From dc06ce3b172ee2e1fce689f00388fd92784d896c Mon Sep 17 00:00:00 2001 From: Jordan Violet <8886650+jtviolet@users.noreply.github.com> Date: Sun, 6 Sep 2026 20:19:31 -0400 Subject: [PATCH 1/6] chore(accessanalyzer): rename version folder 2601 to 26.1 Moves docs/accessanalyzer/2601, the pinned KB source, images, and sidebar to 26.1 and points products.js at the new paths. Activity Monitor cross-links now use the /26_1/ route and the integrations page the 26.1 rewrite adds. Generated with AI Co-Authored-By: Claude Code --- .claude/references/kb-editing-conventions.md | 2 +- .../configurations/_category_.json | 0 .../activity-monitor-integration.md | 78 +++++------ .../configurations/application-settings.md | 0 .../configurations/identity-provider.md | 0 .../{2601 => 26.1}/configurations/logs.md | 0 .../configurations/sensitive-data.md | 0 .../service-accounts/_category_.json | 0 .../service-accounts/client-id-certificate.md | 2 +- .../service-accounts/client-id-secret.md | 2 +- .../service-accounts/overview.md | 2 +- .../service-accounts/ssh-username-key.md | 2 +- .../service-accounts/username-password.md | 2 +- .../source-groups/_category_.json | 0 .../source-groups/scan-executions.md | 0 .../source-groups/scanners/_category_.json | 0 .../source-groups/scanners/best-practices.md | 0 .../source-groups/scanners/deploy-scanner.md | 0 .../source-groups/scanners/manage-scanners.md | 0 .../source-groups/scanners/overview.md | 0 .../source-groups/scanners/requirements.md | 0 .../configurations/source-groups/scans.md | 0 .../source-groups/source-groups.md | 0 .../{2601 => 26.1}/configurations/users.md | 2 +- .../{2601 => 26.1}/connectors/_category_.json | 0 .../connectors/activedirectory.md | 0 .../connectors/entra-id/_category_.json | 0 .../entra-id/app-registration-secret.md | 0 .../connectors/entra-id/entra-requirements.md | 0 .../connectors/entra-id/overview.md | 0 .../connectors/file-servers/_category_.json | 0 .../connectors/file-servers/celerra.md | 0 .../connectors/file-servers/cifs.md | 0 .../connectors/file-servers/dell-unity.md | 0 .../file-servers/isilon-powerscale.md | 0 .../connectors/file-servers/netapp.md | 0 .../connectors/file-servers/vnx.md | 0 .../sharepoint-online/_category_.json | 0 .../sharepoint-online/azure-permissions.md | 0 .../connectors/sharepoint-online/overview.md | 0 .../tenant-certificate-config.md | 0 .../dashboards-reports/_category_.json | 0 .../dashboards-reports/my-reports.md | 0 .../dashboards-reports/reports.md | 4 +- .../gettingstarted/_category_.json | 0 .../active-directory/_category_.json | 0 .../active-directory/active-directory.md | 0 .../active-directory/reports.md | 0 .../active-directory/scanning-options.md | 0 .../active-directory/schema-reference.md | 0 .../active-directory/set-up-source-group.md | 0 .../gettingstarted/entra-id/_category_.json | 0 .../gettingstarted/entra-id/entra-id.md | 0 .../gettingstarted/entra-id/reports.md | 0 .../entra-id/scanning-options.md | 0 .../entra-id/schema-reference.md | 0 .../entra-id/set-up-source-group.md | 0 .../file-servers/_category_.json | 0 .../file-servers/file-servers.md | 2 +- .../gettingstarted/file-servers/reports.md | 0 .../file-servers/scanning-options.md | 0 .../file-servers/schema-reference.md | 0 .../file-servers/set-up-source-group.md | 0 .../sharepoint-online/_category_.json | 0 .../sharepoint-online/reports.md | 0 .../sharepoint-online/scanning-options.md | 0 .../sharepoint-online/schema-reference.md | 0 .../sharepoint-online/set-up-source-group.md | 0 .../sharepoint-online/sharepoint-online.md | 0 docs/accessanalyzer/26.1/index.md | 67 +++++++++ .../{2601 => 26.1}/install/_category_.json | 0 .../install/identity-provider.md | 14 +- .../install/install-commands.md | 8 +- .../{2601 => 26.1}/install/postinstall.md | 4 +- .../{2601 => 26.1}/install/prerequisites.md | 0 .../{2601 => 26.1}/install/quickinstall.md | 14 +- .../{2601 => 26.1}/install/security.md | 4 +- .../install/system/_category_.json | 0 .../install/system/certificates.md | 0 .../install/system/kubernetes.md | 2 +- .../{2601 => 26.1}/install/system/network.md | 0 .../install/system/requirements.md | 0 .../{2601 => 26.1}/install/uninstall.md | 2 +- .../{2601/overview => 26.1}/keyconcepts.md | 8 +- docs/accessanalyzer/2601/index.md | 21 --- .../2601/overview/_category_.json | 6 - docs/accessanalyzer/2601/overview/overview.md | 131 ------------------ .../admin/monitoredhosts/output/output.md | 2 +- .../10.0/admin/outputs/accessanalyzer26.md | 2 +- docs/activitymonitor/10.0/install/overview.md | 2 +- .../_category_.json | 0 .../index.md | 6 +- .../kb-article-template.md | 4 +- .../migration/_category_.json | 0 .../migration/audit-data-strategy.md | 0 .../migration/index.md | 0 .../migration/migrate-credentials.md | 0 .../migration/migrate-job-configurations.md | 10 +- .../migration/migrate-proxy-servers.md | 4 +- .../migration/migrate-schedules.md | 2 +- .../migration/migrate-target-servers.md | 8 +- .../migration/migration-checklist.md | 0 .../updating-to-the-latest-version.md | 8 +- sidebars/accessanalyzer/{2601.js => 26.1.js} | 0 src/config/products.js | 10 +- src/theme/searchUtils.js | 4 +- .../add-service-account-certificate.png | Bin .../add-service-account-client-secret.png | Bin .../add-service-account-form.png | Bin .../add-service-account-ssh.png | Bin .../add-service-account-username-password.png | Bin .../configurations/scanner-deploy-form.png | Bin .../configurations/scanners-list.png | Bin .../configurations/service-accounts-list.png | Bin .../add-service-account-certificate.png | Bin .../add-service-account-client-secret.png | Bin .../migration/add-service-account-form.png | Bin .../migration/add-service-account-initial.png | Bin ...add-service-account-type-dropdown-open.png | Bin .../add-service-account-username-password.png | Bin .../create-source-group-ad-scan-config.png | Bin .../create-source-group-ad-step4.png | Bin .../migration/create-source-group-ad.png | Bin .../create-source-group-configure.png | Bin ...eate-source-group-entra-id-scan-config.png | Bin .../create-source-group-entra-id.png | Bin ...e-source-group-file-server-scan-config.png | Bin .../create-source-group-file-server-setup.png | Bin .../create-source-group-file-server-step2.png | Bin .../create-source-group-file-server-step4.png | Bin .../create-source-group-file-server.png | Bin .../migration/create-source-group-filled.png | Bin .../create-source-group-scan-config.png | Bin ...te-source-group-sharepoint-scan-config.png | Bin .../create-source-group-sharepoint.png | Bin .../migration/create-source-group-step1.png | Bin .../create-source-group-type-select.png | Bin .../migration/scan-edit-ad-scrolled.png | Bin .../{2601 => 26.1}/migration/scan-edit-ad.png | Bin .../migration/scan-edit-entra-id-scrolled.png | Bin .../migration/scan-edit-entra-id.png | Bin .../scan-edit-file-server-access-scrolled.png | Bin .../scan-edit-file-server-access.png | Bin .../scan-edit-file-server-sdd-scrolled.png | Bin .../migration/scan-edit-file-server-sdd.png | Bin .../migration/scanner-deploy-form.png | Bin .../migration/scanners-list.png | Bin .../{2601 => 26.1}/migration/scans-list.png | Bin .../migration/service-accounts-list.png | Bin .../migration/source-groups-list.png | Bin .../migration/type-dropdown-open.png | Bin 151 files changed, 175 insertions(+), 266 deletions(-) rename docs/accessanalyzer/{2601 => 26.1}/configurations/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/activity-monitor-integration.md (85%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/application-settings.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/identity-provider.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/logs.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/sensitive-data.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/client-id-certificate.md (97%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/client-id-secret.md (96%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/overview.md (96%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/ssh-username-key.md (95%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/service-accounts/username-password.md (97%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scan-executions.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/best-practices.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/deploy-scanner.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/manage-scanners.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/overview.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scanners/requirements.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/scans.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/source-groups/source-groups.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/configurations/users.md (99%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/activedirectory.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/entra-id/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/entra-id/app-registration-secret.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/entra-id/entra-requirements.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/entra-id/overview.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/celerra.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/cifs.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/dell-unity.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/isilon-powerscale.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/netapp.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/file-servers/vnx.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/sharepoint-online/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/sharepoint-online/azure-permissions.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/sharepoint-online/overview.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/connectors/sharepoint-online/tenant-certificate-config.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/dashboards-reports/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/dashboards-reports/my-reports.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/dashboards-reports/reports.md (98%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/active-directory.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/reports.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/scanning-options.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/schema-reference.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/active-directory/set-up-source-group.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/entra-id.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/reports.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/scanning-options.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/schema-reference.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/entra-id/set-up-source-group.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/file-servers.md (98%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/reports.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/scanning-options.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/schema-reference.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/file-servers/set-up-source-group.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/reports.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/scanning-options.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/schema-reference.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/set-up-source-group.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/gettingstarted/sharepoint-online/sharepoint-online.md (100%) create mode 100644 docs/accessanalyzer/26.1/index.md rename docs/accessanalyzer/{2601 => 26.1}/install/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/identity-provider.md (98%) rename docs/accessanalyzer/{2601 => 26.1}/install/install-commands.md (98%) rename docs/accessanalyzer/{2601 => 26.1}/install/postinstall.md (95%) rename docs/accessanalyzer/{2601 => 26.1}/install/prerequisites.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/quickinstall.md (98%) rename docs/accessanalyzer/{2601 => 26.1}/install/security.md (97%) rename docs/accessanalyzer/{2601 => 26.1}/install/system/_category_.json (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/system/certificates.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/system/kubernetes.md (96%) rename docs/accessanalyzer/{2601 => 26.1}/install/system/network.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/system/requirements.md (100%) rename docs/accessanalyzer/{2601 => 26.1}/install/uninstall.md (97%) rename docs/accessanalyzer/{2601/overview => 26.1}/keyconcepts.md (97%) delete mode 100644 docs/accessanalyzer/2601/index.md delete mode 100644 docs/accessanalyzer/2601/overview/_category_.json delete mode 100644 docs/accessanalyzer/2601/overview/overview.md rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/_category_.json (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/index.md (83%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/kb-article-template.md (98%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/_category_.json (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/audit-data-strategy.md (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/index.md (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migrate-credentials.md (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migrate-job-configurations.md (97%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migrate-proxy-servers.md (98%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migrate-schedules.md (98%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migrate-target-servers.md (96%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/migration/migration-checklist.md (100%) rename docs/kb/{accessanalyzer-2601 => accessanalyzer-26.1}/updating-to-the-latest-version.md (92%) rename sidebars/accessanalyzer/{2601.js => 26.1.js} (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/add-service-account-certificate.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/add-service-account-client-secret.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/add-service-account-form.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/add-service-account-ssh.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/add-service-account-username-password.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/scanner-deploy-form.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/scanners-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/configurations/service-accounts-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-certificate.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-client-secret.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-form.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-initial.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-type-dropdown-open.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/add-service-account-username-password.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-ad-scan-config.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-ad-step4.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-ad.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-configure.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-entra-id-scan-config.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-entra-id.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-file-server-scan-config.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-file-server-setup.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-file-server-step2.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-file-server-step4.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-file-server.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-filled.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-scan-config.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-sharepoint-scan-config.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-sharepoint.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-step1.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/create-source-group-type-select.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-ad-scrolled.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-ad.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-entra-id-scrolled.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-entra-id.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-file-server-access-scrolled.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-file-server-access.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-file-server-sdd-scrolled.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scan-edit-file-server-sdd.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scanner-deploy-form.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scanners-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/scans-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/service-accounts-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/source-groups-list.png (100%) rename static/images/accessanalyzer/{2601 => 26.1}/migration/type-dropdown-open.png (100%) diff --git a/.claude/references/kb-editing-conventions.md b/.claude/references/kb-editing-conventions.md index 1050e7d22a..24b796e023 100644 --- a/.claude/references/kb-editing-conventions.md +++ b/.claude/references/kb-editing-conventions.md @@ -229,7 +229,7 @@ Determine the article type from its structure first — this is authoritative an - Contains `## Overview` or `## Instructions` (or both) → **How-To (Instructions)**. Same partial-match tolerance. - Contains `## Question` or `## Answer` (or both) → **How-To (Q&A)**. If only one is present, §15 flags the other as missing — don't fall through to a different classification. -**Known edge case (not worth reordering for):** checking Instructions before Q&A means a Q&A article that happens to carry an `## Overview` heading — with no Symptom/Cause/Resolution heading, which would otherwise claim it first under the Resolution-first rule above — classifies as How-To (Instructions) instead, and gets told to add `## Instructions`. This is the mirror risk of the Resolution-first ordering, but in the opposite direction. It hits zero files in the current corpus (checked: every `## Question`+`## Overview` file also has a Symptom/Cause/Resolution heading and classifies as Resolution instead, per the Resolution-first rule — including `docs/kb/accessanalyzer-2601/kb-article-template.md`, a multi-template reference file containing all three article-type templates concatenated, which is a Resolution match, not an instance of this edge case). Documented here so a future maintainer doesn't mistake it for a new bug when a file eventually does hit it. +**Known edge case (not worth reordering for):** checking Instructions before Q&A means a Q&A article that happens to carry an `## Overview` heading — with no Symptom/Cause/Resolution heading, which would otherwise claim it first under the Resolution-first rule above — classifies as How-To (Instructions) instead, and gets told to add `## Instructions`. This is the mirror risk of the Resolution-first ordering, but in the opposite direction. It hits zero files in the current corpus (checked: every `## Question`+`## Overview` file also has a Symptom/Cause/Resolution heading and classifies as Resolution instead, per the Resolution-first rule — including `docs/kb/accessanalyzer-26.1/kb-article-template.md`, a multi-template reference file containing all three article-type templates concatenated, which is a Resolution match, not an instance of this edge case). Documented here so a future maintainer doesn't mistake it for a new bug when a file eventually does hit it. If none of these section structures are present, fall back to the title: diff --git a/docs/accessanalyzer/2601/configurations/_category_.json b/docs/accessanalyzer/26.1/configurations/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/configurations/_category_.json rename to docs/accessanalyzer/26.1/configurations/_category_.json diff --git a/docs/accessanalyzer/2601/configurations/activity-monitor-integration.md b/docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md similarity index 85% rename from docs/accessanalyzer/2601/configurations/activity-monitor-integration.md rename to docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md index be4f315fd7..d204601af0 100644 --- a/docs/accessanalyzer/2601/configurations/activity-monitor-integration.md +++ b/docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md @@ -8,9 +8,9 @@ sidebar_position: 85 ## Overview -Access Analyzer integrates with **Netwrix Activity Monitor (NAM)** to ingest real-time file system, SharePoint Online, and Microsoft 365 Copilot activity events. After you configure the integration, these events populate the activity reports in AA2601 and power anomaly detection and sensitive data activity tracking. +Access Analyzer integrates with **Netwrix Activity Monitor (NAM)** to ingest real-time file system, SharePoint Online, and Microsoft 365 Copilot activity events. After you configure the integration, these events populate the activity reports in AA26.1 and power anomaly detection and sensitive data activity tracking. -The integration works through a built-in TCP listener that NAM agents connect to over a secure, mutually authenticated TLS 1.3 channel. Events stream continuously from NAM agents into AA2601's analytics database (ClickHouse), where they become available in reports. +The integration works through a built-in TCP listener that NAM agents connect to over a secure, mutually authenticated TLS 1.3 channel. Events stream continuously from NAM agents into AA26.1's analytics database (ClickHouse), where they become available in reports. ### Architecture @@ -20,14 +20,14 @@ NAM Agent(s) │ TLS 1.3 (default port 4504) │ mTLS — client certificate required ▼ -AA2601 NAM Listener (core-api) +AA26.1 NAM Listener (core-api) │ │ Validated & buffered in memory ▼ ClickHouse (analytics database) │ ▼ -AA2601 Reports (file system activity, SharePoint, Copilot) +AA26.1 Reports (file system activity, SharePoint, Copilot) ``` ### Event Types @@ -42,7 +42,7 @@ AA2601 Reports (file system activity, SharePoint, Copilot) Authentication uses **mutual TLS with Subject Public Key Info (SPKI) hash pinning**: -- AA2601 requires TLS 1.3 and