions, Getting More Out of Your Enterprise Reporter Infrastructure.
What we'll cover-- implementation tips, recommended configuration options to maximize performance whilst minimizing discovery time. Now when I talk about these implementation tips, I'm going to give scenario examples, because based upon the type of your discoveries, locations, regional coverage, infrastructure layout, those implementation tips would certainly be recommended based upon a lot of variables within your infrastructure.
Feature overviews-- most popular features and reports and recommendations on how to organize them, how to align scheduled reports with discoveries. And some use cases we're going to touch upon-- improving security, regulatory compliance, audit reports, cleanup, pre-migration reports as well.
So we're going to jump into the technical aspect of this because I know that's what everybody is here for today. Now everybody on this call, I'm not sure 100% your familiarity with Enterprise Reporter, but it's one of our applications we certainly get many questions on, what's the best way to go about implementing it, what's the best way to go about utilizing it. We're going to touch upon how it works because understanding how it works is just as important as understanding what would be best practices when it comes to implementing an install of this application.
Now, when installing Enterprise Reporter, I'm only going to touch upon this for about 30 seconds or so, you can see that there's a lot of things that are required when installing Enterprise Reporter, from having to need administrative rights to be able to install the application, because we're going to create security groups within active directory. It's SQL back-ended, so it needs that as well. Plus, you're going to have to have further credentials, and we're going to cover that as we go through implementation.
Within Enterprise Reporter, there are two consoles. There's a Configuration Manager console and a Report Manager console. We're going to start out with the Configuration Manager console. When you bring up the Configuration Manager console, it's going to default to clusters. Enterprise Reporter uses clusters.
Now they're virtual clusters in an essence that you create. Now what dictates these clusters? Usually geographical proximity, how you want these discoveries to take place. Every cluster must use a discovery node. And what is a discovery node? Well, it's a member server that has our discovery service installed on it.
That discovery node should be in geographical proximity of any place that you're doing discoveries. So if you had an East Coast and a West Coast datacenter, you would certainly need at least one discovery engine in each of those datacenters. Because when discovering information, the type of information, the quantity of information is really what's dictating a lot of this.
So in the example that I have here, you can see I have an East Coast Datacenter and a West Coast Datacenter. Now the only cluster that I currently have enabled is local to my domain. But when you configure a cluster, you have to add discovery nodes to that cluster. This is simply a service.
Now when installing this service, you have to take a couple of things into account. You'll notice it does use a service account. This service account, by default, needs to have rights to everything that you want to discover. You can add multiple nodes here. In the case of adding multiple nodes, we would load balance and fault tolerant those discoveries.
Now, the key really comes in to the next step. Because when dealing with the next step is how you and can make or break your discoveries. I mean, I hear organizations sit there and tell me, well, the discoveries take too long. Well, how do you have this configured? There's a big difference between an Active Directory discovery and an NTFS discovery.
An Active Directory discovery, even in a larger Active Directory which has 100,000 objects, pales in comparison if you're asking us to discover 50 million files off of a NetApp or an EMC. So you have to take into account what you want to discover.
Also, SQL resources-- well, Enterprise Reporter with multiple nodes is going to discover the information more rapidly. Is your SQL Server capable of taking this information? Do we have those kind of resources on the SQL box? Are we using a SQL cluster? A lot of times, it's not just the configuration. There's reasons why there's bottlenecks.
But this is where it starts-- discoveries. When dealing with discoveries, always the default discovery that 99% of all organizations are utilizing it for is Active Directory. When you create an Active Directory discovery, you would simply go to New Discovery. Now, when creating these discoveries, there are a couple of options that you can do.
Now, Active Directory, once again, is one of the most mildest discoveries. There's always so much data that exists in Active Directory that would take time to be able to discover. But one of the tips that I always recommend, and I'm going to bring up an existing discovery here, simply on Active Directory, because most discoveries are the same. The only difference is the filter parameters that are being utilized for that type of discovery.
But in this case, I gave it a name. I'm going to give it a scope-- Active Directory domain. Well, that's kind of a wide scope. No, that's not the problem. But we're going to discover user information, groups and members, computers, domains. This is the default of what we're discovering.
But you'll notice there's an ellipsis here. Because if Active Directory discoveries are taking time, one of the first things I would check is this ellipsis. Because by default, we're going to use an automatic selection. We're going to just grab any domain controller within your infrastructure. Is there a possibility that we could grab a domain controller in the East Coast instead of the West Coast? Sure, there is.
