NetVision

NetVision Company Blog

A Discussion on Effective Audit of User Access

Reporting on Delegated Admin Rights

Tags: , ,

Management of Active Directory is commonly delegated to local or departmental administrators.  This means that certain individuals are (for example) granted permission to create user accounts and manage security groups within a given area of the directory.  Microsoft provides a built-in wizard (known as the Delegation of Control Wizard) to delegate these tasks which does the work of applying all the underlying permissions associated to the task.

For example, here are just a few of the many underlying permissions granted when you delegate the task [Create, delete, and manage user accounts] over an OU:

  • List Contents
  • List Object
  • Delete Object
  • Delete Subtree
  • Read Permissions
  • Read All Properties
  • Modify Permissions
  • Modify Owner
  • etc.

There are potentially hundreds of underlying permissions for any given delegated task.  The challenge, therefore, lies in being able to understand and report-on which rights have been delegated over time.  How do you know who has been delegated those permissions?  How do you know when underlying permissions are updated after the wizard has applied the task?  Or when rights are applied directly without using the wizard?  How do you know who has rights to create accounts through their group memberships when groups may be several levels deep?

NetVision’s Access Rights Inspector has built-in ability for in-depth reporting on rights over Active Directory objects and that includes reporting on the tasks delegated via the Delegation of Control Wizard.  It provides extremely useful reports and removes the guesswork and manual effort associated with understanding what tasks have been delegated throughout Active Directory.

Permissions and Group Membership Cleanup

Tags: , ,

At NetVision, we hear from numerous organizations who are looking for help with cleaning up permissions that have gotten out of control over time.  David Rowe explains the challenges and provides some tips on how to tackle the job in this ESJ article titled Coming Clean: Getting a Handle on Permissions and Group Memberships.

NetVision is Hiring

Tags: ,

We’re looking for an experienced engineer to help with software builds, installation, and configuration management.  More details here.

NetVision Announces Relationship with Sparxent

TAGS: None

Today, NetVision announced our partnership with Sparxent.  More details here.

Quoted from the release:

“Today’s enterprises are strapped for resources and very often lack the expertise needed to meet compliance and audit demands,” said David Rowe, CEO of NetVision, Inc. “We’re pleased to be partnering with a value-add solutions developer like Sparxent who brings a true ground-level understanding of the business challenges related to audit and compliance. We see Sparxent as an integral part in extending our reach here and in the EMEA, where our customers will receive hands-on, localized support professionals to help them improve their audit results.”

Active Directory Group Clean Up

Tags: , ,

A recent edition of NetVision’s monthly newsletter AuditMonthly discussed the issues of permission bloat and group clean up.  There are some focus areas outlined in one of our solutions pages: Active Directory Group Clean Up.  We can help you get your arms around the issue, identify low hanging fruit, and clean things up.

The Business Value of Effective Audit

Tags: ,

There’s a new white paper on the NetVision Knowledge page titled:

The Business Value of Effective Audit

Effective access auditcan be a powerful business enabler providing significant value beyond protecting against malicious insiders. This paper identifies the business challenge, how the industry is approaching the challenge, and NetVision’s unique approach to access rights reporting and monitoring.

Microsoft Exchange Monitoring: Preview

Tags: , ,

NetVision will soon be announcing availability of our Microsoft Exchange monitoring capabilities.  Indepent of Microsoft event logs, this solution will enable you to monitor message, calendar, contact, and task activity.  Events can be triggered based on whether the initiator is the mailbox owner as well as event filtering by subsets of users.  So, for example, if a help desk user sends a message from your CEO, you might want to take different action than if the CEO’s assistant sends a message from that account.

If you’d like us to keep you updated on the Exchange monitoring release, please let us know.

Updated: Access Rights Inspector SSE

Tags: , , , ,

NetVision today released an updated version of Access Rights Inspector Single Server Edition.  The new version applies a fix to issues related to large volume size and the initial file/folder rights scan.  The SSE version is a free 30-day trial providing access rights reports on a single server. 

Access Rights Inspector SSE enables users to select user accounts/groups and files/folders to generate custom reports on access rights based on those selections.

Available Reports include:

  • Effective Rights: calculates permissions based on group memberships, inherited rights, ownership, and more.
  • Explicit Rights: provides explicit permission settings for selected accounts and resources.
  • Deny ACEs: provides a list of all locations where permissions are explicitly denied.

Click here to download a copy to get immediate reports on your server!

HIPAA: Windows Security and Active Directory

Tags: , , ,

In a new paper for NetVision customers titled Active HIPAA Response, we break down the security and privacy requirements found within the HIPAA regulation text and map NetVision policies and reports to those requirements. While organizations need to perform discovery of Protected Health Information (PHI), NetVision’s HIPAA compliance pack provides quick setup of compliance reporting related to Windows file system and Active Directory for complete coverage of Microsoft networking platforms.  The HIPAA package is also available for Novell networking environments.  NetVision isn’t claiming to make anyone compliant with a set of canned reports.  But, if you’re concerned about HIPAA requirements, the HIPAA compliance pack automates the creation of a set of reports that map to the areas within HIPAA for which NetVision can help.  Let us know if you’d like more information!

Take Ownership Issue

Tags: , , , ,

According to the two TechNet articles below, a user with the ‘take ownership’ permission on a file or folder should be able to assign ownership to a group of which they’re a member. Unfortunately, it doesn’t seem to work that way.  An error is thrown indicating that the user should have ‘restore files and directories’ permission in order to assign ownership to a group.

http://technet.microsoft.com/en-us/library/cc753659.aspx
http://technet.microsoft.com/en-us/library/cc780020(WS.10).aspx

Thanks! to FK for raising the issue (which contradicts information in the NetVision paper on Windows Access Rights)  It’s a fairly obscure find, but worth understanding.

© 2009 NetVision Company Blog. All Rights Reserved.

This blog is powered by Wordpress and Magatheme by Bryan Helmig.