rejects older protocol versions. +- AA26.1 requires TLS 1.3 and rejects older protocol versions. - Both products perform mutual authentication by matching hashes of each other's certificate public key (SPKI hash) against a persistent allowlist in their configuration. SPKI hashes survive certificate renewal as long as the key pair is unchanged. Re-enroll only when an agent generates a new key pair. @@ -51,15 +51,15 @@ SPKI hashes survive certificate renewal as long as the key pair is unchanged. Re ## Prerequisites -Before connecting NAM agents to AA2601: +Before connecting NAM agents to AA26.1: -- **Netwrix Activity Monitor** must be installed and monitoring the hosts or services for which you want real-time activity in AA2601. Confirm monitoring is active before adding the AA2601 output. -- **TLS certificates** must be provisioned on the AA2601 server. The environment variables `SYSLOG_TLS_CERT_PATH` and `SYSLOG_TLS_KEY_PATH` specify the server certificate and private key paths. Contact your infrastructure team if the listener isn't starting. -- **Network connectivity** must allow NAM agents to reach AA2601 on TCP port 4504 (default) through any firewalls or network policies. -- You must have **Administrator** access to AA2601 to generate enrollment tokens and view enrolled agents. +- **Netwrix Activity Monitor** must be installed and monitoring the hosts or services for which you want real-time activity in AA26.1. Confirm monitoring is active before adding the AA26.1 output. +- **TLS certificates** must be provisioned on the AA26.1 server. The environment variables `SYSLOG_TLS_CERT_PATH` and `SYSLOG_TLS_KEY_PATH` specify the server certificate and private key paths. Contact your infrastructure team if the listener isn't starting. +- **Network connectivity** must allow NAM agents to reach AA26.1 on TCP port 4504 (default) through any firewalls or network policies. +- You must have **Administrator** access to AA26.1 to generate enrollment tokens and view enrolled agents. :::note -Activity data flows from NAM to AA2601 — AA2601 doesn't initiate the connection. Ensure firewalls allow outbound traffic from each NAM agent host to the AA2601 server on the configured listener port. +Activity data flows from NAM to AA26.1 — AA26.1 doesn't initiate the connection. Ensure firewalls allow outbound traffic from each NAM agent host to the AA26.1 server on the configured listener port. ::: --- @@ -68,7 +68,7 @@ Activity data flows from NAM to AA2601 — AA2601 doesn't initiate the connectio ### Step 1 — Verify the Listener Is Running -The listener starts automatically when AA2601 starts, provided TLS certificates are present and the `enable_activitymonitor_ingestion` feature flag is enabled (it is by default). +The listener starts automatically when AA26.1 starts, provided TLS certificates are present and the `enable_activitymonitor_ingestion` feature flag is enabled (it is by default). To confirm it is active: @@ -88,9 +88,9 @@ If the listener isn't running, check the application logs for the reason — mis Tokens expire after **1 hour**. Generating a new token immediately invalidates any previously issued token. A single token can enroll multiple agents and outputs simultaneously — plan your enrollment session and generate the token immediately before you begin. ::: -### Step 3 — Add the AA2601 Output in Netwrix Activity Monitor +### Step 3 — Add the AA26.1 Output in Netwrix Activity Monitor -Add an AA2601 output to each monitored host or service in NAM you want to stream into AA2601. +Add an AA26.1 output to each monitored host or service in NAM you want to stream into AA26.1. :::note The following steps describe the general configuration flow. Exact menu labels and field names in the NAM console may differ depending on your NAM version. Verify the steps against the NAM documentation for your installed version. @@ -99,7 +99,7 @@ The following steps describe the general configuration flow. Exact menu labels a 1. Open the Netwrix Activity Monitor console. 2. Navigate to the monitored host or service. 3. Add a new output and select the **Netwrix Access Analyzer 26** output type. -4. Enter the hostname or IP address of your AA2601 instance and the listener port (default: 4504). +4. Enter the hostname or IP address of your AA26.1 instance and the listener port (default: 4504). 5. Enter the enrollment token you generated in Step 2 and select **Enroll**. Ensure the connection is successful. 6. Save the output configuration. 7. Repeat for each monitored host or service. @@ -108,14 +108,14 @@ The following steps describe the general configuration flow. Exact menu labels a You can add an output in bulk by selecting multiple hosts/services and selecting **Add Output**. ::: -The NAM agent connects to AA2601, validates AA2601's certificate by comparing it to the hash embedded in the enrollment token, -presents its client certificate, and sends an enrollment request. AA2601 validates the token, adds the agent's SPKI hash to the trusted agents allowlist, and confirms enrollment. -The NAM agent also adds AA2601's SPKI hash to the allowlist. +The NAM agent connects to AA26.1, validates AA26.1's certificate by comparing it to the hash embedded in the enrollment token, +presents its client certificate, and sends an enrollment request. AA26.1 validates the token, adds the agent's SPKI hash to the trusted agents allowlist, and confirms enrollment. +The NAM agent also adds AA26.1's SPKI hash to the allowlist. After that, the agent reconnects and begins streaming events. You no longer need the enrollment token unless the agent generates a new key pair. ### Step 4 — Verify Enrollment -After enrollment, the agent appears in AA2601's trusted agents list. You can view enrolled agents via the API: +After enrollment, the agent appears in AA26.1's trusted agents list. You can view enrolled agents via the API: ``` GET /api/v1/nam-listener/agents @@ -123,7 +123,7 @@ GET /api/v1/nam-listener/agents Each entry shows the agent's hostname, source IP, and enrollment timestamp. -To confirm AA2601 is receiving events: +To confirm AA26.1 is receiving events: 1. Log in to Access Analyzer. 2. Navigate to the resource or host that NAM is monitoring. @@ -142,8 +142,8 @@ All Activity Monitor settings are at **Configuration > Application Settings > Ac | Setting | Default | Range | Description | | --- | --- | --- | --- | | `activitymonitor_tcp_port` | 4504 | 1 – 65535 | TCP port the listener binds to. Must match the port configured in NAM agent settings. | -| `activitymonitor_max_connections` | 100 | 10 – 1000 | Maximum simultaneous agent connections. AA2601 rejects connections beyond this limit at the TCP layer. | -| `activitymonitor_connection_timeout` | 900 | 5 – 3600 | Seconds of inactivity before AA2601 drops an idle agent connection. Set this to be comfortably longer than your NAM polling interval. | +| `activitymonitor_max_connections` | 100 | 10 – 1000 | Maximum simultaneous agent connections. AA26.1 rejects connections beyond this limit at the TCP layer. | +| `activitymonitor_connection_timeout` | 900 | 5 – 3600 | Seconds of inactivity before AA26.1 drops an idle agent connection. Set this to be comfortably longer than your NAM polling interval. | ### Performance and Throughput Settings @@ -151,7 +151,7 @@ All Activity Monitor settings are at **Configuration > Application Settings > Ac | --- | --- | --- | --- | | `activitymonitor_reactor_threads` | 0 (auto) | 0 – 32 | Async input/output threads for handling connections. `0` automatically uses one thread per CPU core — correct for almost all deployments. | | `activitymonitor_buffer_threads` | 8 | 1 – 16 | Writer threads that drain the in-memory event buffer to ClickHouse. More threads help sustain high write rates. | -| `activitymonitor_buffer_max_size` | 10,000 | 1,000 – 500,000 | Maximum events held in memory at once. When full, AA2601 holds new arrivals at the TCP layer (backpressure to agents) rather than dropping them. | +| `activitymonitor_buffer_max_size` | 10,000 | 1,000 – 500,000 | Maximum events held in memory at once. When full, AA26.1 holds new arrivals at the TCP layer (backpressure to agents) rather than dropping them. | | `activitymonitor_batch_size` | 100 | 10 – 1,000 | Events grouped per internal processing batch. | | `activitymonitor_batch_interval_seconds` | 10 | 1 – 60 | Maximum seconds between batch flushes to ClickHouse. The primary control for **data freshness** — lower values mean events appear in reports sooner, at the cost of more frequent small writes. | | `activitymonitor_clickhouse_batch_size` | 10,000 | 1,000 – 100,000 | Events per ClickHouse write operation. Larger batches are more efficient but increase memory usage during the write. | @@ -161,15 +161,15 @@ All Activity Monitor settings are at **Configuration > Application Settings > Ac | Setting | Default | Range | Description | | --- | --- | --- | --- | -| `activitymonitor_enrollment_first_message_timeout_seconds` | 10 | 5 – 60 | Seconds AA2601 waits for the first message after a new connection is established. AA2601 closes connections that send nothing within this window. | -| `activitymonitor_enrollment_ban_duration_seconds` | 10 | 5 – 300 | Seconds AA2601 blocks a source IP after a protocol violation (invalid enrollment code, malformed JSON, or unexpected message format). | -| `activitymonitor_max_message_size` | 16,777,216 (16 MB) | 65,536 – 67,108,864 | Maximum byte size of a single message from a NAM agent. If a message exceeds this size without a line delimiter, AA2601 drops the connection. | +| `activitymonitor_enrollment_first_message_timeout_seconds` | 10 | 5 – 60 | Seconds AA26.1 waits for the first message after a new connection is established. AA26.1 closes connections that send nothing within this window. | +| `activitymonitor_enrollment_ban_duration_seconds` | 10 | 5 – 300 | Seconds AA26.1 blocks a source IP after a protocol violation (invalid enrollment code, malformed JSON, or unexpected message format). | +| `activitymonitor_max_message_size` | 16,777,216 (16 MB) | 65,536 – 67,108,864 | Maximum byte size of a single message from a NAM agent. If a message exceeds this size without a line delimiter, AA26.1 drops the connection. | ### Shutdown Settings | Setting | Default | Range | Description | | --- | --- | --- | --- | -| `activitymonitor_shutdown_drain_timeout_seconds` | 300 | 10 – 3,600 | Maximum seconds AA2601 waits for buffered events to finish writing to ClickHouse during a graceful shutdown. After this window, AA2601 force-terminates remaining writer threads and loses any events still in the buffer. | +| `activitymonitor_shutdown_drain_timeout_seconds` | 300 | 10 – 3,600 | Maximum seconds AA26.1 waits for buffered events to finish writing to ClickHouse during a graceful shutdown. After this window, AA26.1 force-terminates remaining writer threads and loses any events still in the buffer. | --- @@ -179,13 +179,13 @@ All Activity Monitor settings are at **Configuration > Application Settings > Ac Use the default port (4504) unless you have a conflict. If you must change it: -- Update NAM agent configuration to match **before** saving the new port in AA2601. +- Update NAM agent configuration to match **before** saving the new port in AA26.1. - Update firewall rules and network policies before making the change. - Changing the port requires all connected agents to reconnect. ### TLS Certificate Management -- **Monitor certificate expiration.** AA2601 logs a warning when the server certificate is within 30 days of expiry, and again within 7 days. Treat the 30-day warning as actionable. +- **Monitor certificate expiration.** AA26.1 logs a warning when the server certificate is within 30 days of expiry, and again within 7 days. Treat the 30-day warning as actionable. - **NAM agents use self-signed certificates by default** — this is expected and supported. If you replace them with CA-signed certificates, re-enroll the agent. - **Key pair rotation requires re-enrollment.** If a NAM agent generates a new key pair, its previous SPKI hash entry will no longer match. Re-enroll the agent using a new enrollment token. Remove the stale entry via the API: `DELETE /api/v1/nam-listener/agents/:spki_hash`. @@ -213,11 +213,11 @@ Start with defaults. Only adjust if you observe specific symptoms. **If you have many agents connecting simultaneously:** - Raise `activitymonitor_max_connections` to at least the number of expected concurrent agents, with 20–30% headroom. -**Don't lower `activitymonitor_connection_timeout` below your NAM polling interval.** If NAM sends events every 5 minutes and the timeout is less than 300 seconds, AA2601 drops agents between batches and forces them to reconnect constantly. The default of 900 seconds provides safe headroom for most polling configurations. +**Don't lower `activitymonitor_connection_timeout` below your NAM polling interval.** If NAM sends events every 5 minutes and the timeout is less than 300 seconds, AA26.1 drops agents between batches and forces them to reconnect constantly. The default of 900 seconds provides safe headroom for most polling configurations. ### Kubernetes Shutdown Considerations -The `activitymonitor_shutdown_drain_timeout_seconds` setting (default: 300 seconds) controls how long AA2601 waits during graceful shutdown to flush buffered events to ClickHouse. +The `activitymonitor_shutdown_drain_timeout_seconds` setting (default: 300 seconds) controls how long AA26.1 waits during graceful shutdown to flush buffered events to ClickHouse. In Kubernetes deployments, the pod's `terminationGracePeriodSeconds` must be greater than this value plus a small buffer for the rest of the shutdown sequence. If `terminationGracePeriodSeconds` is less than the drain timeout, Kubernetes will force-kill the pod before drain completes, losing any buffered events. @@ -248,18 +248,18 @@ The listener retries startup up to 5 times with exponential backoff (starting at ### A NAM agent can't connect -- Verify network connectivity from the agent host to AA2601 on the configured port (default: 4504). +- Verify network connectivity from the agent host to AA26.1 on the configured port (default: 4504). - Verify the agent is configured with the correct hostname and port. The port in NAM agent configuration must match `activitymonitor_tcp_port`. -- Verify the agent has a valid TLS client certificate. AA2601 rejects connections without a client certificate and temporarily bans the source IP. +- Verify the agent has a valid TLS client certificate. AA26.1 rejects connections without a client certificate and temporarily bans the source IP. ### An agent connected but isn't sending data -- Verify the agent enrolled successfully. AA2601 silently rejects data connections from agents that have not completed enrollment because their SPKI hash isn't in the allowlist. Re-enroll using a new token. -- Verify `activitymonitor_connection_timeout` isn't shorter than the agent's event polling interval. If agents idle longer than the timeout, AA2601 drops them between batches and they must reconnect. +- Verify the agent enrolled successfully. AA26.1 silently rejects data connections from agents that have not completed enrollment because their SPKI hash isn't in the allowlist. Re-enroll using a new token. +- Verify `activitymonitor_connection_timeout` isn't shorter than the agent's event polling interval. If agents idle longer than the timeout, AA26.1 drops them between batches and they must reconnect. ### Events aren't appearing in reports -- Verify ClickHouse is healthy and reachable from AA2601. Writer threads log errors if ClickHouse writes fail. +- Verify ClickHouse is healthy and reachable from AA26.1. Writer threads log errors if ClickHouse writes fail. - Check `activitymonitor_batch_interval_seconds` — at the default of 10 seconds, there is a short delay between an event occurring and appearing in a report. - Check application logs for buffer queue depth statistics. If the buffer is full, ClickHouse writes may be lagging — consider increasing `activitymonitor_buffer_max_size` or `activitymonitor_clickhouse_batch_size`. @@ -270,7 +270,7 @@ Protocol violations trigger repeated IP bans (governed by `activitymonitor_enrol - Verify the agent is sending the correct enrollment payload. The agent should be a supported Netwrix Activity Monitor version. - Verify the enrollment token has not expired (1-hour TTL). An expired token causes an invalid-code rejection and a short ban. Generate a new token and retry. -Bans are short (default: 10 seconds) and reset on pod restart. For persistent issues, check NAM agent logs for the specific error response AA2601 sends during enrollment. +Bans are short (default: 10 seconds) and reset on pod restart. For persistent issues, check NAM agent logs for the specific error response AA26.1 sends during enrollment. ### Enrolled agents list has stale entries @@ -307,5 +307,5 @@ GET /api/v1/nam-listener/agents ## Related Resources - [Netwrix Activity Monitor Documentation](https://docs.netwrix.com/docs/activitymonitor) -- [Hardware and System Requirements](/docs/accessanalyzer/2601/install/system/requirements) -- [Network and Port Requirements](/docs/accessanalyzer/2601/install/system/network) +- [Hardware and System Requirements](/docs/accessanalyzer/26_1/install/system/requirements) +- [Network and Port Requirements](/docs/accessanalyzer/26_1/install/system/network) diff --git a/docs/accessanalyzer/2601/configurations/application-settings.md b/docs/accessanalyzer/26.1/configurations/application-settings.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/application-settings.md rename to docs/accessanalyzer/26.1/configurations/application-settings.md diff --git a/docs/accessanalyzer/2601/configurations/identity-provider.md b/docs/accessanalyzer/26.1/configurations/identity-provider.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/identity-provider.md rename to docs/accessanalyzer/26.1/configurations/identity-provider.md diff --git a/docs/accessanalyzer/2601/configurations/logs.md b/docs/accessanalyzer/26.1/configurations/logs.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/logs.md rename to docs/accessanalyzer/26.1/configurations/logs.md diff --git a/docs/accessanalyzer/2601/configurations/sensitive-data.md b/docs/accessanalyzer/26.1/configurations/sensitive-data.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/sensitive-data.md rename to docs/accessanalyzer/26.1/configurations/sensitive-data.md diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/_category_.json b/docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/configurations/service-accounts/_category_.json rename to docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/client-id-certificate.md b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md similarity index 97% rename from docs/accessanalyzer/2601/configurations/service-accounts/client-id-certificate.md rename to docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md index 123216bd34..8f8533f3af 100644 --- a/docs/accessanalyzer/2601/configurations/service-accounts/client-id-certificate.md +++ b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md @@ -17,7 +17,7 @@ This requires a registered application in your Entra ID tenant. The source group 3. In the **Name** field, enter a descriptive name for this service account. 4. From the **Service account type** dropdown, select **Client ID/Certificate**. - ![Add service account form showing Client ID/Certificate fields: name, client application ID, and tenant ID](/images/accessanalyzer/2601/configurations/add-service-account-certificate.png) + ![Add service account form showing Client ID/Certificate fields: name, client application ID, and tenant ID](/images/accessanalyzer/26.1/configurations/add-service-account-certificate.png) 5. In the **Client Application ID** field, enter the Application (client) ID from your Entra ID app registration. 6. In the **Tenant ID** field, enter the Directory (tenant) ID of your Entra ID tenant. diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/client-id-secret.md b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md similarity index 96% rename from docs/accessanalyzer/2601/configurations/service-accounts/client-id-secret.md rename to docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md index 254fd2415c..7c08f48a0b 100644 --- a/docs/accessanalyzer/2601/configurations/service-accounts/client-id-secret.md +++ b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md @@ -17,7 +17,7 @@ This requires a registered application in your Entra ID tenant with the appropri 3. In the **Name** field, enter a descriptive name for this service account. 4. From the **Service account type** dropdown, select **Client ID/Secret**. - ![Add service account form showing Client ID/Secret fields: name, client application ID, and client secret](/images/accessanalyzer/2601/configurations/add-service-account-client-secret.png) + ![Add service account form showing Client ID/Secret fields: name, client application ID, and client secret](/images/accessanalyzer/26.1/configurations/add-service-account-client-secret.png) 5. In the **Client Application ID** field, enter the Application (client) ID from your Entra ID app registration. 6. In the **Client Secret** field, enter a client secret value generated for the registered application. diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/overview.md b/docs/accessanalyzer/26.1/configurations/service-accounts/overview.md similarity index 96% rename from docs/accessanalyzer/2601/configurations/service-accounts/overview.md rename to docs/accessanalyzer/26.1/configurations/service-accounts/overview.md index d8d8a0d429..ccba4dfcc4 100644 --- a/docs/accessanalyzer/2601/configurations/service-accounts/overview.md +++ b/docs/accessanalyzer/26.1/configurations/service-accounts/overview.md @@ -10,7 +10,7 @@ Service accounts store the credentials Access Analyzer uses to authenticate agai Navigate to **Configuration** > **Service Accounts** to manage service accounts. -![Service Accounts list showing existing accounts by name, type, source group, and creation date](/images/accessanalyzer/2601/configurations/service-accounts-list.png) +![Service Accounts list showing existing accounts by name, type, source group, and creation date](/images/accessanalyzer/26.1/configurations/service-accounts-list.png) ## Credential types by data source diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/ssh-username-key.md b/docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md similarity index 95% rename from docs/accessanalyzer/2601/configurations/service-accounts/ssh-username-key.md rename to docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md index 07bd38a7cd..ce21ae278c 100644 --- a/docs/accessanalyzer/2601/configurations/service-accounts/ssh-username-key.md +++ b/docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md @@ -15,7 +15,7 @@ The SSH Username/Key credential type authenticates using an SSH username and pri 3. In the **Name** field, enter a descriptive name for this service account. 