Permission analyzer 2

19
PERMISSION ANALYZER V2.3 Reports NTFS permissions from the file system combined with user and group data from the Active Directory ARCHITECTURAL OVERVIEW AND SCREENSHOTS

Transcript of Permission analyzer 2

Page 1: Permission analyzer 2

PERMISSION ANALYZER V2.3

Reports NTFS permissions from the file system combined

with user and group data from the Active Directory

ARCHITECTURAL OVERVIEW AND SCREENSHOTS

Page 2: Permission analyzer 2

PROBLEM DESCRIPTON:

In a Windows environment it is not possible to view file permissions

(NTFS) by user or group. This makes it very hard to insure the operational integrity and security of your network.

SOLUTION:

Perdemia has released Permission Analyzer v2, a Windows

application that scans your network on NTFS permissions and stores

all information in a database. Users can run reports by creating

filters that include or exclude members, permissions, files, or folders.

Page 3: Permission analyzer 2

PERMISSION ANALYZER WITH EMBEDDED DATABASE

2) The application will scan (nested)

group memberships and user details

from the Active Directory

3) The application will scan

the ACLs from the file systems

1) Schedule a scan from a workstation or

file server using Windows Scheduled Tasks

or start a scan manually in the Scan View

4) Use the embedded database to

analyze permissions and to build

filters and exports

Use the embedded database to scan NTFS permissions and to create overviews:

Page 4: Permission analyzer 2

PERMISSION ANALYZER WITH A CENTRAL DATABASE

2) The application will scan (nested)

group memberships and user details

from the Active Directory

3) The application will scan

the ACLs from the file systems

1) Schedule a scan from a workstation or file

server using Windows Scheduled Tasks or

start a scan manually in the Scan View

4) Store the information in a

central database (MS SQL, DB2,

Oracle, MySQL and more)

5) Use the scanned information on

different workstations to build overviews

Use a central database server to scan NTFS permissions and to share network data, filter definitions and reports:

Page 5: Permission analyzer 2

PERMISSION ANALYZER WITH SCAN AGENTS

2) Let one file server scan the (nested)

group memberships and user details

from the Active Directory

1) Schedule a scan locally

on each file server

3) Store the information in a

central database (MS SQL,

DB2, Oracle, MySQL and more)

4) Use the scanned

information on different

workstations to build

overviews

Install Permission Analyzer on each file server and scan files locally while using a central database server to share information:

Page 6: Permission analyzer 2

PERMISSION ANALYZER WITH POWERSHELL SCRIPTS

Run a PowerShell script to export the ACL’s to a text file. This text file can be imported into Permission Analyzer

Page 7: Permission analyzer 2

SCANNING THE NETWORK

Page 8: Permission analyzer 2

OPEN THE SCAN VIEW TO ADD DIRECTORIES AND LDAP OU'S

Page 9: Permission analyzer 2

CONFIGURE MORE LDAP CONNECTIONS IN THE PREFERENCES

Page 10: Permission analyzer 2

BUILDING THE OVERVIEWS

Page 11: Permission analyzer 2

OPEN THE REPORT VIEW AND BUILD YOUR FILTERS

Page 12: Permission analyzer 2

FILTER FOR MEMBERS

Page 13: Permission analyzer 2

FILTER FOR PERMISSIONS

Page 14: Permission analyzer 2

FILTER FOR FOLDERS

Page 15: Permission analyzer 2

USE THE TRACE VIEW AND VIEW THE ORIGIN OF PERMISSIONS

Page 16: Permission analyzer 2

DEFINE REPORTS

Page 17: Permission analyzer 2

EXPORT TO HTML OR CSV

Page 18: Permission analyzer 2

DEFINE POLICIES TO CHECK FOR UNWANTED PERMISSIONS

Page 19: Permission analyzer 2

AUDIT DASHBOARD