So what I recommend is "Select available domain controllers from current Sub-net." That's what I would check. I would selectively choose that option, and we'll automatically discover a DC within that sub-net. If you what DC's specifically are in that sub-net, you could selectively choose which ones that you want to add here. So this is one of the first tips that I would recommend when configuring options.
Now one of the other things, I'm going to come back to some other types of discoveries. Because Entra discoveries, even NetApp, NAS type of appliance discoveries, require additional stuff. Well, where would I go to from that? Configuration. When I go to Configuration, you're going to look for one thing to start with-- Credential Manager. Because when you go to apply discoveries, it's going to ask you whether you want to use optional credentials, optional credentials in lieu of the service account's credentials.
Oh, OK. So the service account doesn't necessarily need access to Entra. I can specifically have accounts that have access to Entra setup and select that discovery to work under those accounts. Yes. I recommend configuring Credential Manager before you do any discoveries, with the credentials that you need to discover the platforms that you want to gather information from.
Probably 75% of Enterprise Reporter installations are of the suite version. The suite version includes all modules for discovery. If you're not on the suite version, then you would have selected modules that you're capable of discovering. You could see here, I've created certain types of accounts. Now this is an on-prem account. You'll notice on-prem account does not have to authenticate.
But if I'm listing my Entra account, it has to authenticate. And we will show you when it last authenticated. Now, due to Microsoft, you might have to authenticate one of these individual accounts up to seven or eight times for it to show last authentication. This way, you have your credentials in place before you start configuring your discoveries. It makes it a lot easier.
This account has access to SharePoint. This account has access to Entra ID. This account has access to Active Directory. Highly recommended. Also, when it comes to anything Office 365, that's one, I speak to a lot of organizations, when it comes to Enterprise Reporter for Office 365 and they have the suite, they're not utilizing it. First of all, they didn't even know they had that ability, but they're not utilizing it, because you have to use Tenant Application Management when setting up Office 365.
If you wanted to take full advantage of what Enterprise Reporter has, we are going to create six web applications within your infrastructure. You would not see Reconfigure, you would see Configure. When it comes to Exchange Online and Teams, because we view those as messaging, you have to register a certificate for it as well.
We'll take care of this process. But when you open up the Tenant Application Manager, you would add your tenant. You could see where you could add multiple tenants. You would add your tenant. Then, when you would go to configure any of these specific web applications, it's going to prompt you for credentials. We're also going to show you what access you're granting to this web application.
OK, well, what else? Well, the account that you're utilizing must have the rights to be able to create a web application within your tenant. So because of that, that's some more thinking. So when configuring for the first time your Enterprise Reporter, I would recommend highly configuring Credential Manager.
And if you plan on using it for Office 365, configure it right now. You just set up the credentials of what you need. This process only takes maybe 30 seconds per web application. It's very quick. And then you are now able to start connecting on certain discoveries.
There is one or two prereqs. The SharePoint Online Discovery requires the SharePoint Management Shell, but you would see that as well when you go to configure it. But outside of that, there's really not too much left from here. So I recommend these. When discovering a NAS, primarily, you would add your NAS right here.
We're really looking for the Host IP Address, Port, Device Type, Credential, and Description to access that NAS. So it's quite a bit that's happening at the configuration level before you can even get to discoveries. But going back once again to the discoveries, most of the discoveries are pretty much the same.
It's the data that they're discovering is completely different. So because of that, when doing a discovery, you have to take into account what you're discovering. The example I gave, 100,000 objects in an on-prem Active Directory, is completely different than maybe a remote NAS that you have that has 50 million files on it.
Now, something else I'm going to show is a configuration, and we list this as a recommendation on our best practices. If I go into an Office 365 discovery, Microsoft has a notorious habit of throttling data. It's something that they do. They like to do it. And you'll see it, the application will list it, that it's actually being throttled.
So if I bring up a Microsoft Entra discovery, what is recommendation number one that we list? Credentials. Yeah, here I'm listing those optional credentials that have access into Office 365, and it is authenticated. I can authenticate it through here. But if you followed my recommendation on the configuration, it would already be authenticated.
Next, we're going to recommend at least two accounts that have credentials to the type of information you're asking us to discover. In this case, it's just Entra ID. Why? Because then we can set up two channels for discovery. Since Microsoft is throttling information, we can pull the information twice as quick if we have multiple accounts authenticating into Office 365.
So that's a hot recommendation that we recommend. We may even list it as a point here. If I bring it up, it might show that. But going through, this is recommendation number two or three that I made. Do we list it? You can add alternate accounts with access to the target tenant for this discovery to minimize Entra throttling limitations.