4. From the **Service account type** dropdown, select **SSH Username/Key**. - ![Add service account form showing SSH Username/Key fields: name, SSH username, and SSH key](/images/accessanalyzer/2601/configurations/add-service-account-ssh.png) + ![Add service account form showing SSH Username/Key fields: name, SSH username, and SSH key](/images/accessanalyzer/26.1/configurations/add-service-account-ssh.png) 5. In the **SSH Username** field, enter the username for the SSH account. 6. In the **SSH Key** field, paste the SSH private key. diff --git a/docs/accessanalyzer/2601/configurations/service-accounts/username-password.md b/docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md similarity index 97% rename from docs/accessanalyzer/2601/configurations/service-accounts/username-password.md rename to docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md index 75b349dc07..13d54dd8a7 100644 --- a/docs/accessanalyzer/2601/configurations/service-accounts/username-password.md +++ b/docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md @@ -15,7 +15,7 @@ Active Directory and file server source groups use the Username and Password cre 3. In the **Name** field, enter a descriptive name for this service account. 4. From the **Service account type** dropdown, select **Username/Password**. - ![Add service account form showing Username/Password fields: name, username, and password](/images/accessanalyzer/2601/configurations/add-service-account-username-password.png) + ![Add service account form showing Username/Password fields: name, username, and password](/images/accessanalyzer/26.1/configurations/add-service-account-username-password.png) 5. In the **Username** field, enter the domain account in `DOMAIN\username` or `username@domain` format. 6. In the **Password** field, enter the account password. diff --git a/docs/accessanalyzer/2601/configurations/source-groups/_category_.json b/docs/accessanalyzer/26.1/configurations/source-groups/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/_category_.json rename to docs/accessanalyzer/26.1/configurations/source-groups/_category_.json diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scan-executions.md b/docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scan-executions.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/_category_.json b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/_category_.json rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/_category_.json diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/best-practices.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/best-practices.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/deploy-scanner.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/deploy-scanner.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/manage-scanners.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/manage-scanners.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/overview.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/overview.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scanners/requirements.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scanners/requirements.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/scans.md b/docs/accessanalyzer/26.1/configurations/source-groups/scans.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/scans.md rename to docs/accessanalyzer/26.1/configurations/source-groups/scans.md diff --git a/docs/accessanalyzer/2601/configurations/source-groups/source-groups.md b/docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md similarity index 100% rename from docs/accessanalyzer/2601/configurations/source-groups/source-groups.md rename to docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md diff --git a/docs/accessanalyzer/2601/configurations/users.md b/docs/accessanalyzer/26.1/configurations/users.md similarity index 99% rename from docs/accessanalyzer/2601/configurations/users.md rename to docs/accessanalyzer/26.1/configurations/users.md index 7ceb78f36a..6f9314f0d2 100644 --- a/docs/accessanalyzer/2601/configurations/users.md +++ b/docs/accessanalyzer/26.1/configurations/users.md @@ -55,7 +55,7 @@ On first login, Access Analyzer prompts you to enroll an authenticator app for M Keep the bootstrap account active as an emergency recovery account, but don't use it for routine user management. Create at least one named User Admin account during initial setup and use that account for ongoing administration. ::: -For the full first-login walkthrough, see [Quick Install — Step 6](/docs/accessanalyzer/2601/install/quickinstall#step-6-sign-in). +For the full first-login walkthrough, see [Quick Install — Step 6](/docs/accessanalyzer/26_1/install/quickinstall#step-6-sign-in). ## Recommended initial setup diff --git a/docs/accessanalyzer/2601/connectors/_category_.json b/docs/accessanalyzer/26.1/connectors/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/connectors/_category_.json rename to docs/accessanalyzer/26.1/connectors/_category_.json diff --git a/docs/accessanalyzer/2601/connectors/activedirectory.md b/docs/accessanalyzer/26.1/connectors/activedirectory.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/activedirectory.md rename to docs/accessanalyzer/26.1/connectors/activedirectory.md diff --git a/docs/accessanalyzer/2601/connectors/entra-id/_category_.json b/docs/accessanalyzer/26.1/connectors/entra-id/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/connectors/entra-id/_category_.json rename to docs/accessanalyzer/26.1/connectors/entra-id/_category_.json diff --git a/docs/accessanalyzer/2601/connectors/entra-id/app-registration-secret.md b/docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/entra-id/app-registration-secret.md rename to docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md diff --git a/docs/accessanalyzer/2601/connectors/entra-id/entra-requirements.md b/docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/entra-id/entra-requirements.md rename to docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md diff --git a/docs/accessanalyzer/2601/connectors/entra-id/overview.md b/docs/accessanalyzer/26.1/connectors/entra-id/overview.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/entra-id/overview.md rename to docs/accessanalyzer/26.1/connectors/entra-id/overview.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/_category_.json b/docs/accessanalyzer/26.1/connectors/file-servers/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/_category_.json rename to docs/accessanalyzer/26.1/connectors/file-servers/_category_.json diff --git a/docs/accessanalyzer/2601/connectors/file-servers/celerra.md b/docs/accessanalyzer/26.1/connectors/file-servers/celerra.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/celerra.md rename to docs/accessanalyzer/26.1/connectors/file-servers/celerra.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/cifs.md b/docs/accessanalyzer/26.1/connectors/file-servers/cifs.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/cifs.md rename to docs/accessanalyzer/26.1/connectors/file-servers/cifs.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/dell-unity.md b/docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/dell-unity.md rename to docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/isilon-powerscale.md b/docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/isilon-powerscale.md rename to docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/netapp.md b/docs/accessanalyzer/26.1/connectors/file-servers/netapp.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/netapp.md rename to docs/accessanalyzer/26.1/connectors/file-servers/netapp.md diff --git a/docs/accessanalyzer/2601/connectors/file-servers/vnx.md b/docs/accessanalyzer/26.1/connectors/file-servers/vnx.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/file-servers/vnx.md rename to docs/accessanalyzer/26.1/connectors/file-servers/vnx.md diff --git a/docs/accessanalyzer/2601/connectors/sharepoint-online/_category_.json b/docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/connectors/sharepoint-online/_category_.json rename to docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json diff --git a/docs/accessanalyzer/2601/connectors/sharepoint-online/azure-permissions.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/sharepoint-online/azure-permissions.md rename to docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md diff --git a/docs/accessanalyzer/2601/connectors/sharepoint-online/overview.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/sharepoint-online/overview.md rename to docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md diff --git a/docs/accessanalyzer/2601/connectors/sharepoint-online/tenant-certificate-config.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md similarity index 100% rename from docs/accessanalyzer/2601/connectors/sharepoint-online/tenant-certificate-config.md rename to docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md diff --git a/docs/accessanalyzer/2601/dashboards-reports/_category_.json b/docs/accessanalyzer/26.1/dashboards-reports/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/dashboards-reports/_category_.json rename to docs/accessanalyzer/26.1/dashboards-reports/_category_.json diff --git a/docs/accessanalyzer/2601/dashboards-reports/my-reports.md b/docs/accessanalyzer/26.1/dashboards-reports/my-reports.md similarity index 100% rename from docs/accessanalyzer/2601/dashboards-reports/my-reports.md rename to docs/accessanalyzer/26.1/dashboards-reports/my-reports.md diff --git a/docs/accessanalyzer/2601/dashboards-reports/reports.md b/docs/accessanalyzer/26.1/dashboards-reports/reports.md similarity index 98% rename from docs/accessanalyzer/2601/dashboards-reports/reports.md rename to docs/accessanalyzer/26.1/dashboards-reports/reports.md index fc48660abf..fd82bfe7d8 100644 --- a/docs/accessanalyzer/2601/dashboards-reports/reports.md +++ b/docs/accessanalyzer/26.1/dashboards-reports/reports.md @@ -19,7 +19,7 @@ Reports are organized by data source type and grouped by category in the navigat ## File Server reports -For full details on these reports, see [File Server Reports](/docs/accessanalyzer/2601/gettingstarted/file-servers/reports). +For full details on these reports, see [File Server Reports](/docs/accessanalyzer/26_1/gettingstarted/file-servers/reports). ### Access @@ -60,7 +60,7 @@ For full details on these reports, see [File Server Reports](/docs/accessanalyze ## SharePoint Online reports -For full details on these reports, see [SharePoint Online Reports](/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/reports). +For full details on these reports, see [SharePoint Online Reports](/docs/accessanalyzer/26_1/gettingstarted/sharepoint-online/reports). ### Access diff --git a/docs/accessanalyzer/2601/gettingstarted/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/_category_.json rename to docs/accessanalyzer/26.1/gettingstarted/_category_.json diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/_category_.json rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/active-directory.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/active-directory.md rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/reports.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/reports.md rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/scanning-options.md rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/schema-reference.md rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md diff --git a/docs/accessanalyzer/2601/gettingstarted/active-directory/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/active-directory/set-up-source-group.md rename to docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/entra-id/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/_category_.json rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/_category_.json diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/entra-id.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/entra-id.md rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/reports.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/reports.md rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/scanning-options.md rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/schema-reference.md rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md diff --git a/docs/accessanalyzer/2601/gettingstarted/entra-id/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/entra-id/set-up-source-group.md rename to docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/_category_.json rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/file-servers.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md similarity index 98% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/file-servers.md rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md index 1eaab1b140..6c7dcf2971 100644 --- a/docs/accessanalyzer/2601/gettingstarted/file-servers/file-servers.md +++ b/docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md @@ -46,5 +46,5 @@ When you add a file server source group, Access Analyzer automatically creates a ::: :::note -File activity reports — including open, modify, and delete events, and anomaly detection — require a separate **Netwrix Activity Monitor** deployment. Without Activity Monitor, activity-related reports will show no data. See [File Activity Monitoring](../../overview/overview.md#key-capabilities) for details. +File activity reports — including open, modify, and delete events, and anomaly detection — require a separate **Netwrix Activity Monitor** deployment. Without Activity Monitor, activity-related reports will show no data. See [File Activity Monitoring](../../index.md#key-capabilities) for details. ::: diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/reports.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/reports.md rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/scanning-options.md rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/schema-reference.md rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md diff --git a/docs/accessanalyzer/2601/gettingstarted/file-servers/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/file-servers/set-up-source-group.md rename to docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/_category_.json rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/_category_.json diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/reports.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/reports.md rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/scanning-options.md rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/schema-reference.md rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/set-up-source-group.md rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md diff --git a/docs/accessanalyzer/2601/gettingstarted/sharepoint-online/sharepoint-online.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md similarity index 100% rename from docs/accessanalyzer/2601/gettingstarted/sharepoint-online/sharepoint-online.md rename to docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md diff --git a/docs/accessanalyzer/26.1/index.md b/docs/accessanalyzer/26.1/index.md new file mode 100644 index 0000000000..e61df81485 --- /dev/null +++ b/docs/accessanalyzer/26.1/index.md @@ -0,0 +1,67 @@ +--- +id: access-analyzer +title: "Access Analyzer" +pagination_label: Access Analyzer +keywords: ['access', 'analyzer', 'dspm'] +description: "Netwrix Access Analyzer, an on-premises DSPM product for data security and access analysis" +sidebar_position: 1 +--- + +# Overview + +Access Analyzer is an on-premises Data Security Posture Management (DSPM) product that helps organizations discover, classify, and report on sensitive data across enterprise file systems. Deployed on your own infrastructure, it provides visibility into data access patterns, identifies compliance risks, and more, all without sending data to the cloud. + +Today, Access Analyzer has three functional components: + +- **Discovery** - Connect to file systems, cloud file sources, and your identity systems to collect metadata about your files and employees +- **Classification** - Detect and classify your data using our pattern classifier +- **Reporting** - Visualize your security posture with built-in dashboards + +:::note Using an older version? +This documentation covers **Access Analyzer version 26.0**. If you are running a previous Windows-based version, select your version from the following list: + +- [Access Analyzer 12.0 documentation](https://docs.netwrix.com/docs/accessanalyzer/12_0) +- [Access Analyzer 11.6 documentation](https://docs.netwrix.com/docs/accessanalyzer/11_6) +::: + +## Discovery + +One of the three major components to Access Analyzer is discovering the files and other metadata available within your sources. When you add a Service Account & a Source then setup a Scan, Access Analyzer immediately starts pulling in this metadata. + +An optional but powerful feature of Access Analyzer is that you can run Access Analyzer Agents anywhere, and these agents can share the load of your scans (or handle them entirely!). This is great to ensure data never leaves certain regions or to improve discovery performance by handling the discovery process close to the source. + +:::note +The discovery process is a read-only operation. Access Analyzer does not modify objects on a source. It also does not install persistent agents on file servers or domain controllers. +::: + +## Classification + +Once you have gotten the metadata about your information and where it lives you can classify that information by reading it in and classifying that information with known patterns. We do this today with our Pattern Classifier. + +## Reporting + +After each scan, Access Analyzer stores results in a high-performance analytics database and makes them available through embedded dashboards and reports. Security teams can filter by domain, file server, site, classification type, and more to drill into specific findings without having to write queries. + +Below are just a few examples of the reports available: + +| Report | Description | +| --- | --- | +| **Sensitive Data Discovery** | Classifies file content across file servers and SharePoint Online against built-in detection patterns for PII, PHI, credentials, and financial data. Access Analyzer maps findings to compliance frameworks including GDPR, HIPAA, PCI DSS, and CCPA. | +| **Access Risk Analysis** | Identifies open access, overly permissive ACLs, broken permission inheritance, and stale entitlements across file shares and SharePoint sites. Shows effective permissions for any user or group. | +| **Identity Inventory** | Continuously syncs users, groups, memberships, and roles from Active Directory and Entra ID. Tracks group nesting, stale accounts, and role assignments across your identity providers. | +| **File Activity Monitoring** | Ingests real-time file system and SharePoint activity events from Netwrix Activity Monitor. Powers activity reports and enables anomaly detection and sensitive data activity tracking. Requires a separate Netwrix Activity Monitor deployment. | + +# Supported Source Types + +Where can you look for information in your environment? Today, Access Analyzer supports connecting to the following sources types: + +| Name | Type | Connection Method | +|---|---|---| +| Active Directory | Identity | LDAP/LDAPS | +| Entra ID | Identity | API | +| SMB (generic) | File System | SMB 3.x | +| NetApp | File System | SMB 3.x | +| Dell PowerScale (formerly Isilon) | File System | SMB 3.x | +| Windows File Server | File System | SMB 3.x | +| Nutanix | File System | SMB 3.x | +| Microsoft 365 (M365) | Cloud Storage | API | diff --git a/docs/accessanalyzer/2601/install/_category_.json b/docs/accessanalyzer/26.1/install/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/install/_category_.json rename to docs/accessanalyzer/26.1/install/_category_.json diff --git a/docs/accessanalyzer/2601/install/identity-provider.md b/docs/accessanalyzer/26.1/install/identity-provider.md similarity index 98% rename from docs/accessanalyzer/2601/install/identity-provider.md rename to docs/accessanalyzer/26.1/install/identity-provider.md index 80c62fdb3b..46deb34ee0 100644 --- a/docs/accessanalyzer/2601/install/identity-provider.md +++ b/docs/accessanalyzer/26.1/install/identity-provider.md @@ -169,9 +169,9 @@ If an internal CA not in the OS trust store (typical for on-prem AD) signs your export LICENSE_KEY='[YOUR_LICENSE_KEY]' curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --hostname aa2601.corp.example.com \ - --tls-cert /opt/dspm-tls/aa2601.crt \ - --tls-key /opt/dspm-tls/aa2601.key \ + --hostname aa26.1.corp.example.com \ + --tls-cert /opt/dspm-tls/aa26.1.crt \ + --tls-key /opt/dspm-tls/aa26.1.key \ --ca-bundle /opt/dspm-tls/ca-bundle.crt \ --idp-type ad \ --idp-alias active-directory \ @@ -198,9 +198,9 @@ Use this type for OpenLDAP and other non-AD LDAP directories. export LICENSE_KEY='[YOUR_LICENSE_KEY]' curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --hostname aa2601.corp.example.com \ - --tls-cert /opt/dspm-tls/aa2601.crt \ - --tls-key /opt/dspm-tls/aa2601.key \ + --hostname aa26.1.corp.example.com \ + --tls-cert /opt/dspm-tls/aa26.1.crt \ + --tls-key /opt/dspm-tls/aa26.1.key \ --ca-bundle /opt/dspm-tls/ca-bundle.crt \ --idp-type ldap \ --idp-alias ldap \ @@ -513,7 +513,7 @@ If the cluster is healthy but IdP configuration failed, re-run the installer wit ```bash curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ --configure-idp-only \ - --hostname aa2601.corp.example.com \ + --hostname aa26.1.corp.example.com \ --ca-bundle /opt/dspm-tls/ca-bundle.crt \ --idp-type \ --idp-alias \ diff --git a/docs/accessanalyzer/2601/install/install-commands.md b/docs/accessanalyzer/26.1/install/install-commands.md similarity index 98% rename from docs/accessanalyzer/2601/install/install-commands.md rename to docs/accessanalyzer/26.1/install/install-commands.md index 9626d78acd..892905dcc7 100644 --- a/docs/accessanalyzer/2601/install/install-commands.md +++ b/docs/accessanalyzer/26.1/install/install-commands.md @@ -88,11 +88,11 @@ Export the variables before running the installer. When you set the same option | Environment variable | Equivalent flag | Example | | --- | --- | --- | | `LICENSE_KEY` | `--license-key` | `NWRX-XXXX-XXXX-XXXX` | -| `DSPM_HOSTNAME` | `--hostname` | `aa2601.corp.example.com` | +| `DSPM_HOSTNAME` | `--hostname` | `aa26.1.corp.example.com` | | `TARGET_REVISION` | `--target-revision` | `1.0.8` (pinned) or omit for latest | | `SIZE` | `--size` | `small`, `medium` (default), `large`, `enterprise` | -| `TLS_CERT_FILE` | `--tls-cert` | `/opt/dspm-tls/aa2601.crt` | -| `TLS_KEY_FILE` | `--tls-key` | `/opt/dspm-tls/aa2601.key` | +| `TLS_CERT_FILE` | `--tls-cert` | `/opt/dspm-tls/aa26.1.crt` | +| `TLS_KEY_FILE` | `--tls-key` | `/opt/dspm-tls/aa26.1.key` | | `TLS_CA_BUNDLE_FILE` | `--ca-bundle` | `/opt/dspm-tls/ca-bundle.crt` | | `IDP_TYPE` | `--idp-type` | `ad`, `ldap` | | `IDP_ALIAS` | `--idp-alias` | `corporate-ad` (no spaces) | @@ -257,7 +257,7 @@ The installer checks the following before installation begins. The installer wri A **FAIL** result stops the installer. Resolve it before retrying. A **WARN** result also stops the installer by default — see [If the Installer Stops with Warnings](#if-the-installer-stops-with-warnings). -For the full list of required network domains, see [Network and Port Requirements](/docs/accessanalyzer/2601/install/system/network). +For the full list of required network domains, see [Network and Port Requirements](/docs/accessanalyzer/26_1/install/system/network). ## If the Installer Stops with Warnings diff --git a/docs/accessanalyzer/2601/install/postinstall.md b/docs/accessanalyzer/26.1/install/postinstall.md similarity index 95% rename from docs/accessanalyzer/2601/install/postinstall.md rename to docs/accessanalyzer/26.1/install/postinstall.md index e1ef68c85d..58eeee2004 100644 --- a/docs/accessanalyzer/2601/install/postinstall.md +++ b/docs/accessanalyzer/26.1/install/postinstall.md @@ -23,7 +23,7 @@ All pods should be in one of these states: | `Running` | Pod is active and healthy | | `Completed` | One-time job completed successfully | -If any pods show `CrashLoopBackOff`, `Error`, or `ImagePullBackOff`, check the [application logs](/docs/accessanalyzer/2601/configurations/logs). +If any pods show `CrashLoopBackOff`, `Error`, or `ImagePullBackOff`, check the [application logs](/docs/accessanalyzer/26_1/configurations/logs). ## ArgoCD Application Status @@ -92,6 +92,6 @@ kubectl top pods -A --sort-by=memory ## Next Steps -- [Create your first admin account](/docs/accessanalyzer/2601/configurations/users) and sign in +- [Create your first admin account](/docs/accessanalyzer/26_1/configurations/users) and sign in - [Configure a data source](../gettingstarted/active-directory/active-directory.md) and run your first scan - Run `dspmctl --help` for ongoing application management via the command line tool diff --git a/docs/accessanalyzer/2601/install/prerequisites.md b/docs/accessanalyzer/26.1/install/prerequisites.md similarity index 100% rename from docs/accessanalyzer/2601/install/prerequisites.md rename to docs/accessanalyzer/26.1/install/prerequisites.md diff --git a/docs/accessanalyzer/2601/install/quickinstall.md b/docs/accessanalyzer/26.1/install/quickinstall.md similarity index 98% rename from docs/accessanalyzer/2601/install/quickinstall.md rename to docs/accessanalyzer/26.1/install/quickinstall.md index 9bb1fe6c52..e64a1cece1 100644 --- a/docs/accessanalyzer/2601/install/quickinstall.md +++ b/docs/accessanalyzer/26.1/install/quickinstall.md @@ -44,7 +44,7 @@ The required disk space scales with the number of objects across your sources, n ::: :::note -If the server runs on a hypervisor, configure **static memory allocation** (not dynamic/ballooned memory). See [Hardware and System Requirements](/docs/accessanalyzer/2601/install/system/requirements) for hypervisor-specific instructions. +If the server runs on a hypervisor, configure **static memory allocation** (not dynamic/ballooned memory). See [Hardware and System Requirements](/docs/accessanalyzer/26_1/install/system/requirements) for hypervisor-specific instructions. - **VMware vSphere:** disable memory ballooning (`mem.balloon.enable = "FALSE"`) - **Hyper-V:** use static memory (`Set-VMMemory -DynamicMemoryEnabled $false`) @@ -161,11 +161,11 @@ These ports handle service-to-service communication within the Access Analyzer V | 9000 | TCP | ClickHouse | Native protocol | | 6379 | TCP | Redis | Cache and queue connections | -For firewall rule examples, see [Network and Port Requirements](/docs/accessanalyzer/2601/install/system/network). +For firewall rule examples, see [Network and Port Requirements](/docs/accessanalyzer/26_1/install/system/network). ## Required Domains -All outbound endpoints use HTTPS (port 443). The Access Analyzer server must reach the following domains before installation. For firewall rule examples, see [Network and Port Requirements](/docs/accessanalyzer/2601/install/system/network). +All outbound endpoints use HTTPS (port 443). The Access Analyzer server must reach the following domains before installation. For firewall rule examples, see [Network and Port Requirements](/docs/accessanalyzer/26_1/install/system/network). | Endpoint | Category | Purpose | When Required | | --- | --- | --- | --- | @@ -329,7 +329,7 @@ sudo update-ca-certificates ```bash export LICENSE_KEY="" -export DSPM_HOSTNAME="" +export DSPM_HOSTNAME="" ``` The Entra ID installer is invoked using CLI flags rather than environment variables. The flags are passed directly to the install command in Step 3. @@ -338,9 +338,9 @@ The Entra ID installer is invoked using CLI flags rather than environment variab | Flag | Description | Example | | --- | --- | --- | -| `--hostname` | Fully qualified domain name. Must be lowercase and match the cert SAN | `aa2601.corp.example.com` | -| `--tls-cert` | Full path to PEM server certificate | `/opt/dspm-tls/aa2601.crt` | -| `--tls-key` | Full path to PEM private key | `/opt/dspm-tls/aa2601.key` | +| `--hostname` | Fully qualified domain name. Must be lowercase and match the cert SAN | `aa26.1.corp.example.com` | +| `--tls-cert` | Full path to PEM server certificate | `/opt/dspm-tls/aa26.1.crt` | +| `--tls-key` | Full path to PEM private key | `/opt/dspm-tls/aa26.1.key` | | `--ca-bundle` | Full path to CA bundle | `/opt/dspm-tls/ca-bundle.crt` | | `--idp-type` | Identity provider type for Entra ID OIDC | `entra-oidc` | | `--idp-alias` | Login button label. Letters, digits, hyphens, underscores, dots only | `entra-id` | diff --git a/docs/accessanalyzer/2601/install/security.md b/docs/accessanalyzer/26.1/install/security.md similarity index 97% rename from docs/accessanalyzer/2601/install/security.md rename to docs/accessanalyzer/26.1/install/security.md index 089088c18e..79151c09fd 100644 --- a/docs/accessanalyzer/2601/install/security.md +++ b/docs/accessanalyzer/26.1/install/security.md @@ -24,12 +24,12 @@ Your Netwrix license key provides access to the Open Container Initiative (OCI) - Restrict access to the K3s API server (port 6443) to trusted networks only - Limit inbound access to the Access Analyzer web interface to authorized IP ranges -- Use firewall rules to allow only the minimum required outbound endpoints — see [Network Configuration](/docs/accessanalyzer/2601/install/system/network) +- Use firewall rules to allow only the minimum required outbound endpoints — see [Network Configuration](/docs/accessanalyzer/26_1/install/system/network) ## TLS / SSL - Replace the default self-signed certificate with a certificate issued by a trusted CA for production use -- Mount your organization's CA bundle to enable outbound TLS verification — see [SSL / TLS Configuration](/docs/accessanalyzer/2601/install/system/certificates) +- Mount your organization's CA bundle to enable outbound TLS verification — see [SSL / TLS Configuration](/docs/accessanalyzer/26_1/install/system/certificates) ## RBAC and Access Control diff --git a/docs/accessanalyzer/2601/install/system/_category_.json b/docs/accessanalyzer/26.1/install/system/_category_.json similarity index 100% rename from docs/accessanalyzer/2601/install/system/_category_.json rename to docs/accessanalyzer/26.1/install/system/_category_.json diff --git a/docs/accessanalyzer/2601/install/system/certificates.md b/docs/accessanalyzer/26.1/install/system/certificates.md similarity index 100% rename from docs/accessanalyzer/2601/install/system/certificates.md rename to docs/accessanalyzer/26.1/install/system/certificates.md diff --git a/docs/accessanalyzer/2601/install/system/kubernetes.md b/docs/accessanalyzer/26.1/install/system/kubernetes.md similarity index 96% rename from docs/accessanalyzer/2601/install/system/kubernetes.md rename to docs/accessanalyzer/26.1/install/system/kubernetes.md index 2fdf2bf161..5e65d1f24c 100644 --- a/docs/accessanalyzer/2601/install/system/kubernetes.md +++ b/docs/accessanalyzer/26.1/install/system/kubernetes.md @@ -33,7 +33,7 @@ The Access Analyzer installer installs and manages K3s automatically. The `kubec ## Kernel Features -The following kernel features must be available. The installer validates these automatically during installation (see [System Requirements](/docs/accessanalyzer/2601/install/system/requirements)): +The following kernel features must be available. The installer validates these automatically during installation (see [System Requirements](/docs/accessanalyzer/26_1/install/system/requirements)): | Feature | Description | | --- | --- | diff --git a/docs/accessanalyzer/2601/install/system/network.md b/docs/accessanalyzer/26.1/install/system/network.md similarity index 100% rename from docs/accessanalyzer/2601/install/system/network.md rename to docs/accessanalyzer/26.1/install/system/network.md diff --git a/docs/accessanalyzer/2601/install/system/requirements.md b/docs/accessanalyzer/26.1/install/system/requirements.md similarity index 100% rename from docs/accessanalyzer/2601/install/system/requirements.md rename to docs/accessanalyzer/26.1/install/system/requirements.md diff --git a/docs/accessanalyzer/2601/install/uninstall.md b/docs/accessanalyzer/26.1/install/uninstall.md similarity index 97% rename from docs/accessanalyzer/2601/install/uninstall.md rename to docs/accessanalyzer/26.1/install/uninstall.md index 2aa3fda5b5..cbb8564296 100644 --- a/docs/accessanalyzer/2601/install/uninstall.md +++ b/docs/accessanalyzer/26.1/install/uninstall.md @@ -49,4 +49,4 @@ The service should either not exist or show as inactive. ## Reinstallation -After uninstalling, you can reinstall Access Analyzer by running the installer again. See [Quick Install](/docs/accessanalyzer/2601/install/quickinstall). +After uninstalling, you can reinstall Access Analyzer by running the installer again. See [Quick Install](/docs/accessanalyzer/26_1/install/quickinstall). diff --git a/docs/accessanalyzer/2601/overview/keyconcepts.md b/docs/accessanalyzer/26.1/keyconcepts.md similarity index 97% rename from docs/accessanalyzer/2601/overview/keyconcepts.md rename to docs/accessanalyzer/26.1/keyconcepts.md index bf69b325be..3cc577efad 100644 --- a/docs/accessanalyzer/2601/overview/keyconcepts.md +++ b/docs/accessanalyzer/26.1/keyconcepts.md @@ -40,7 +40,7 @@ Access Analyzer has three roles: | **User Admin** | User and role management only — creates accounts, assigns roles, and pre-provisions federated users. Can't change system configuration. | | **Viewer** | Read-only access to data, reports, and dashboards. Can't make changes. | -For a full walkthrough of role assignment, see the [Quick Install — Roles](/docs/accessanalyzer/2601/install/quickinstall#roles) section. +For a full walkthrough of role assignment, see the [Quick Install — Roles](/docs/accessanalyzer/26_1/install/quickinstall#roles) section. ## Connectors @@ -59,7 +59,7 @@ Access Analyzer uses edge scanners for **Active Directory** and **File Server** You register edge scanners in **Configuration** > **Source Groups** > **Scanners** and associate them with a service account using **SSH Username / Key** credentials. Use scanner labels to route specific scan executions to dedicated scanner pools — for example, to isolate production scanning traffic from non-production environments. -For configuration details and best practices, see [Overview of Scanners](/docs/accessanalyzer/2601/configurations/source-groups/scanners/overview). +For configuration details and best practices, see [Overview of Scanners](/docs/accessanalyzer/26_1/configurations/source-groups/scanners/overview). ## Scans @@ -78,7 +78,7 @@ A **scan execution** is a single run of a scan — the record produced each time Each scan execution captures a status (such as running, completed, or failed), start and end times, duration, and result details. Execution history is visible in **Configuration** > **Source Groups** > **Scan Executions**. -For a full list of execution statuses and how they affect other operations, see [Scan Executions](/docs/accessanalyzer/2601/configurations/source-groups/scan-executions). +For a full list of execution statuses and how they affect other operations, see [Scan Executions](/docs/accessanalyzer/26_1/configurations/source-groups/scan-executions). ## Identities and Entitlements @@ -134,4 +134,4 @@ Access Analyzer organizes reports by source type and category: **My Reports** is a personal workspace for saving filtered report views. Apply filters to any report, save the configuration by name, and reload it later without reapplying filters manually. Saved reports are private to each user. -For the full list of available reports and descriptions, see [Dashboards and Reports](/docs/accessanalyzer/2601/dashboards-reports/reports). +For the full list of available reports and descriptions, see [Dashboards and Reports](/docs/accessanalyzer/26_1/dashboards-reports/reports). diff --git a/docs/accessanalyzer/2601/index.md b/docs/accessanalyzer/2601/index.md deleted file mode 100644 index 74e897b9fa..0000000000 --- a/docs/accessanalyzer/2601/index.md +++ /dev/null @@ -1,21 +0,0 @@ ---- -title: "Netwrix Access Analyzer Documentation" -description: "Netwrix Access Analyzer 1.0 product documentation - on-premises DSPM platform for data security and access analysis" -sidebar_position: 1 ---- - -# Netwrix Access Analyzer Documentation - -Netwrix Access Analyzer is an on-premises Data Security Posture Management (DSPM) platform that helps organizations discover, classify, and monitor sensitive data across enterprise file systems. Deployed entirely within your own infrastructure, it provides comprehensive visibility into data access patterns, identifies compliance risks, and enables data governance — without sending data to the cloud. - -## Key Capabilities - -- **Data Source Scanning** — Connect to CIFS/SMB file shares and other on-premises data repositories to discover and analyze data -- **Sensitive Data Discovery** — Detect sensitive data using built-in and custom regex patterns with taxonomy-based classification -- **Identity and Access Management** — Sync users and groups from Active Directory and Entra ID to analyze permission paths -- **Dashboards and Reporting** — Visualize security posture with built-in dashboards and embedded Metabase reports - -## Documentation Sections - -- [Overview](overview/overview.md) — Introduction to the product, key concepts, requirements, and installation -- [Getting Started](gettingstarted/active-directory/active-directory.md) — Step-by-step guides for your first scans and syncs diff --git a/docs/accessanalyzer/2601/overview/_category_.json b/docs/accessanalyzer/2601/overview/_category_.json deleted file mode 100644 index e030b69dcf..0000000000 --- a/docs/accessanalyzer/2601/overview/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Overview", - "position": 10, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/2601/overview/overview.md b/docs/accessanalyzer/2601/overview/overview.md deleted file mode 100644 index 536f4c6d05..0000000000 --- a/docs/accessanalyzer/2601/overview/overview.md +++ /dev/null @@ -1,131 +0,0 @@ ---- -title: "Overview" -description: "Product overview and architecture of Netwrix Access Analyzer" -sidebar_position: 10 ---- - -# Overview - -:::note Using an older version? -This documentation covers **Access Analyzer 2601**, the latest release — a containerized, Linux-based deployment. If you are running a previous Windows-based installation, select your version from the following list: - -- [Access Analyzer 12.0 documentation](https://docs.netwrix.com/docs/accessanalyzer/12_0) -- [Access Analyzer 11.6 documentation](https://docs.netwrix.com/docs/accessanalyzer/11_6) -::: - -## Product Overview - -Netwrix Access Analyzer is an on-premises Data Security Posture Management (DSPM) platform that helps security and compliance teams discover where sensitive data lives, who has access to it, and where access risks exist across their environment. - -Organizations face a persistent challenge: sensitive data accumulates across file servers, cloud platforms, and identity systems faster than security teams can track it. Permissions expand over time, inheritance breaks, and stale data sits untouched for years — all without anyone knowing. Access Analyzer addresses this by scanning your data sources and identity providers continuously, classifying what it finds, and surfacing the results in dashboards and reports your team can act on. - -Access Analyzer connects to the following source types: - -- **File servers** — Scans SMB/CIFS file shares for permissions, folder-level ACLs, file ownership, and sensitive data content -- **SharePoint Online** — Scans SharePoint sites for permissions, sharing links, and sensitive data across document libraries -- **Active Directory** — Syncs users, groups, group memberships, and security risks from on-premises AD domains -- **Entra ID** — Syncs users, groups, and roles from your Microsoft 365 tenant, and collects Microsoft Information Protection (MIP) sensitivity labels applied across the tenant - -After each scan, Access Analyzer stores results in a high-performance analytics database and makes them available through embedded Metabase dashboards and reports. Security teams can filter by domain, file server, site, or classification type, and drill into specific findings without writing queries. - -:::note -Scans are **read-only**. Access Analyzer doesn't modify files, permissions, or directory objects on any scanned source. Access Analyzer doesn't install persistent agents on file servers or domain controllers — edge scanners run as short-lived jobs and terminate after each scan. -::: - -## Key Capabilities - -| Capability | Description | -| --- | --- | -| **Sensitive Data Discovery** | Classifies file content across file servers and SharePoint Online against built-in detection patterns for PII, PHI, credentials, and financial data. Access Analyzer maps findings to compliance frameworks including GDPR, HIPAA, PCI DSS, and CCPA. | -| **Access Risk Analysis** | Identifies open access, overly permissive ACLs, broken permission inheritance, and stale entitlements across file shares and SharePoint sites. Shows effective permissions for any user or group. | -| **Identity Inventory** | Continuously syncs users, groups, memberships, and roles from Active Directory and Entra ID. Tracks group nesting, stale accounts, and role assignments across your identity providers. | -| **File Activity Monitoring** | Ingests real-time file system and SharePoint activity events from Netwrix Activity Monitor. Powers activity reports and enables anomaly detection and sensitive data activity tracking. Requires a separate Netwrix Activity Monitor deployment. | - -## Architecture Overview - -This section describes how Access Analyzer components are deployed and how data flows through the system. It is primarily intended for IT administrators and architects planning or troubleshooting a deployment. - -Access Analyzer runs entirely within your Kubernetes cluster. All components — the web application, API server, analytics database, and connector jobs — deploy to a single `access-analyzer` namespace. No data leaves your infrastructure. - -The platform uses a scan-as-job model: triggering a scan causes the Connector API to create an ephemeral Kubernetes Job for the connector type (CIFS, SharePoint, Active Directory, or Entra ID). The job runs, connects to the external source, collects data, and streams results to the data ingestion service, which bulk-inserts them into ClickHouse. When the job completes, it posts a webhook back to the Core API to finalize the scan execution record. - -```mermaid -graph TB - Browser(["Browser"]) - - subgraph K8s["Kubernetes — access-analyzer namespace"] - Webapp["Web App\n(React)"] - CoreAPI["Core API\n(Rails + Sidekiq)"] - ConnAPI["Connector API\n(Go)"] - DI["Data Ingestion\n(Python)"] - MB["Metabase\n(Embedded Analytics)"] - - Redis[("Redis\nJob queue")] - PG[("PostgreSQL\nApp data")] - CH[("ClickHouse\nScan results")] - - subgraph Jobs["Connector Jobs — ephemeral Kubernetes Jobs"] - J1["CIFS Connector"] - J2["SharePoint Connector"] - J3["Active Directory Connector"] - J4["Entra ID Connector"] - end - end - - subgraph Ext["External Sources"] - FS["File Servers\nSMB · port 445"] - SP["SharePoint Online\nHTTPS · port 443"] - AD["Active Directory\nLDAP · port 389"] - EID["Entra ID\nHTTPS · port 443"] - end - - Browser -->|HTTPS| Webapp - Webapp -->|REST API| CoreAPI - Webapp -->|Embedded SDK + JWT SSO| MB - CoreAPI --> PG - CoreAPI --> Redis - CoreAPI -->|HTTP| ConnAPI - ConnAPI -->|Kubernetes Job API| Jobs - J1 -->|SMB| FS - J2 -->|Graph API| SP - J3 -->|LDAP| AD - J4 -->|Graph API| EID - J1 --> DI - J2 --> DI - J3 --> DI - J4 --> DI - DI -->|Bulk insert| CH - MB -->|JDBC| PG - MB -->|JDBC| CH -``` - -### Components - -**Web App** — React single-page application served from the cluster. Handles scan management, source configuration, results browsing, and embeds Metabase dashboards via the Metabase SDK using JWT-based single sign-on. - -**Core API** — Rails 8 application that exposes the REST API used by the web app. Manages application state in PostgreSQL, queues background jobs through Sidekiq and Redis, and coordinates scan execution by delegating to the Connector API. - -**Connector API** — Go service that translates scan requests from the Core API into Kubernetes Job definitions. It creates connector Jobs, monitors their completion, and posts results back to the Core API via webhook. - -**Connector Jobs** — Ephemeral Kubernetes Jobs that perform the scan work. Each connector type (CIFS, SharePoint, Active Directory, Entra ID) is a containerized Python handler. Jobs connect directly to their target source, collect data, and stream rows to the Data Ingestion service in batches. The Connector API creates Jobs on demand and cleans them up after completion. - -**Data Ingestion** — Python service that receives batched rows from connector jobs and bulk-inserts them into ClickHouse. Provides write isolation — connectors never write to ClickHouse directly. - -**Metabase** — Embedded analytics platform pre-configured with Access Analyzer dashboards and reports. Connects to both PostgreSQL and ClickHouse via JDBC. Users access Metabase through the web app and don't need a separate login. - -### Data Stores - -| Store | Purpose | -|-------|---------| -| **PostgreSQL** | Application data: users, sources, scans, scan executions, service accounts, configuration | -| **ClickHouse** | Scan results: file objects, permissions, ACLs, group memberships, sensitive data findings | -| **Redis** | Sidekiq job queue and session cache for the Core API | - -## Next Steps - -| | | -| --- | --- | -| **New to Access Analyzer?