When it comes to scopes of Entra, it's pretty straightforward. We're only able to discover whatever information Microsoft does make available. Now, all these discoveries can be scheduled. A lot of times scheduling comes in much more when you're looking to do very large discoveries or you're looking to run reports on a given period of time. Then you would certainly want to have that information in advance.
So, implementation tips, recommended configurations, now features. What are the biggest features when it comes to Enterprise Reporter? Well, it's a reporting application. Where is its biggest use cases? Without a doubt, improved security, SecOps. A lot of times we're on with the infrastructure team, and they would sit there and say, well, this is the type of stuff our security team is asking for us.
Regulatory compliance, always a big thing. Are you subject to any kind of regulatory compliance? I mentioned audit reports as well, my forward regulatory compliance. But now with one of the newest modules that we've added, from a reporting standpoint, is cleanup, AD modernization. Also pre-migration, it's used a lot for pre-migration, merger and acquisition. Let's find out what we don't know about that infrastructure.
When you open up the Reporting Console, you would see the Report Library. Those are the only reports that are built into the application. Now you'll quickly find out that the reports inside the Report Library cannot be edited. They cannot be modified.
They cannot be edited. They cannot be saved in any way. But you could easily go in to anything within the Report Library and simply make a copy of that report. Once you make a copy of it, then you can put it into the My Reports section or the Published Reports section.
Now, what's the difference? The Published Reports section is an area that if you customized any kind of report or saved a report, and you wanted other people who have access to this console to be able to run those reports, you could put them into your published reports. Whereas My Reports, I'm the only one who's going to see that.
Now, tip number four, I'm going on right now, what I always recommend in an Enterprise Reporter installation is organize your reports. You can see under My Reports, I have pretty much created a folder specifically which mirrors our categories in our Report Library.
Now, why did I do that? Well, because this way I can schedule these reports. I can save the parameters as default. I can tweak the reports, especially reports that I want to run on a regular basis. Because within the Report Library, any report that I go to, I would have to implement or put in my parameters that I want associated with that report.
Red X'S are a required parameter, green are an optional parameter. But I can't save these parameters as default. There is no Edit button here. So literally, if I have a report that I want to target and run on a regular basis, the first thing I should do is create a duplicate of this report and place that copy into My Reports or the Published Reports. The first thing that you would want to do.
So this way when I expand my Active Directory reports, you can see, oh, it's about two dozen reports or so that I want to run on a regular basis, that maybe I have tweaked the names a little bit with specific values. So now when I go to run a report, for example, and let's just take Domain Groups without Members, take a nice simple one. My domain is even populated here, so I don't have to put this information in.
Enterprise Reporter is an application that you might have to spend a little bit of time with in the beginning. But once you set it up to the parameters that you want and the reports that you want, and you have this discovery scheduled in advance, there's an automation that goes with it. Because by default, the reports are always going to show the last discovered information. And that's what everybody is looking for.
You'll notice I also have an Edit Report button at this point. So by far, probably one of the most popular subset of reports are Domain Groups. Domain Groups without Members, Domain Groups-- Last Modified Date, Domain Groups and Members with a DA Suffix. You can customize all these reports.
And you can see, whereas I mentioned the cleanup of Active Directory-- Users Not Logged On in the Past 60 Days, Users With Passwords Set to Never Expire. Now, this is just a handful of reports-- Computers Not Logged On in the Last (N) Days. Circular Nested Domain Groups, also popular.
But that module I talked about has gained a tremendous amount of traction within organizations because everybody understands that Active Directory is old. We've added AD Modernization reports. Now, when dealing with AD Modernization reports, we have quite a bit more in the library. But once again, these are the reports, the 8 or 9, 10 reports that I want to run on a regular basis.
Because everybody is worried about now indicators of expulsion, dangerous configuration settings that exist in my Active Directory because it's so old. So how about taking a look for privileged accounts vulnerable to a server hosting account attack. Users Golden Ticket Mitigation, the AdminSDHolder Permissions, Active Directory Permissions with Dangerous Permissions Delegated.
Yes, we are looking at the admin stamp on all accounts, all computers, and all groups to even see if any of those accounts has been manipulated in any way, maybe just internally as a bad actor. So the AD Modernization has become very popular. Now, of course, as I minimize this, well, what would also be very popular? Entra.
Entra for many organizations is still new. Yes, and I'm not talking about new from, we have AD sync running and we're syncing our objects into Entra. OK, but you're creating more now cloud-only users, cloud-only groups. You have more and more cloud applications. I showed before, Enterprise Reporter if you want to have full configuration into Office 365, we're creating six web applications in there.