** | Read [Key Concepts](/docs/accessanalyzer/2601/overview/keyconcepts) to learn the terminology used throughout the product and documentation. | -| **Ready to install?** | Follow the [Quick Install](/docs/accessanalyzer/2601/install/quickinstall) guide for an end-to-end deployment walkthrough. | -| **Planning your deployment?** | Review [Hardware and System Requirements](/docs/accessanalyzer/2601/install/system/requirements) and [Network and Port Requirements](/docs/accessanalyzer/2601/install/system/network) before provisioning your server. | -| **Connecting your first source?** | Go to **Configuration** > **Source Groups** in the application and use the Connect Source wizard. | diff --git a/docs/activitymonitor/10.0/admin/monitoredhosts/output/output.md b/docs/activitymonitor/10.0/admin/monitoredhosts/output/output.md index ac7032bae0..d941f7f515 100644 --- a/docs/activitymonitor/10.0/admin/monitoredhosts/output/output.md +++ b/docs/activitymonitor/10.0/admin/monitoredhosts/output/output.md @@ -44,7 +44,7 @@ Tokens expire after **1 hour**. Generating a new token immediately invalidates a A single token can enroll multiple agents and outputs simultaneously — plan your enrollment session and generate the token immediately before you begin. ::: -See the [Netwrix Access Analyzer 26 Documentation](/docs/accessanalyzer/2601/configurations/activity-monitor-integration) for +See the [Netwrix Access Analyzer 26 Documentation](/docs/accessanalyzer/26_1/integrations/netwrix-activity-monitor) for additional information. ### Add the Output in Netwrix Activity Monitor diff --git a/docs/activitymonitor/10.0/admin/outputs/accessanalyzer26.md b/docs/activitymonitor/10.0/admin/outputs/accessanalyzer26.md index 4fad8b8b6e..4d319082a5 100644 --- a/docs/activitymonitor/10.0/admin/outputs/accessanalyzer26.md +++ b/docs/activitymonitor/10.0/admin/outputs/accessanalyzer26.md @@ -44,4 +44,4 @@ Tokens expire after **1 hour**. Generating a new token immediately invalidates a A single token can enroll multiple agents and outputs simultaneously — plan your enrollment session and generate the token immediately before you begin. ::: -See the [Netwrix Access Analyzer 26 Documentation](/docs/accessanalyzer/2601/configurations/activity-monitor-integration) for additional information. +See the [Netwrix Access Analyzer 26 Documentation](/docs/accessanalyzer/26_1/integrations/netwrix-activity-monitor) for additional information. diff --git a/docs/activitymonitor/10.0/install/overview.md b/docs/activitymonitor/10.0/install/overview.md index 3e3599db39..1fb4a883d4 100644 --- a/docs/activitymonitor/10.0/install/overview.md +++ b/docs/activitymonitor/10.0/install/overview.md @@ -18,7 +18,7 @@ the versions to be compatible. | Component | Version | | ----------------------------------------------------- | ------- | | Netwrix Activity Monitor | 10.0.x | -| Netwrix Access Analyzer | 12.0.x or 2601 | +| Netwrix Access Analyzer | 12.0.x or 26.1 | | Netwrix Threat Prevention | 8.0.x | | Netwrix Threat Manager | 3.0.x | diff --git a/docs/kb/accessanalyzer-2601/_category_.json b/docs/kb/accessanalyzer-26.1/_category_.json similarity index 100% rename from docs/kb/accessanalyzer-2601/_category_.json rename to docs/kb/accessanalyzer-26.1/_category_.json diff --git a/docs/kb/accessanalyzer-2601/index.md b/docs/kb/accessanalyzer-26.1/index.md similarity index 83% rename from docs/kb/accessanalyzer-2601/index.md rename to docs/kb/accessanalyzer-26.1/index.md index 0574c80c1d..ec7eebed34 100644 --- a/docs/kb/accessanalyzer-2601/index.md +++ b/docs/kb/accessanalyzer-26.1/index.md @@ -1,12 +1,12 @@ --- title: "Access Analyzer Knowledge Base" -description: "Access Analyzer v2601 knowledge base articles and troubleshooting guides" -slug: accessanalyzer-2601 +description: "Access Analyzer v26.1 knowledge base articles and troubleshooting guides" +slug: accessanalyzer-26.1 --- # Access Analyzer Knowledge Base -Welcome to the Access Analyzer knowledge base. Browse troubleshooting guides, configuration instructions, and best practices for Access Analyzer v2601. +Welcome to the Access Analyzer knowledge base. Browse troubleshooting guides, configuration instructions, and best practices for Access Analyzer v26.1. Use the search function above to find specific articles or browse through all Access Analyzer KB articles in this section. diff --git a/docs/kb/accessanalyzer-2601/kb-article-template.md b/docs/kb/accessanalyzer-26.1/kb-article-template.md similarity index 98% rename from docs/kb/accessanalyzer-2601/kb-article-template.md rename to docs/kb/accessanalyzer-26.1/kb-article-template.md index 5f568715d6..b9ce7f9e01 100644 --- a/docs/kb/accessanalyzer-2601/kb-article-template.md +++ b/docs/kb/accessanalyzer-26.1/kb-article-template.md @@ -24,7 +24,7 @@ knowledge_article_id: kA0Qk000000XXXXKAA # KB Article Template and Style Guide -This file is a placeholder and authoring guide for Access Analyzer v2601 knowledge base articles. Copy this file, rename it, and replace the placeholder content with the actual article. Remove this introduction paragraph before publishing. +This file is a placeholder and authoring guide for Access Analyzer v26.1 knowledge base articles. Copy this file, rename it, and replace the placeholder content with the actual article. Remove this introduction paragraph before publishing. --- @@ -104,7 +104,7 @@ If multiple resolutions exist, use ### subheadings for each. ## Related Links -- [Netwrix Access Analyzer Documentation — System Requirements](/docs/accessanalyzer/2601/install/system/requirements) +- [Netwrix Access Analyzer Documentation — System Requirements](/docs/accessanalyzer/26_1/install/system/requirements) - [Link text describing destination — add a line for each relevant resource](#) --- diff --git a/docs/kb/accessanalyzer-2601/migration/_category_.json b/docs/kb/accessanalyzer-26.1/migration/_category_.json similarity index 100% rename from docs/kb/accessanalyzer-2601/migration/_category_.json rename to docs/kb/accessanalyzer-26.1/migration/_category_.json diff --git a/docs/kb/accessanalyzer-2601/migration/audit-data-strategy.md b/docs/kb/accessanalyzer-26.1/migration/audit-data-strategy.md similarity index 100% rename from docs/kb/accessanalyzer-2601/migration/audit-data-strategy.md rename to docs/kb/accessanalyzer-26.1/migration/audit-data-strategy.md diff --git a/docs/kb/accessanalyzer-2601/migration/index.md b/docs/kb/accessanalyzer-26.1/migration/index.md similarity index 100% rename from docs/kb/accessanalyzer-2601/migration/index.md rename to docs/kb/accessanalyzer-26.1/migration/index.md diff --git a/docs/kb/accessanalyzer-2601/migration/migrate-credentials.md b/docs/kb/accessanalyzer-26.1/migration/migrate-credentials.md similarity index 100% rename from docs/kb/accessanalyzer-2601/migration/migrate-credentials.md rename to docs/kb/accessanalyzer-26.1/migration/migrate-credentials.md diff --git a/docs/kb/accessanalyzer-2601/migration/migrate-job-configurations.md b/docs/kb/accessanalyzer-26.1/migration/migrate-job-configurations.md similarity index 97% rename from docs/kb/accessanalyzer-2601/migration/migrate-job-configurations.md rename to docs/kb/accessanalyzer-26.1/migration/migrate-job-configurations.md index c7d5162733..a800c44989 100644 --- a/docs/kb/accessanalyzer-2601/migration/migrate-job-configurations.md +++ b/docs/kb/accessanalyzer-26.1/migration/migrate-job-configurations.md @@ -56,7 +56,7 @@ Each legacy data collector maps to a specific AA26 scan type: Navigate to **Configuration** > **Scans** to view and configure all scans across your sources. -![Scans list showing existing scans with columns for Name, Scan Type, Source, Source Group, Source Type, Schedule, Scanner, and Actions](/images/accessanalyzer/2601/migration/scans-list.png) +![Scans list showing existing scans with columns for Name, Scan Type, Source, Source Group, Source Type, Schedule, Scanner, and Actions](/images/accessanalyzer/26.1/migration/scans-list.png) Each row shows a scan's type, source, schedule, and assigned scanner. Click the scan name to open the edit panel for that scan. @@ -66,7 +66,7 @@ Each row shows a scan's type, source, schedule, and assigned scanner. Click the The Access Scan collects file permissions, share structure, and file metadata from file servers. -![Edit Scan panel for a File Server access scan showing Basic Information, Scan Configuration, and Schedule sections](/images/accessanalyzer/2601/migration/scan-edit-file-server-access.png) +![Edit Scan panel for a File Server access scan showing Basic Information, Scan Configuration, and Schedule sections](/images/accessanalyzer/26.1/migration/scan-edit-file-server-access.png) | AA26 Parameter | Description | Legacy Equivalent | | --- | --- | --- | @@ -83,7 +83,7 @@ The Access Scan has no additional scoping parameters. It scans all accessible sh The Sensitive Data Scan classifies file contents against configured data type patterns. It must be run after the Access Scan — the scan uses the share list discovered by the Access Scan to determine scope. -![Edit Scan panel for a File Server sensitive data scan showing Scan Type, Configuration Source, and Processing Options sections](/images/accessanalyzer/2601/migration/scan-edit-file-server-sdd.png) +![Edit Scan panel for a File Server sensitive data scan showing Scan Type, Configuration Source, and Processing Options sections](/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd.png) | AA26 Parameter | Description | Legacy Equivalent | | --- | --- | --- | @@ -108,7 +108,7 @@ The Share Selection list is populated from the results of the Access Scan. If no The Identity Sync collects users, groups, group membership, and custom attributes from Active Directory domain controllers. -![Edit Scan panel for an Active Directory identity sync showing Identity Source, connection override settings, and Schedule](/images/accessanalyzer/2601/migration/scan-edit-ad.png) +![Edit Scan panel for an Active Directory identity sync showing Identity Source, connection override settings, and Schedule](/images/accessanalyzer/26.1/migration/scan-edit-ad.png) | AA26 Parameter | Description | Legacy Equivalent | | --- | --- | --- | @@ -129,7 +129,7 @@ AA26 collects standard Active Directory attributes: users, groups, group members The Identity Sync collects users, groups, and roles from Entra ID via the Microsoft Graph API. -![Edit Scan panel for an Entra ID identity sync showing Identity Source, connection override settings, and Schedule](/images/accessanalyzer/2601/migration/scan-edit-entra-id.png) +![Edit Scan panel for an Entra ID identity sync showing Identity Source, connection override settings, and Schedule](/images/accessanalyzer/26.1/migration/scan-edit-entra-id.png) | AA26 Parameter | Description | Legacy Equivalent | | --- | --- | --- | diff --git a/docs/kb/accessanalyzer-2601/migration/migrate-proxy-servers.md b/docs/kb/accessanalyzer-26.1/migration/migrate-proxy-servers.md similarity index 98% rename from docs/kb/accessanalyzer-2601/migration/migrate-proxy-servers.md rename to docs/kb/accessanalyzer-26.1/migration/migrate-proxy-servers.md index 6e85501f61..52302cf9f6 100644 --- a/docs/kb/accessanalyzer-2601/migration/migrate-proxy-servers.md +++ b/docs/kb/accessanalyzer-26.1/migration/migrate-proxy-servers.md @@ -78,13 +78,13 @@ This inventory determines how many scanner nodes you need and how to label them. Navigate to **Configuration** > **Scanners** in Access Analyzer 26. -![Scanners list showing the Default Scanner with columns for Name/IP, Labels, Source Groups, Health Status, and Last Heartbeat](/images/accessanalyzer/2601/migration/scanners-list.png) +![Scanners list showing the Default Scanner with columns for Name/IP, Labels, Source Groups, Health Status, and Last Heartbeat](/images/accessanalyzer/26.1/migration/scanners-list.png) The list shows all registered scanner nodes. The **Default Scanner** is always present and represents local scanning from the AA26 server. Click **Deploy Scanner** to register a new scanner node. -![Deploy Scanner form showing fields for Name, SSH Host, SSH Host Key, SSH Port, Service Account, and Labels](/images/accessanalyzer/2601/migration/scanner-deploy-form.png) +![Deploy Scanner form showing fields for Name, SSH Host, SSH Host Key, SSH Port, Service Account, and Labels](/images/accessanalyzer/26.1/migration/scanner-deploy-form.png) Complete the form for each scanner node you are deploying: diff --git a/docs/kb/accessanalyzer-2601/migration/migrate-schedules.md b/docs/kb/accessanalyzer-26.1/migration/migrate-schedules.md similarity index 98% rename from docs/kb/accessanalyzer-2601/migration/migrate-schedules.md rename to docs/kb/accessanalyzer-26.1/migration/migrate-schedules.md index 947dde6d0f..d19d603658 100644 --- a/docs/kb/accessanalyzer-2601/migration/migrate-schedules.md +++ b/docs/kb/accessanalyzer-26.1/migration/migrate-schedules.md @@ -96,7 +96,7 @@ AA26 stores cron schedules in UTC. If your legacy jobs used local time triggers, Scan schedules are configured on source groups. Navigate to **Configuration** > **Source Groups**, then edit the group or configure schedules during source group creation. -![Source group creation wizard step 3 showing scan type selection and cron schedule configuration fields](/images/accessanalyzer/2601/migration/create-source-group-scan-config.png) +![Source group creation wizard step 3 showing scan type selection and cron schedule configuration fields](/images/accessanalyzer/26.1/migration/create-source-group-scan-config.png) For each source group: diff --git a/docs/kb/accessanalyzer-2601/migration/migrate-target-servers.md b/docs/kb/accessanalyzer-26.1/migration/migrate-target-servers.md similarity index 96% rename from docs/kb/accessanalyzer-2601/migration/migrate-target-servers.md rename to docs/kb/accessanalyzer-26.1/migration/migrate-target-servers.md index 906198b586..7020a118d6 100644 --- a/docs/kb/accessanalyzer-2601/migration/migrate-target-servers.md +++ b/docs/kb/accessanalyzer-26.1/migration/migrate-target-servers.md @@ -85,7 +85,7 @@ Export a complete inventory of your legacy host lists and hosts before making an Navigate to **Configuration** > **Source Groups**. -![Source Groups list showing existing groups with source type, service account, scan type, and status columns](/images/accessanalyzer/2601/migration/source-groups-list.png) +![Source Groups list showing existing groups with source type, service account, scan type, and status columns](/images/accessanalyzer/26.1/migration/source-groups-list.png) Create one source group for each connector type across your legacy host lists. Click **Create Source Group** to open the wizard. @@ -93,13 +93,13 @@ Create one source group for each connector type across your legacy host lists. C The wizard first asks you to choose a connector type. -![Source group creation wizard step 1 showing four source type options: Active Directory, Entra ID, File Server, and SharePoint Online](/images/accessanalyzer/2601/migration/create-source-group-type-select.png) +![Source group creation wizard step 1 showing four source type options: Active Directory, Entra ID, File Server, and SharePoint Online](/images/accessanalyzer/26.1/migration/create-source-group-type-select.png) Select the connector type that matches the hosts you are migrating. If you have hosts of multiple types from the same legacy host list, you'll repeat this process for each type. ### Step 2 of 3 — Configure the group -![Source group creation wizard step 2 showing name field, service account selection, and max concurrent scans setting for a File Server group](/images/accessanalyzer/2601/migration/create-source-group-file-server.png) +![Source group creation wizard step 2 showing name field, service account selection, and max concurrent scans setting for a File Server group](/images/accessanalyzer/26.1/migration/create-source-group-file-server.png) | Field | What to enter | | --- | --- | @@ -114,7 +114,7 @@ Add sources to the group: ### Step 3 of 3 — Configure scan parameters -![Source group creation wizard step 3 showing scan type selection and schedule configuration fields](/images/accessanalyzer/2601/migration/create-source-group-scan-config.png) +![Source group creation wizard step 3 showing scan type selection and schedule configuration fields](/images/accessanalyzer/26.1/migration/create-source-group-scan-config.png) Select the scan types to enable. Configure the scan schedule using a cron expression. See [Migrating Job Schedules](./migrate-schedules.md) for guidance on translating legacy schedule triggers to cron expressions. diff --git a/docs/kb/accessanalyzer-2601/migration/migration-checklist.md b/docs/kb/accessanalyzer-26.1/migration/migration-checklist.md similarity index 100% rename from docs/kb/accessanalyzer-2601/migration/migration-checklist.md rename to docs/kb/accessanalyzer-26.1/migration/migration-checklist.md diff --git a/docs/kb/accessanalyzer-2601/updating-to-the-latest-version.md b/docs/kb/accessanalyzer-26.1/updating-to-the-latest-version.md similarity index 92% rename from docs/kb/accessanalyzer-2601/updating-to-the-latest-version.md rename to docs/kb/accessanalyzer-26.1/updating-to-the-latest-version.md index ed5c1ac2d3..645ec83e6a 100644 --- a/docs/kb/accessanalyzer-2601/updating-to-the-latest-version.md +++ b/docs/kb/accessanalyzer-26.1/updating-to-the-latest-version.md @@ -1,10 +1,10 @@ --- title: "Updating to the Latest Version" description: >- - How to verify your current version of Netwrix Access Analyzer 2601 and update to the latest release. Applies to both auto-update and targeted version installations. + How to verify your current version of Netwrix Access Analyzer 26.1 and update to the latest release. Applies to both auto-update and targeted version installations. sidebar_label: "Updating to the Latest Version" keywords: - - access analyzer 2601 + - access analyzer 26.1 - upgrade access analyzer - dspmctl version - dspmctl set-revision @@ -25,12 +25,12 @@ knowledge_article_id: kA0Qk000000XXXXKAA ## Overview -ArgoCD deploys Netwrix Access Analyzer 2601, and you update it using the `dspmctl` command-line tool over an SSH connection to the host server. How you update Access Analyzer depends on how it was originally installed: +ArgoCD deploys Netwrix Access Analyzer 26.1, and you update it using the `dspmctl` command-line tool over an SSH connection to the host server. How you update Access Analyzer depends on how it was originally installed: - **Auto-update installation** — ArgoCD automatically applies new releases as they become available. You do not need to perform any manual update steps; you only need to verify that ArgoCD applied the update. - **Targeted version installation** — The original installation pinned a specific version. You must manually set the new target version and trigger a sync. -If you are not sure which installation type applies to your environment, run `sudo dspmctl version` and compare the output to the latest announced release. If they match, the application is already current. For system requirements, see [System Requirements](/docs/accessanalyzer/2601/install/system/requirements). +If you are not sure which installation type applies to your environment, run `sudo dspmctl version` and compare the output to the latest announced release. If they match, the application is already current. For system requirements, see [System Requirements](/docs/accessanalyzer/26_1/install/system/requirements). ## Instructions diff --git a/sidebars/accessanalyzer/2601.js b/sidebars/accessanalyzer/26.1.js similarity index 100% rename from sidebars/accessanalyzer/2601.js rename to sidebars/accessanalyzer/26.1.js diff --git a/src/config/products.js b/src/config/products.js index 54771a050d..c66393c8d6 100644 --- a/src/config/products.js +++ b/src/config/products.js @@ -62,11 +62,11 @@ export const PRODUCTS = [ icon: '', versions: [ { - version: '2601', - label: '2601', + version: '26.1', + label: '26.1', isLatest: true, - sidebarFile: './sidebars/accessanalyzer/2601.js', - kbSource: 'docs/kb/accessanalyzer-2601', + sidebarFile: './sidebars/accessanalyzer/26.1.js', + kbSource: 'docs/kb/accessanalyzer-26.1', }, { version: '12.0', @@ -81,7 +81,7 @@ export const PRODUCTS = [ sidebarFile: './sidebars/accessanalyzer/11.6.js', }, ], - defaultVersion: '2601', + defaultVersion: '26.1', }, { id: 'accessinformationcenter', diff --git a/src/theme/searchUtils.js b/src/theme/searchUtils.js index 2db2415982..b15fdc60ee 100644 --- a/src/theme/searchUtils.js +++ b/src/theme/searchUtils.js @@ -37,8 +37,8 @@ export function versionLabel(version) { // A version-pinned KB source (kbSource override) publishes under its directory // basename instead of the product id — both as the standalone route segment and as -// the copied landing page's slug (docs/kb/accessanalyzer-2601/index.md pins -// slug: accessanalyzer-2601 while the default source pins slug: accessanalyzer). +// the copied landing page's slug (docs/kb/accessanalyzer-26.1/index.md pins +// slug: accessanalyzer-26.1 while the default source pins slug: accessanalyzer). // basename -> product id, so every shape of one article normalizes to one key. const PINNED_KB_SOURCES = new Map(); PRODUCTS.forEach(p => (p.versions || []).forEach(v => { diff --git a/static/images/accessanalyzer/2601/configurations/add-service-account-certificate.png b/static/images/accessanalyzer/26.1/configurations/add-service-account-certificate.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/add-service-account-certificate.png rename to static/images/accessanalyzer/26.1/configurations/add-service-account-certificate.png diff --git a/static/images/accessanalyzer/2601/configurations/add-service-account-client-secret.png b/static/images/accessanalyzer/26.1/configurations/add-service-account-client-secret.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/add-service-account-client-secret.png rename to static/images/accessanalyzer/26.1/configurations/add-service-account-client-secret.png diff --git a/static/images/accessanalyzer/2601/configurations/add-service-account-form.png b/static/images/accessanalyzer/26.1/configurations/add-service-account-form.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/add-service-account-form.png rename to static/images/accessanalyzer/26.1/configurations/add-service-account-form.png diff --git a/static/images/accessanalyzer/2601/configurations/add-service-account-ssh.png b/static/images/accessanalyzer/26.1/configurations/add-service-account-ssh.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/add-service-account-ssh.png rename to static/images/accessanalyzer/26.1/configurations/add-service-account-ssh.png diff --git a/static/images/accessanalyzer/2601/configurations/add-service-account-username-password.png b/static/images/accessanalyzer/26.1/configurations/add-service-account-username-password.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/add-service-account-username-password.png rename to static/images/accessanalyzer/26.1/configurations/add-service-account-username-password.png diff --git a/static/images/accessanalyzer/2601/configurations/scanner-deploy-form.png b/static/images/accessanalyzer/26.1/configurations/scanner-deploy-form.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/scanner-deploy-form.png rename to static/images/accessanalyzer/26.1/configurations/scanner-deploy-form.png diff --git a/static/images/accessanalyzer/2601/configurations/scanners-list.png b/static/images/accessanalyzer/26.1/configurations/scanners-list.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/scanners-list.png rename to static/images/accessanalyzer/26.1/configurations/scanners-list.png diff --git a/static/images/accessanalyzer/2601/configurations/service-accounts-list.png b/static/images/accessanalyzer/26.1/configurations/service-accounts-list.png similarity index 100% rename from static/images/accessanalyzer/2601/configurations/service-accounts-list.png rename to static/images/accessanalyzer/26.1/configurations/service-accounts-list.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-certificate.png b/static/images/accessanalyzer/26.1/migration/add-service-account-certificate.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-certificate.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-certificate.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-client-secret.png b/static/images/accessanalyzer/26.1/migration/add-service-account-client-secret.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-client-secret.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-client-secret.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-form.png b/static/images/accessanalyzer/26.1/migration/add-service-account-form.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-form.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-form.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-initial.png b/static/images/accessanalyzer/26.1/migration/add-service-account-initial.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-initial.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-initial.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-type-dropdown-open.png b/static/images/accessanalyzer/26.1/migration/add-service-account-type-dropdown-open.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-type-dropdown-open.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-type-dropdown-open.png diff --git a/static/images/accessanalyzer/2601/migration/add-service-account-username-password.png b/static/images/accessanalyzer/26.1/migration/add-service-account-username-password.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/add-service-account-username-password.png rename to static/images/accessanalyzer/26.1/migration/add-service-account-username-password.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-ad-scan-config.png b/static/images/accessanalyzer/26.1/migration/create-source-group-ad-scan-config.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-ad-scan-config.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-ad-scan-config.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-ad-step4.png b/static/images/accessanalyzer/26.1/migration/create-source-group-ad-step4.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-ad-step4.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-ad-step4.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-ad.png b/static/images/accessanalyzer/26.1/migration/create-source-group-ad.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-ad.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-ad.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-configure.png b/static/images/accessanalyzer/26.1/migration/create-source-group-configure.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-configure.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-configure.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-entra-id-scan-config.png b/static/images/accessanalyzer/26.1/migration/create-source-group-entra-id-scan-config.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-entra-id-scan-config.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-entra-id-scan-config.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-entra-id.png b/static/images/accessanalyzer/26.1/migration/create-source-group-entra-id.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-entra-id.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-entra-id.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-file-server-scan-config.png b/static/images/accessanalyzer/26.1/migration/create-source-group-file-server-scan-config.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-file-server-scan-config.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-file-server-scan-config.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-file-server-setup.png b/static/images/accessanalyzer/26.1/migration/create-source-group-file-server-setup.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-file-server-setup.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-file-server-setup.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-file-server-step2.png b/static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step2.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-file-server-step2.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step2.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-file-server-step4.png b/static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step4.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-file-server-step4.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step4.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-file-server.png b/static/images/accessanalyzer/26.1/migration/create-source-group-file-server.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-file-server.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-file-server.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-filled.png b/static/images/accessanalyzer/26.1/migration/create-source-group-filled.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-filled.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-filled.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-scan-config.png b/static/images/accessanalyzer/26.1/migration/create-source-group-scan-config.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-scan-config.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-scan-config.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-sharepoint-scan-config.png b/static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint-scan-config.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-sharepoint-scan-config.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint-scan-config.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-sharepoint.png b/static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-sharepoint.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-step1.png b/static/images/accessanalyzer/26.1/migration/create-source-group-step1.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-step1.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-step1.png diff --git a/static/images/accessanalyzer/2601/migration/create-source-group-type-select.png b/static/images/accessanalyzer/26.1/migration/create-source-group-type-select.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/create-source-group-type-select.png rename to static/images/accessanalyzer/26.1/migration/create-source-group-type-select.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-ad-scrolled.png b/static/images/accessanalyzer/26.1/migration/scan-edit-ad-scrolled.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-ad-scrolled.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-ad-scrolled.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-ad.png b/static/images/accessanalyzer/26.1/migration/scan-edit-ad.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-ad.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-ad.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-entra-id-scrolled.png b/static/images/accessanalyzer/26.1/migration/scan-edit-entra-id-scrolled.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-entra-id-scrolled.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-entra-id-scrolled.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-entra-id.png b/static/images/accessanalyzer/26.1/migration/scan-edit-entra-id.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-entra-id.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-entra-id.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-file-server-access-scrolled.png b/static/images/accessanalyzer/26.1/migration/scan-edit-file-server-access-scrolled.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-file-server-access-scrolled.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-file-server-access-scrolled.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-file-server-access.png b/static/images/accessanalyzer/26.1/migration/scan-edit-file-server-access.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-file-server-access.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-file-server-access.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-file-server-sdd-scrolled.png b/static/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd-scrolled.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-file-server-sdd-scrolled.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd-scrolled.png diff --git a/static/images/accessanalyzer/2601/migration/scan-edit-file-server-sdd.png b/static/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scan-edit-file-server-sdd.png rename to static/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd.png diff --git a/static/images/accessanalyzer/2601/migration/scanner-deploy-form.png b/static/images/accessanalyzer/26.1/migration/scanner-deploy-form.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scanner-deploy-form.png rename to static/images/accessanalyzer/26.1/migration/scanner-deploy-form.png diff --git a/static/images/accessanalyzer/2601/migration/scanners-list.png b/static/images/accessanalyzer/26.1/migration/scanners-list.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scanners-list.png rename to static/images/accessanalyzer/26.1/migration/scanners-list.png diff --git a/static/images/accessanalyzer/2601/migration/scans-list.png b/static/images/accessanalyzer/26.1/migration/scans-list.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/scans-list.png rename to static/images/accessanalyzer/26.1/migration/scans-list.png diff --git a/static/images/accessanalyzer/2601/migration/service-accounts-list.png b/static/images/accessanalyzer/26.1/migration/service-accounts-list.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/service-accounts-list.png rename to static/images/accessanalyzer/26.1/migration/service-accounts-list.png diff --git a/static/images/accessanalyzer/2601/migration/source-groups-list.png b/static/images/accessanalyzer/26.1/migration/source-groups-list.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/source-groups-list.png rename to static/images/accessanalyzer/26.1/migration/source-groups-list.png diff --git a/static/images/accessanalyzer/2601/migration/type-dropdown-open.png b/static/images/accessanalyzer/26.1/migration/type-dropdown-open.png similarity index 100% rename from static/images/accessanalyzer/2601/migration/type-dropdown-open.png rename to static/images/accessanalyzer/26.1/migration/type-dropdown-open.png From 49feb680c9b8120f31a902d770c0cfb779f2e920 Mon Sep 17 00:00:00 2001 From: Jordan Violet <8886650+jtviolet@users.noreply.github.com> Date: Mon, 7 Sep 2026 10:40:50 -0400 Subject: [PATCH 2/6] docs(accessanalyzer): rewrite the 26.1 documentation against the shipping product Replace the 26.1 tree with 52 pages organized by task: overview, installation, per-source guides, sources, service accounts, agents, scans, sensitive data patterns, dashboards and reports, settings, and integrations. Autogenerated sidebar with _category_.json per section; the Dashboards and Reports groups use generated indexes slugged into the tree. 90 screenshots from a 26.1 build. Add an installer reference for dspm-installer (flags, config file, preflight checks, exit codes, wait-for-apps) and a Netwrix Activity Monitor integration page cross-linked to the Activity Monitor 10.0 output docs. Redirect every page that lived under the old 2601 folder, and its unversioned form, to its replacement (src/config/redirects/accessanalyzer-26.1.js) so the product's in-app help links and existing bookmarks keep resolving. Repoint two KB articles from the removed install/system/requirements page to install/requirements; the KB content is otherwise untouched. Generated with AI Co-Authored-By: Claude Code --- .../_category_.json | 2 +- .../26.1/agents/agent-labels.md | 99 ++++ .../26.1/agents/deploy-agent.md | 136 +++++ docs/accessanalyzer/26.1/agents/index.md | 66 +++ .../activity-monitor-integration.md | 311 ---------- .../configurations/application-settings.md | 106 ---- .../26.1/configurations/identity-provider.md | 137 ----- .../26.1/configurations/logs.md | 108 ---- .../26.1/configurations/sensitive-data.md | 154 ----- .../service-accounts/_category_.json | 6 - .../service-accounts/client-id-certificate.md | 40 -- .../service-accounts/client-id-secret.md | 34 -- .../service-accounts/overview.md | 36 -- .../service-accounts/ssh-username-key.md | 30 - .../service-accounts/username-password.md | 42 -- .../source-groups/_category_.json | 6 - .../source-groups/scan-executions.md | 49 -- .../source-groups/scanners/best-practices.md | 100 ---- .../source-groups/scanners/deploy-scanner.md | 77 --- .../source-groups/scanners/manage-scanners.md | 66 --- .../source-groups/scanners/overview.md | 65 -- .../source-groups/scanners/requirements.md | 77 --- .../configurations/source-groups/scans.md | 108 ---- .../source-groups/source-groups.md | 100 ---- .../26.1/configurations/users.md | 176 ------ .../26.1/connectors/_category_.json | 6 - .../26.1/connectors/activedirectory.md | 48 -- .../entra-id/app-registration-secret.md | 54 -- .../connectors/entra-id/entra-requirements.md | 66 --- .../26.1/connectors/entra-id/overview.md | 38 -- .../26.1/connectors/file-servers/celerra.md | 36 -- .../26.1/connectors/file-servers/cifs.md | 41 -- .../connectors/file-servers/dell-unity.md | 36 -- .../file-servers/isilon-powerscale.md | 36 -- .../26.1/connectors/file-servers/netapp.md | 41 -- .../26.1/connectors/file-servers/vnx.md | 39 -- .../sharepoint-online/_category_.json | 10 - .../sharepoint-online/azure-permissions.md | 64 -- .../connectors/sharepoint-online/overview.md | 35 -- .../tenant-certificate-config.md | 33 -- .../26.1/dashboards-reports/_category_.json | 4 +- .../dashboards/_category_.json | 11 + .../dashboards/active-directory.md | 88 +++ .../dashboards/data-security.md | 67 +++ .../26.1/dashboards-reports/index.md | 56 ++ .../26.1/dashboards-reports/my-reports.md | 83 --- .../26.1/dashboards-reports/reports.md | 76 --- .../reports/_category_.json | 11 + .../dashboards-reports/reports/compliance.md | 59 ++ .../26.1/dashboards-reports/reports/data.md | 343 +++++++++++ .../dashboards-reports/reports/identity.md | 77 +++ .../26.1/gettingstarted/_category_.json | 6 - .../active-directory/_category_.json | 6 - .../active-directory/active-directory.md | 34 -- .../active-directory/reports.md | 49 -- .../active-directory/scanning-options.md | 11 - .../active-directory/schema-reference.md | 273 --------- .../active-directory/set-up-source-group.md | 41 -- .../26.1/gettingstarted/entra-id/entra-id.md | 38 -- .../26.1/gettingstarted/entra-id/reports.md | 42 -- .../entra-id/scanning-options.md | 17 - .../entra-id/schema-reference.md | 122 ---- .../entra-id/set-up-source-group.md | 43 -- .../file-servers/_category_.json | 6 - .../file-servers/file-servers.md | 50 -- .../gettingstarted/file-servers/reports.md | 35 -- .../file-servers/scanning-options.md | 29 - .../file-servers/schema-reference.md | 201 ------- .../file-servers/set-up-source-group.md | 52 -- .../sharepoint-online/reports.md | 17 - .../sharepoint-online/scanning-options.md | 28 - .../sharepoint-online/schema-reference.md | 166 ------ .../sharepoint-online/set-up-source-group.md | 61 -- .../sharepoint-online/sharepoint-online.md | 42 -- .../file-servers => guides}/_category_.json | 2 +- .../26.1/guides/active-directory.md | 108 ++++ docs/accessanalyzer/26.1/guides/entra-id.md | 104 ++++ docs/accessanalyzer/26.1/guides/index.md | 17 + .../26.1/guides/microsoft-365.md | 138 +++++ .../26.1/guides/smb-file-servers.md | 151 +++++ docs/accessanalyzer/26.1/index.md | 68 +-- .../26.1/install/_category_.json | 2 +- .../26.1/install/first-sign-in.md | 81 +++ .../26.1/install/identity-provider.md | 553 ------------------ docs/accessanalyzer/26.1/install/index.md | 24 + .../26.1/install/install-commands.md | 302 ---------- .../26.1/install/installer-reference.md | 139 +++++ .../26.1/install/postinstall.md | 97 --- .../26.1/install/prerequisites.md | 203 ------- .../26.1/install/quickinstall.md | 462 --------------- .../26.1/install/requirements.md | 127 ++++ .../26.1/install/run-the-installer.md | 150 +++++ docs/accessanalyzer/26.1/install/security.md | 65 -- .../26.1/install/system/_category_.json | 6 - .../26.1/install/system/certificates.md | 96 --- .../26.1/install/system/kubernetes.md | 53 -- .../26.1/install/system/network.md | 139 ----- .../26.1/install/system/requirements.md | 114 ---- docs/accessanalyzer/26.1/install/uninstall.md | 52 -- .../_category_.json | 4 +- .../accessanalyzer/26.1/integrations/index.md | 8 + .../integrations/netwrix-activity-monitor.md | 136 +++++ docs/accessanalyzer/26.1/key-concepts.md | 60 ++ docs/accessanalyzer/26.1/keyconcepts.md | 137 ----- docs/accessanalyzer/26.1/known-limitations.md | 83 +++ .../scanners => scans}/_category_.json | 4 +- docs/accessanalyzer/26.1/scans/index.md | 196 +++++++ .../26.1/scans/scan-executions.md | 122 ++++ docs/accessanalyzer/26.1/scans/scan-types.md | 123 ++++ docs/accessanalyzer/26.1/scans/schedules.md | 88 +++ .../sensitive-data-patterns/_category_.json | 6 + .../built-in-patterns.md | 389 ++++++++++++ .../custom-patterns.md | 123 ++++ .../26.1/sensitive-data-patterns/index.md | 104 ++++ .../sensitive-data-patterns/pattern-groups.md | 135 +++++ .../_category_.json | 2 +- .../service-accounts/client-id-certificate.md | 130 ++++ .../26.1/service-accounts/client-id-secret.md | 61 ++ .../26.1/service-accounts/index.md | 106 ++++ .../26.1/service-accounts/ssh-key.md | 72 +++ .../service-accounts/username-password.md | 76 +++ .../26.1/settings/_category_.json | 6 + .../26.1/settings/application.md | 124 ++++ docs/accessanalyzer/26.1/settings/backups.md | 72 +++ .../26.1/settings/feature-flags.md | 37 ++ docs/accessanalyzer/26.1/settings/index.md | 35 ++ .../26.1/settings/single-sign-on.md | 166 ++++++ .../26.1/settings/system-logs.md | 62 ++ docs/accessanalyzer/26.1/settings/users.md | 191 ++++++ .../entra-id => sources}/_category_.json | 2 +- .../26.1/sources/active-directory.md | 86 +++ docs/accessanalyzer/26.1/sources/entra-id.md | 82 +++ .../26.1/sources/import-sources.md | 161 +++++ docs/accessanalyzer/26.1/sources/index.md | 104 ++++ docs/accessanalyzer/26.1/sources/labels.md | 82 +++ .../26.1/sources/microsoft-365.md | 110 ++++ .../26.1/sources/smb-file-servers.md | 90 +++ docs/accessanalyzer/26.1/whats-new.md | 45 ++ .../kb-article-template.md | 2 +- .../updating-to-the-latest-version.md | 2 +- docusaurus.config.js | 36 +- src/config/redirects/accessanalyzer-26.1.js | 115 ++++ .../26.1/agents/deploy-agent.webp | Bin 0 -> 91330 bytes .../26.1/agents/edit-agent.webp | Bin 0 -> 68926 bytes .../accessanalyzer/26.1/agents/list.webp | Bin 0 -> 90892 bytes .../26.1/agents/row-actions.webp | Bin 0 -> 93074 bytes .../add-service-account-certificate.png | Bin 132731 -> 0 bytes .../add-service-account-client-secret.png | Bin 134435 -> 0 bytes .../add-service-account-form.png | Bin 135750 -> 0 bytes .../add-service-account-ssh.png | Bin 135101 -> 0 bytes .../add-service-account-username-password.png | Bin 135750 -> 0 bytes .../configurations/scanner-deploy-form.png | Bin 135808 -> 0 bytes .../26.1/configurations/scanners-list.png | Bin 108652 -> 0 bytes .../configurations/service-accounts-list.png | Bin 141715 -> 0 bytes .../active-directory-dashboard.webp | Bin 0 -> 83328 bytes .../data-security-dashboard-activity.webp | Bin 0 -> 90886 bytes .../data-security-dashboard-full.webp | Bin 0 -> 104948 bytes .../data-security-dashboard.webp | Bin 0 -> 104948 bytes .../report-activity-investigation.webp | Bin 0 -> 94586 bytes .../dashboards-reports/report-ad-users.webp | Bin 0 -> 72496 bytes .../report-broken-inheritance.webp | Bin 0 -> 108414 bytes .../report-entra-groups.webp | Bin 0 -> 73464 bytes .../report-entra-users.webp | Bin 0 -> 73650 bytes .../report-high-risk-acls.webp | Bin 0 -> 116606 bytes .../report-open-access.webp | Bin 0 -> 85790 bytes .../report-sensitive-data-overview.webp | Bin 0 -> 98172 bytes .../report-share-audit-sensitive.webp | Bin 0 -> 88998 bytes .../report-share-audit.webp | Bin 0 -> 89082 bytes .../report-shared-links.webp | Bin 0 -> 95484 bytes .../report-sharepoint-high-risk-acls.webp | Bin 0 -> 96242 bytes .../report-sharepoint-open-access.webp | Bin 0 -> 88090 bytes ...rt-sharepoint-sensitive-data-overview.webp | Bin 0 -> 73806 bytes .../reports-compliance-gdpr.webp | Bin 0 -> 144004 bytes .../reports-compliance.webp | Bin 0 -> 135356 bytes .../reports-data-sharepoint.webp | Bin 0 -> 103542 bytes .../26.1/dashboards-reports/reports-data.webp | Bin 0 -> 128616 bytes .../reports-identity-entra-id.webp | Bin 0 -> 82960 bytes .../dashboards-reports/reports-identity.webp | Bin 0 -> 90008 bytes .../identity-provider-active-directory.webp | Bin 0 -> 80862 bytes .../identity-provider-choose.webp | Bin 0 -> 56822 bytes .../identity-provider-entra-id.webp | Bin 0 -> 84356 bytes .../integrations/identity-provider-setup.webp | Bin 0 -> 86500 bytes .../add-service-account-certificate.png | Bin 126602 -> 0 bytes .../add-service-account-client-secret.png | Bin 128026 -> 0 bytes .../migration/add-service-account-form.png | Bin 129106 -> 0 bytes .../migration/add-service-account-initial.png | Bin 129069 -> 0 bytes ...add-service-account-type-dropdown-open.png | Bin 129069 -> 0 bytes .../add-service-account-username-password.png | Bin 129106 -> 0 bytes .../create-source-group-ad-scan-config.png | Bin 140918 -> 0 bytes .../create-source-group-ad-step4.png | Bin 140918 -> 0 bytes .../26.1/migration/create-source-group-ad.png | Bin 142789 -> 0 bytes .../create-source-group-configure.png | Bin 108906 -> 0 bytes ...eate-source-group-entra-id-scan-config.png | Bin 111545 -> 0 bytes .../create-source-group-entra-id.png | Bin 114142 -> 0 bytes ...e-source-group-file-server-scan-config.png | Bin 118241 -> 0 bytes .../create-source-group-file-server-setup.png | Bin 113863 -> 0 bytes .../create-source-group-file-server-step2.png | Bin 120849 -> 0 bytes .../create-source-group-file-server-step4.png | Bin 118241 -> 0 bytes .../migration/create-source-group-filled.png | Bin 110181 -> 0 bytes ...te-source-group-sharepoint-scan-config.png | Bin 132530 -> 0 bytes .../create-source-group-sharepoint.png | Bin 134874 -> 0 bytes .../migration/create-source-group-step1.png | Bin 110087 -> 0 bytes .../26.1/migration/scan-edit-ad-scrolled.png | Bin 172109 -> 0 bytes .../migration/scan-edit-entra-id-scrolled.png | Bin 188589 -> 0 bytes .../scan-edit-file-server-access-scrolled.png | Bin 197238 -> 0 bytes .../scan-edit-file-server-sdd-scrolled.png | Bin 169877 -> 0 bytes .../26.1/migration/service-accounts-list.png | Bin 134923 -> 0 bytes .../26.1/migration/type-dropdown-open.png | Bin 132149 -> 0 bytes .../accessanalyzer/26.1/overview/home.webp | Bin 0 -> 89432 bytes .../accessanalyzer/26.1/overview/sign-in.webp | Bin 0 -> 18484 bytes .../26.1/overview/user-menu.webp | Bin 0 -> 97514 bytes .../accessanalyzer/26.1/scans/calendar.webp | Bin 0 -> 50360 bytes .../26.1/scans/create-scan-1-type.webp | Bin 0 -> 91266 bytes .../scans/create-scan-2-target-labels.webp | Bin 0 -> 91030 bytes .../scans/create-scan-2-target-selected.webp | Bin 0 -> 106330 bytes .../create-scan-3-configure-customize.webp | Bin 0 -> 151728 bytes .../create-scan-4-schedule-agent-menu.webp | Bin 0 -> 85468 bytes .../scans/create-scan-4-schedule-daily.webp | Bin 0 -> 84982 bytes ...create-scan-4-schedule-frequency-menu.webp | Bin 0 -> 86466 bytes .../scans/create-scan-4-schedule-manual.webp | Bin 0 -> 79922 bytes .../scans/create-scan-4-schedule-weekly.webp | Bin 0 -> 91208 bytes .../scans/create-scan-5-review-named.webp | Bin 0 -> 87132 bytes ...n-sensitive-3-configure-custom-groups.webp | Bin 0 -> 157742 bytes .../create-scan-sensitive-3-configure.webp | Bin 0 -> 146552 bytes .../scans/create-scan-unsaved-changes.webp | Bin 0 -> 76262 bytes .../accessanalyzer/26.1/scans/edit-scan.webp | Bin 0 -> 92880 bytes .../26.1/scans/execution-logs-detailed.webp | Bin 0 -> 425906 bytes .../26.1/scans/execution-logs-overview.webp | Bin 0 -> 90042 bytes .../26.1/scans/executions-list.webp | Bin 0 -> 89454 bytes .../26.1/scans/executions-row-actions.webp | Bin 0 -> 91408 bytes .../26.1/scans/executions-status-filter.webp | Bin 0 -> 102244 bytes .../accessanalyzer/26.1/scans/list.webp | Bin 0 -> 85232 bytes .../26.1/scans/row-actions.webp | Bin 0 -> 87664 bytes .../confidence-filter.webp | Bin 0 -> 216068 bytes .../create-pattern-group.webp | Bin 0 -> 133618 bytes .../create-pattern.webp | Bin 0 -> 136874 bytes .../group-actions.webp | Bin 0 -> 198030 bytes .../group-selected.webp | Bin 0 -> 157694 bytes .../group-test-patterns.webp | Bin 0 -> 138912 bytes .../26.1/sensitive-data-patterns/list.webp | Bin 0 -> 218276 bytes .../add-client-id-certificate.webp | Bin 0 -> 115962 bytes .../add-client-id-secret.webp | Bin 0 -> 85302 bytes .../add-ssh-username-key.webp | Bin 0 -> 82076 bytes .../26.1/service-accounts/add-type-menu.webp | Bin 0 -> 84542 bytes .../add-username-password.webp | Bin 0 -> 82696 bytes .../26.1/service-accounts/edit.webp | Bin 0 -> 78018 bytes .../26.1/service-accounts/list.webp | Bin 0 -> 113140 bytes .../26.1/service-accounts/row-actions.webp | Bin 0 -> 113862 bytes .../26.1/settings/add-user.webp | Bin 0 -> 108940 bytes .../26.1/settings/application-full.webp | Bin 0 -> 149114 bytes .../26.1/settings/application.webp | Bin 0 -> 149114 bytes .../26.1/settings/feature-flags.webp | Bin 0 -> 106444 bytes .../26.1/settings/security-settings.webp | Bin 0 -> 89142 bytes .../26.1/settings/system-logs.webp | Bin 0 -> 163758 bytes .../accessanalyzer/26.1/settings/system.webp | Bin 0 -> 108548 bytes .../26.1/settings/user-actions.webp | Bin 0 -> 91530 bytes .../accessanalyzer/26.1/settings/users.webp | Bin 0 -> 87124 bytes .../26.1/sources/add-active-directory.webp | Bin 0 -> 118510 bytes .../26.1/sources/add-entra-id.webp | Bin 0 -> 106990 bytes .../26.1/sources/add-file-server.webp | Bin 0 -> 111008 bytes .../26.1/sources/add-sharepoint-online.webp | Bin 0 -> 110002 bytes .../26.1/sources/add-type-menu.webp | Bin 0 -> 80498 bytes .../26.1/sources/edit-file-server.webp | Bin 0 -> 114918 bytes .../26.1/sources/import-csv.webp | Bin 0 -> 86128 bytes .../26.1/sources/list-row-selected.webp | Bin 0 -> 116908 bytes .../accessanalyzer/26.1/sources/list.webp | Bin 0 -> 105990 bytes 266 files changed, 5694 insertions(+), 6292 deletions(-) rename docs/accessanalyzer/26.1/{gettingstarted/sharepoint-online => agents}/_category_.json (67%) create mode 100644 docs/accessanalyzer/26.1/agents/agent-labels.md create mode 100644 docs/accessanalyzer/26.1/agents/deploy-agent.md create mode 100644 docs/accessanalyzer/26.1/agents/index.md delete mode 100644 docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md delete mode 100644 docs/accessanalyzer/26.1/configurations/application-settings.md delete mode 100644 docs/accessanalyzer/26.1/configurations/identity-provider.md delete mode 100644 docs/accessanalyzer/26.1/configurations/logs.md delete mode 100644 docs/accessanalyzer/26.1/configurations/sensitive-data.md delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/overview.md delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md delete mode 100644 docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/_category_.json delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/scans.md delete mode 100644 docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md delete mode 100644 docs/accessanalyzer/26.1/configurations/users.md delete mode 100644 docs/accessanalyzer/26.1/connectors/_category_.json delete mode 100644 docs/accessanalyzer/26.1/connectors/activedirectory.md delete mode 100644 docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md delete mode 100644 docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md delete mode 100644 docs/accessanalyzer/26.1/connectors/entra-id/overview.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/celerra.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/cifs.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/netapp.md delete mode 100644 docs/accessanalyzer/26.1/connectors/file-servers/vnx.md delete mode 100644 docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json delete mode 100644 docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md delete mode 100644 docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md delete mode 100644 docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/dashboards/_category_.json create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/dashboards/active-directory.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/dashboards/data-security.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/index.md delete mode 100644 docs/accessanalyzer/26.1/dashboards-reports/my-reports.md delete mode 100644 docs/accessanalyzer/26.1/dashboards-reports/reports.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/reports/_category_.json create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/reports/compliance.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/reports/data.md create mode 100644 docs/accessanalyzer/26.1/dashboards-reports/reports/identity.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/_category_.json delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md delete mode 100644 docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md rename docs/accessanalyzer/26.1/{connectors/file-servers => guides}/_category_.json (70%) create mode 100644 docs/accessanalyzer/26.1/guides/active-directory.md create mode 100644 docs/accessanalyzer/26.1/guides/entra-id.md create mode 100644 docs/accessanalyzer/26.1/guides/index.md create mode 100644 docs/accessanalyzer/26.1/guides/microsoft-365.md create mode 100644 docs/accessanalyzer/26.1/guides/smb-file-servers.md create mode 100644 docs/accessanalyzer/26.1/install/first-sign-in.md delete mode 100644 docs/accessanalyzer/26.1/install/identity-provider.md create mode 100644 docs/accessanalyzer/26.1/install/index.md delete mode 100644 docs/accessanalyzer/26.1/install/install-commands.md create mode 100644 docs/accessanalyzer/26.1/install/installer-reference.md delete mode 100644 docs/accessanalyzer/26.1/install/postinstall.md delete mode 100644 docs/accessanalyzer/26.1/install/prerequisites.md delete mode 100644 docs/accessanalyzer/26.1/install/quickinstall.md create mode 100644 docs/accessanalyzer/26.1/install/requirements.md create mode 100644 docs/accessanalyzer/26.1/install/run-the-installer.md delete mode 100644 docs/accessanalyzer/26.1/install/security.md delete mode 100644 docs/accessanalyzer/26.1/install/system/_category_.json delete mode 100644 docs/accessanalyzer/26.1/install/system/certificates.md delete mode 100644 docs/accessanalyzer/26.1/install/system/kubernetes.md delete mode 100644 docs/accessanalyzer/26.1/install/system/network.md delete mode 100644 docs/accessanalyzer/26.1/install/system/requirements.md delete mode 100644 docs/accessanalyzer/26.1/install/uninstall.md rename docs/accessanalyzer/26.1/{configurations => integrations}/_category_.json (50%) create mode 100644 docs/accessanalyzer/26.1/integrations/index.md create mode 100644 docs/accessanalyzer/26.1/integrations/netwrix-activity-monitor.md create mode 100644 docs/accessanalyzer/26.1/key-concepts.md delete mode 100644 docs/accessanalyzer/26.1/keyconcepts.md create mode 100644 docs/accessanalyzer/26.1/known-limitations.md rename docs/accessanalyzer/26.1/{configurations/source-groups/scanners => scans}/_category_.json (53%) create mode 100644 docs/accessanalyzer/26.1/scans/index.md create mode 100644 docs/accessanalyzer/26.1/scans/scan-executions.md create mode 100644 docs/accessanalyzer/26.1/scans/scan-types.md create mode 100644 docs/accessanalyzer/26.1/scans/schedules.md create mode 100644 docs/accessanalyzer/26.1/sensitive-data-patterns/_category_.json create mode 100644 docs/accessanalyzer/26.1/sensitive-data-patterns/built-in-patterns.md create mode 100644 docs/accessanalyzer/26.1/sensitive-data-patterns/custom-patterns.md create mode 100644 docs/accessanalyzer/26.1/sensitive-data-patterns/index.md create mode 100644 docs/accessanalyzer/26.1/sensitive-data-patterns/pattern-groups.md rename docs/accessanalyzer/26.1/{gettingstarted/entra-id => service-accounts}/_category_.json (67%) create mode 100644 docs/accessanalyzer/26.1/service-accounts/client-id-certificate.md create mode 100644 docs/accessanalyzer/26.1/service-accounts/client-id-secret.md create mode 100644 docs/accessanalyzer/26.1/service-accounts/index.md create mode 100644 docs/accessanalyzer/26.1/service-accounts/ssh-key.md create mode 100644 docs/accessanalyzer/26.1/service-accounts/username-password.md create mode 100644 docs/accessanalyzer/26.1/settings/_category_.json create mode 100644 docs/accessanalyzer/26.1/settings/application.md create mode 100644 docs/accessanalyzer/26.1/settings/backups.md create mode 100644 docs/accessanalyzer/26.1/settings/feature-flags.md create mode 100644 docs/accessanalyzer/26.1/settings/index.md create mode 100644 docs/accessanalyzer/26.1/settings/single-sign-on.md create mode 100644 docs/accessanalyzer/26.1/settings/system-logs.md create mode 100644 docs/accessanalyzer/26.1/settings/users.md rename docs/accessanalyzer/26.1/{connectors/entra-id => sources}/_category_.json (73%) create mode 100644 docs/accessanalyzer/26.1/sources/active-directory.md create mode 100644 docs/accessanalyzer/26.1/sources/entra-id.md create mode 100644 docs/accessanalyzer/26.1/sources/import-sources.md create mode 100644 docs/accessanalyzer/26.1/sources/index.md create mode 100644 docs/accessanalyzer/26.1/sources/labels.md create mode 100644 docs/accessanalyzer/26.1/sources/microsoft-365.md create mode 100644 docs/accessanalyzer/26.1/sources/smb-file-servers.md create mode 100644 docs/accessanalyzer/26.1/whats-new.md create mode 100644 src/config/redirects/accessanalyzer-26.1.js create mode 100644 static/images/accessanalyzer/26.1/agents/deploy-agent.webp create mode 100644 static/images/accessanalyzer/26.1/agents/edit-agent.webp create mode 100644 static/images/accessanalyzer/26.1/agents/list.webp create mode 100644 static/images/accessanalyzer/26.1/agents/row-actions.webp delete mode 100644 static/images/accessanalyzer/26.1/configurations/add-service-account-certificate.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/add-service-account-client-secret.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/add-service-account-form.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/add-service-account-ssh.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/add-service-account-username-password.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/scanner-deploy-form.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/scanners-list.png delete mode 100644 static/images/accessanalyzer/26.1/configurations/service-accounts-list.png create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/active-directory-dashboard.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard-activity.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard-full.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-activity-investigation.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-ad-users.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-broken-inheritance.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-entra-groups.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-entra-users.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-high-risk-acls.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-open-access.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-sensitive-data-overview.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-share-audit-sensitive.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-share-audit.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-shared-links.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-high-risk-acls.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-open-access.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-sensitive-data-overview.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-compliance-gdpr.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-compliance.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-data-sharepoint.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-data.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-identity-entra-id.webp create mode 100644 static/images/accessanalyzer/26.1/dashboards-reports/reports-identity.webp create mode 100644 static/images/accessanalyzer/26.1/integrations/identity-provider-active-directory.webp create mode 100644 static/images/accessanalyzer/26.1/integrations/identity-provider-choose.webp create mode 100644 static/images/accessanalyzer/26.1/integrations/identity-provider-entra-id.webp create mode 100644 static/images/accessanalyzer/26.1/integrations/identity-provider-setup.webp delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-certificate.png delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-client-secret.png delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-form.png delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-initial.png delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-type-dropdown-open.png delete mode 100644 static/images/accessanalyzer/26.1/migration/add-service-account-username-password.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-ad-scan-config.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-ad-step4.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-ad.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-configure.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-entra-id-scan-config.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-entra-id.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-file-server-scan-config.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-file-server-setup.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step2.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-file-server-step4.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-filled.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint-scan-config.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-sharepoint.png delete mode 100644 static/images/accessanalyzer/26.1/migration/create-source-group-step1.png delete mode 100644 static/images/accessanalyzer/26.1/migration/scan-edit-ad-scrolled.png delete mode 100644 static/images/accessanalyzer/26.1/migration/scan-edit-entra-id-scrolled.png delete mode 100644 static/images/accessanalyzer/26.1/migration/scan-edit-file-server-access-scrolled.png delete mode 100644 static/images/accessanalyzer/26.1/migration/scan-edit-file-server-sdd-scrolled.png delete mode 100644 static/images/accessanalyzer/26.1/migration/service-accounts-list.png delete mode 100644 static/images/accessanalyzer/26.1/migration/type-dropdown-open.png create mode 100644 static/images/accessanalyzer/26.1/overview/home.webp create mode 100644 static/images/accessanalyzer/26.1/overview/sign-in.webp create mode 100644 static/images/accessanalyzer/26.1/overview/user-menu.webp create mode 100644 static/images/accessanalyzer/26.1/scans/calendar.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-1-type.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-2-target-labels.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-2-target-selected.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-3-configure-customize.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-4-schedule-agent-menu.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-4-schedule-daily.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-4-schedule-frequency-menu.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-4-schedule-manual.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-4-schedule-weekly.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-5-review-named.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-sensitive-3-configure-custom-groups.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-sensitive-3-configure.webp create mode 100644 static/images/accessanalyzer/26.1/scans/create-scan-unsaved-changes.webp create mode 100644 static/images/accessanalyzer/26.1/scans/edit-scan.webp create mode 100644 static/images/accessanalyzer/26.1/scans/execution-logs-detailed.webp create mode 100644 static/images/accessanalyzer/26.1/scans/execution-logs-overview.webp create mode 100644 static/images/accessanalyzer/26.1/scans/executions-list.webp create mode 100644 static/images/accessanalyzer/26.1/scans/executions-row-actions.webp create mode 100644 static/images/accessanalyzer/26.1/scans/executions-status-filter.webp create mode 100644 static/images/accessanalyzer/26.1/scans/list.webp create mode 100644 static/images/accessanalyzer/26.1/scans/row-actions.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/confidence-filter.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/create-pattern-group.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/create-pattern.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/group-actions.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/group-selected.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/group-test-patterns.webp create mode 100644 static/images/accessanalyzer/26.1/sensitive-data-patterns/list.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/add-client-id-certificate.