Maybe I would want to see some of that information. So Entra for AD Reports, very popular. And every category, would you believe, has its own star report. If I was a basketball player, I would call it my pet shot. It's the same thing. When it comes to Exchange Reports, what does everybody want to see? Delegation Access. Because users have the ability to delegate mailboxes to anybody in the organization.
OK, maybe I would want to know who they're delegating to. Microsoft Teams, do we have a Team sprawl problem within our infrastructure? Maybe I would want to get a full list of Teams, Team members, Team ownership information. NTFS is one in many cases that tilts back to, specifically, compliance, permissions, delegated permissions, NTFS permissions, share permissions, where inheritance is broken, file information by extension, also cleanup.
Maybe I want to get a report on how many files we have that haven't been accessed in 10 years, but it's still on our public NTFS infrastructure. So NTFS, and those are some of the most extensive discoveries that we will do. I'm going to say intensive discoveries that we will do. NTFS reports are very intensive. Not so much from a reporting point, because the reports are the filter parameters that you would put in.
Key number five, I'm going to say this right here, recommendation number five, when running an NTFS report, and I can even say the same thing about an AD report, anything that is associated with File Permissions, what would be my biggest extension here? Well, if I go down to the bottom, always run it as Explicit Only.
We always have Inherited and Explicit as default. Not sure why. That's probably one of the reasons why I'm not a developer and I'm a sales architect. Run it Explicit Only. Because if you run it as Inherited and Explicit, it's going to return you a 50,000-page report, which you're going to determine quickly, that's kind of useless.
Explicit Only, same recommendation for Folder Permissions. When dealing with Active Directory Security Permissions, the same thing, make sure that you run it Explicit Permissions, not Inherited. Permissions in Active Directory, if you use Inherited, is ridiculous. Explicit Only, this is one that I changed and I saved the parameters as default.
Recommendations within Enterprise Reporter, well, I need to have reports run on a monthly basis. How would I handle something like that? Well, within Enterprise Reporter, you can only do a couple of things. You can only schedule reports that are within the My Reports or the Published Reports section. It kind of makes sense because we need to filter parameters associated with those reports.
So under the Schedule tab, you do it kind of backwards. And this is where you can see that the product was built for compliance, regulatory compliance, security, SecOps teams because you do it backwards. You create the schedule first, and then you associate a report with that schedule.
So this way when this monthly report schedule runs, I'm going to receive one report, one email with six PDFs attached to it. Whereas a lot of our reporting tools internally, hey, I want to run a report against something or a schedule, I just right mouse click on that report and schedule it.
OK, well, you can see that application was not built for any kind of compliance or security teams because I really don't want to receive 20 separate emails with one report attached to each one. So here you set up the schedule, create a new schedule, and then you attach the reports that you want. Once again, the only reports that are available are reports for within your My Reports or the Published Reports.
Now, one other thing I want to touch upon Reports, because I didn't mention about security teams. Maybe the infrastructure team wants to own the application, but security wants to be able to run certain reports at certain given times, but you really don't want them to have access to the full Enterprise Reporter Manager.
You don't want them to have access to all these reports. Maybe you have your infrastructure team, which is focused on AD reports. You really don't want them to see the Teams reports and the Exchange reports or anything out of Office 365, possibly outside of Entra. Well, all of these reports can be individually published to SQL Reporting Services.
So what I'm saying is, you can't delegate permissions in Enterprise Reporter down to individual reports. You can't do that. But you can inside of SQL Reporting Services. So when I would publish this to SQL Reporting Services, you would be able to open up SQL Reporting Services.
Now, SQL Reporting Services is no longer part of SQL. It is a separate executable. You can download it, install it, and run your own version of SQL Server Reporting Services. It just really requires IIS. But you could see here I created a folder called Enterprise Reporter.
Now, I could have had subfolders underneath here, one called maybe Communications Team, one called maybe HR, one called Infrastructure Team, and then appropriately give them rights on just simply those folders and populate the reports that they want within those folders. Now they get a very friendly web console with a link directly to the reports that they need to run.
So now you've delegated information down or delegated reports down to the individual subset category of reports, or even down to an individual report. So this way, you do not have to worry about giving somebody access to the Reporting Console, because literally within the Reporting Console, if you have access to the Reporting Console, you're going to see all the reports in the Published Reports and the Report Library. My Reports are subject to which ones you put inside of that.
Once again, Enterprise Reporter-- implementation tips, feature overviews, customer use cases, we've tried to cover a little bit of each one. If you needed further details, please feel free to reach out to your AE here at Quest Software, and they'll be able to coordinate a session with their assigned systems engineer. I want to thank you for the time today.