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/add-client-id-secret.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/add-ssh-username-key.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/add-type-menu.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/add-username-password.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/edit.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/list.webp create mode 100644 static/images/accessanalyzer/26.1/service-accounts/row-actions.webp create mode 100644 static/images/accessanalyzer/26.1/settings/add-user.webp create mode 100644 static/images/accessanalyzer/26.1/settings/application-full.webp create mode 100644 static/images/accessanalyzer/26.1/settings/application.webp create mode 100644 static/images/accessanalyzer/26.1/settings/feature-flags.webp create mode 100644 static/images/accessanalyzer/26.1/settings/security-settings.webp create mode 100644 static/images/accessanalyzer/26.1/settings/system-logs.webp create mode 100644 static/images/accessanalyzer/26.1/settings/system.webp create mode 100644 static/images/accessanalyzer/26.1/settings/user-actions.webp create mode 100644 static/images/accessanalyzer/26.1/settings/users.webp create mode 100644 static/images/accessanalyzer/26.1/sources/add-active-directory.webp create mode 100644 static/images/accessanalyzer/26.1/sources/add-entra-id.webp create mode 100644 static/images/accessanalyzer/26.1/sources/add-file-server.webp create mode 100644 static/images/accessanalyzer/26.1/sources/add-sharepoint-online.webp create mode 100644 static/images/accessanalyzer/26.1/sources/add-type-menu.webp create mode 100644 static/images/accessanalyzer/26.1/sources/edit-file-server.webp create mode 100644 static/images/accessanalyzer/26.1/sources/import-csv.webp create mode 100644 static/images/accessanalyzer/26.1/sources/list-row-selected.webp create mode 100644 static/images/accessanalyzer/26.1/sources/list.webp diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/_category_.json b/docs/accessanalyzer/26.1/agents/_category_.json similarity index 67% rename from docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/_category_.json rename to docs/accessanalyzer/26.1/agents/_category_.json index a8d05dd13b..56e5043fce 100644 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/_category_.json +++ b/docs/accessanalyzer/26.1/agents/_category_.json @@ -1,5 +1,5 @@ { - "label": "SharePoint Online", + "label": "Agents", "position": 50, "collapsed": true, "collapsible": true diff --git a/docs/accessanalyzer/26.1/agents/agent-labels.md b/docs/accessanalyzer/26.1/agents/agent-labels.md new file mode 100644 index 0000000000..ee21337e21 --- /dev/null +++ b/docs/accessanalyzer/26.1/agents/agent-labels.md @@ -0,0 +1,99 @@ +--- +title: Agent labels and scan routing +description: How agent labels route each scan execution to an agent, and what happens when no agent carries the label. +sidebar_position: 2 +--- + +Labels are how you tell a scan where to run. Each deployed agent carries one or more `key=value` labels. A scan names a label, and its executions run on an agent that carries it. Leave the label out and the scan runs on the System agent. + +Agent labels are separate from the labels you put on sources. Source labels group sources and pick scan targets; agent labels pick the machine that does the scanning. They don't interact, and they follow different rules. [Labels](../sources/labels.md) describes source labels. + +## Agent labels + +You add labels when you [deploy an agent](deploy-agent.md) and change them later with **Edit**. A deployed agent must have at least one label. The System agent has no labels you can edit, so its **Labels** column on the Agents page is empty. + +The **Labels** field's hint reads "Keys and values are lowercased; spaces become hyphens." Access Analyzer trims surrounding spaces, lowercases the key and the value, and turns each run of spaces inside them into a single hyphen. Enter `Data Center` as the key and `US East` as the value, and the stored label is `data-center=us-east`. + +After that clean-up, the key and the value must fit these rules. + +| Part | Must start with | Can contain | Maximum length | +|---|---|---|---| +| Key | A letter or number | Letters, numbers, and hyphens | 53 characters | +| Value | A letter or number | Letters, numbers, hyphens, underscores, and dots | 63 characters | + +Avoid two keys. `name` is reserved, and `default` marks the System agent internally. Common choices are `region`, `environment`, and `network`, but any keys that make sense for you are fine. + +Pick labels around how you'll route scans, not around how the hosts are built. `region=us-east` and `network=dmz` describe what a scan needs; `cpu=16` doesn't. The **Search agents…** field on the Agents page finds agents by label key, label value, or `key:value`, so a consistent scheme helps there too. + +## Agent selection + +You select a scan's agent when you create it, in the **Agent** field on the **Schedule** step. The dropdown has two groups: **System**, holding the single option **System agent**, and **Agent labels**, listing every `key=value` your agents carry. Select one label. Any agent that carries it can run the scan. + +![Agent location options](/images/accessanalyzer/26.1/scans/create-scan-4-schedule-agent-menu.webp) + +A scan with several sources can send one of them elsewhere. On the **Configure** step: + +1. Expand the source type's section (for example **File Server**). +2. Click **Add source override**. +3. In **Source to override**, select the source. +4. In the override's **Agent** field, select a label. + +Click **Remove override** to undo it. The override applies to that source only; the scan's other sources keep the scan-level choice. + +When an execution starts, Access Analyzer picks the agent for each source in this order: + +```mermaid +flowchart TD + A[Execution starts for a source] --> B{Source has an agent override?} + B -- Yes --> C[Use the override label] + B -- No --> D{Scan has an agent label?} + D -- Yes --> E[Use the scan-level label] + D -- No --> F[Run on the System agent] + C --> G{An online agent carries the label?} + E --> G + G -- Yes --> H[Execution runs on that agent] + G -- No --> I[Execution waits] +``` + +Two details matter here. First, matching is exact: the agent must carry both the key and the value of the label you picked. An agent labeled `region=us-west` doesn't qualify for `region=us-east`, and an agent with only `env=production` doesn't either. Second, an agent that shows **Offline** on the Agents page can't run scans, so a match on labels alone isn't enough; the agent must be online. + +Access Analyzer decides routing each time an execution starts, not when you save the scan. Relabeling an agent, or changing a scan's **Agent** field, takes effect from the next execution. + +The **Agent** column on the Scans page shows where each scan is set to run: **System** for scans with no label, otherwise the label. + +## Executions with no matching agent {#when-no-agent-matches} + +The **Agent** dropdown only offers labels that agents carry, but nothing checks again later. If you delete or relabel the only agent with a scan's label, the scan keeps that label and its schedule fires as normal. Access Analyzer creates the execution, but no scanning happens and the execution doesn't fail immediately. It waits for an agent that carries the label to come online: a new agent you deploy, an offline agent that comes back, or an existing agent you relabel. If no matching agent comes online within about two hours, Access Analyzer marks the execution **Failed**, and the scan's next scheduled execution tries again. + +The same wait happens when the only matching agent goes offline. + +If an execution shows **Running** but makes no progress: + +1. Go to **Configuration > Agents**. +2. Check for a **Healthy** agent whose **Labels** include the scan's label. +3. If there isn't one, deploy an agent with that label, bring the offline agent back online, or edit the scan and select a label that an online agent carries. + +Editing the scan fixes its next execution only; the execution that's already waiting still needs a matching agent to come online. The Home page's **Needs attention** panel lists offline agents with a **Check agents** link, the quickest way to spot an agent that has gone offline. [Scan executions](../scans/scan-executions.md) lists every execution and its status. + +## Example + +Suppose you run the Access Analyzer server in your main data center and have two more agents deployed. + +| Agent | Labels | +|---|---| +| **Default Agent** (the System agent) | none | +| `agent-east` | `env=production`, `region=us-east` | +| `agent-west` | `env=production`, `region=us-west` | + +You configure four scans. + +| Scan | Agent field | Override | Where it runs | +|---|---|---|---| +| HR shares | **System agent** | none | On the server, because no label is set | +| East finance shares | `region=us-east` | none | On `agent-east`, the only agent with that label | +| All production shares | `env=production` | none | On either `agent-east` or `agent-west`, since both carry the label | +| Regional archives | `region=us-east` | `fs-west-01` set to `region=us-west` | On `agent-east` for every source except `fs-west-01`, which runs on `agent-west` | + +If `agent-west` goes offline, "All production shares" keeps running on `agent-east`, while the `fs-west-01` override in "Regional archives" waits for `agent-west` to report **Healthy** again, or fails after about two hours. + +Later you delete `agent-east` to rebuild it. "East finance shares" and the `region=us-east` sources of "Regional archives" keep their label, so their next executions wait, while "All production shares" continues on `agent-west`. The waiting executions start as soon as you deploy the rebuilt agent with `region=us-east` again; if that takes longer than about two hours, they're marked **Failed** and the next scheduled executions try again. diff --git a/docs/accessanalyzer/26.1/agents/deploy-agent.md b/docs/accessanalyzer/26.1/agents/deploy-agent.md new file mode 100644 index 0000000000..6a5b86d0be --- /dev/null +++ b/docs/accessanalyzer/26.1/agents/deploy-agent.md @@ -0,0 +1,136 @@ +--- +title: Deploy an agent +description: Prepare a Linux host and an SSH service account, deploy the agent from the Agents page, and edit or remove it later. +sidebar_position: 1 +--- + +Access Analyzer installs agents for you. You point it at a Linux host it can reach over SSH, and the server runs a set of checks, installs the agent software, and joins the host to the installation. You don't install anything on the host by hand. + +You need the Admin role for everything on this page. Viewers can see the Agents page but can't deploy, edit, or remove agents. + +## Prepare the host + +The host needs a Linux operating system with `bash`, `curl`, and `sudo` installed, an SSH user the server can sign in as, and enough headroom to run scans. Access Analyzer checks every requirement in this table before it installs anything, both when you click **Test connection** and again at the start of a real deployment. + +| Requirement | Minimum | +|---|---| +| CPU | 2 cores | +| Memory | 512 MB available | +| Disk | 5 GB free on `/` | +| SSH user | Can run `sudo` without a password | +| Tools | `bash`, `curl`, and `sudo` on the path | +| Internet | Can reach `https://get.k3s.io` | + +The host also needs these network paths; every port is Transmission Control Protocol (TCP). [Requirements](../install/requirements.md) lists the server side of the first two rows. + +| Direction | Port | Purpose | +|---|---|---| +| Server to host | TCP 22, or the port you enter in **SSH port** | SSH session that installs and configures the agent | +| Host to server | TCP 6443 | The agent's connection to the Access Analyzer server | +| Host to `get.k3s.io` | TCP 443 | Agent software installer | +| Host to `raw.githubusercontent.com` | TCP 443 | Installer checksum | +| Host to `oci.pkg.keygen.sh` | TCP 443 | Licensed software distribution for scan components | + +A deployed agent runs scan work and nothing else. Access Analyzer places nothing else on it. + +## SSH service account + +Access Analyzer signs in to the host with a service account of type **SSH username/key**. The account holds two values: **SSH username**, the Linux user to sign in as, and **SSH key**, that user's private key pasted in PEM or OpenSSH format. The key must not have a passphrase; deployment rejects a passphrase-protected key. The user must be able to run `sudo` without a password prompt. + +You can create the account ahead of time under **Configuration > Service accounts**, or from inside the Deploy agent panel with the **Add new service account** button next to the **Service account** field. The inline **Add service account** form fixes the type to **SSH username/key**; click **Add account** to save it. Either way the result is the same account, and you can reuse it for every agent that uses the same user and key. The field-level detail is in [SSH username and key](../service-accounts/ssh-key.md). + +The host key isn't part of the service account. Each agent has its own, entered when you deploy it. + +## Get the host key + +Access Analyzer checks the host's SSH identity against the key you enter and refuses to continue if the host presents a different one. Collect the public host key from a machine that can reach the host, such as the Access Analyzer server: + +```bash +ssh-keyscan -t ecdsa +``` + +If SSH listens on a port other than 22, add `-p `. The output line begins with the hostname; copy the key type and the key that follow it, for example `ecdsa-sha2-nistp256 AAAA…`. That is the value the **SSH host key** field expects: a key type, a space, and the key. If you can, compare it with the key on the host itself before you trust it. + +## Deploy the agent + +1. Go to **Configuration > Agents**. +2. Click **Deploy agent**. + + ![Deploy agent panel with Name, SSH host, SSH host key, SSH port, Service account, and Labels](/images/accessanalyzer/26.1/agents/deploy-agent.webp) + +3. In **Name**, enter a name for the agent. +4. In **SSH host**, enter the hostname or IP address of the host. +5. In **SSH host key**, paste the host key you collected. +6. In **SSH port**, enter the SSH port if it isn't 22. +7. In **Service account**, select the SSH account. To create one now, click **Add new service account**. +8. Under **Labels**, add at least one label, such as `env=production` or `region=us-east`. Labels are how scans find this agent; see [Agent labels and scan routing](agent-labels.md). +9. To check the host before installing anything, click **Test connection** and wait for **Connection successful**. +10. Click **Deploy**. + +When deployment finishes, the panel closes, a notification reads `Agent "" deployed`, and the agent appears in the list with its **Health Status** and **Last Heartbeat**. + +### Fields + +| Field | What to enter | Rules | +|---|---|---| +| **Name** | A display name, for example `Production Agent` | Required; up to 255 characters | +| **SSH host** | Hostname or IP address, for example `node01.company.com` or `192.168.1.50` | Required; up to 255 characters; must be a valid hostname or IP address | +| **SSH host key** | The host's public key as ` ` | Required; must match the key the host presents | +| **SSH port** | The SSH port | Optional; 1 to 65535; defaults to 22 | +| **Service account** | An account of type SSH username/key | Required; the list shows only SSH accounts; **Edit credentials** opens the selected account | +| **Labels** | One or more `key=value` pairs | At least one required; keys and values are lowercased and spaces become hyphens | + +If you close the panel with unsaved changes, Access Analyzer asks you to confirm. + +### Test connection + +In the Deploy agent panel, **Test connection** becomes available after you fill in **SSH host**, **SSH host key**, and **Service account**. It signs in to the host and runs the checks from [Prepare the host](#prepare-the-host), installing nothing. The button reads **Testing...** while it runs. + +A green **Connection successful** alert means every check passed. It can carry warnings underneath. A red alert reports what failed, for example a missing `curl`, a `sudo` that prompts for a password, or too little free disk. The result clears if you change any of the connection fields. + +### Deployment sequence + +1. The server signs in over SSH and runs the same checks as **Test connection**. +2. It configures the host to download scan components from the software distribution service, authenticated with your license key, and writes the key to a root-only file on the host. +3. It installs the agent software on the host at the same version the server runs. +4. The host connects to the server on port 6443 and joins the installation. +5. The server applies the name and labels you entered to the agent. + +Allow about five minutes. Installation typically takes three to four minutes, and the server allows five minutes for the whole deployment, from signing in over SSH to the agent checking in. If it hasn't checked in by then, deployment still finishes. The Agents list refreshes every 60 seconds, so the agent can still appear a little later. + +If deployment fails, the panel shows the reason. Causes include an SSH user without passwordless `sudo`, a host that can't reach the server on port 6443, and a pasted host key that doesn't match the host. + +## Edit an agent + +1. Go to **Configuration > Agents**. +2. In the agent's **Actions** menu, click **Edit**. + + ![Agent row menu with Edit](/images/accessanalyzer/26.1/agents/row-actions.webp) + +3. Change the **Name** or the **Labels**. A deployed agent must keep at least one label. + + ![Edit agent panel with Name and Labels](/images/accessanalyzer/26.1/agents/edit-agent.webp) + +4. Click **Save changes**. + +The SSH fields don't appear when you edit. Access Analyzer uses SSH only to deploy the agent; after that, the agent talks to the server over its own connection and no longer needs the host key or service account. + +**Test connection** works differently here: instead of checking the host over SSH, it sends a short test task through the agent and confirms it runs. It's a quick way to prove a deployed agent can accept work. Success shows **Connection successful**; a failure shows the server's message. + +You can't rename or relabel the System agent, listed as **Default Agent**; opening **Edit** on it shows **Name** and **Labels** locked. + +## Remove an agent + +1. Go to **Configuration > Agents**. +2. In the agent's **Actions** menu, click **Delete**. +3. Click **Delete Agent** to confirm. + +A notification reads `Agent "" deleted`, and the agent leaves the list. + +Removal takes the agent out of Access Analyzer. The server doesn't connect to the host again, and the agent software stays installed there until you remove it yourself. + +You can't remove an agent while a scan is running on it; the attempt fails with **Failed to delete agent**. Wait for the execution to finish, or stop it from [Scan executions](../scans/scan-executions.md), then try again. + +Scans whose agent label pointed at the removed agent keep that label. Their next execution waits until another agent with matching labels is available, as described in [Agent labels and scan routing](agent-labels.md#when-no-agent-matches). Edit those scans, or deploy a replacement agent with the same labels, before their next scheduled run. + +The System agent has no **Delete** action. diff --git a/docs/accessanalyzer/26.1/agents/index.md b/docs/accessanalyzer/26.1/agents/index.md new file mode 100644 index 0000000000..3fb061ba04 --- /dev/null +++ b/docs/accessanalyzer/26.1/agents/index.md @@ -0,0 +1,66 @@ +--- +title: Agents +description: Agents are the Linux machines that run scans; the System agent is built into every installation, and you can deploy more where the network or the workload calls for it. +--- + +An agent is a Linux machine that runs scans. Every installation has one from the moment setup finishes: the System agent, which runs on the Access Analyzer server itself. Unless you route a scan, or one of its sources, to other agents with a label, every scan runs there. + +You can deploy more agents on other Linux hosts. Access Analyzer connects to the host over SSH, installs the agent software, and adds the agent to the list. From then on you steer scans to it with labels. [Deploy an agent](deploy-agent.md) covers the host requirements and the procedure; [Agent labels and scan routing](agent-labels.md) explains how a scan chooses where to run. + +## The System agent + +The System agent always exists. You can't delete or rename it, and you can't give it labels, so its **Labels** column is empty. It shares the server with the rest of Access Analyzer, so heavy scans compete with the server's own services. + +The same agent goes by three names in the interface, depending on where it appears: + +| Where | What you see | +|---|---| +| The Agents page | **Default Agent** | +| The **Agent** field in the Create scan steps | **System agent** | +| The **Agent** column on the Scans page | **System** | + +## When to deploy more agents + +The System agent is enough for many installations. Add an agent when: + +- The server can't reach a source. An agent placed inside a segmented network or behind a firewall scans the sources there, so the scan traffic comes from the agent rather than the server. +- You want scan traffic to stay local. An agent in the same site or region as the data keeps large reads off slow or expensive links. +- Scans compete with the server. A dedicated agent takes only scan work, so long-running scans no longer slow the server. + +## Who can manage agents + +Deploying, editing, and deleting agents requires the Admin role. Viewers can open the Agents page and see every agent but can't change anything. Assign roles on the [Users and roles](../settings/users.md) page. + +## The Agents page + +Go to **Configuration > Agents**. + +![Agents list with Name, Health Status, Last Heartbeat, and Labels columns](/images/accessanalyzer/26.1/agents/list.webp) + +| Column | Meaning | +|---|---| +| **Name / IP** | The agent's name, with its hostname or IP address underneath | +| **Labels** | The `key=value` labels used for scan routing | +| **Health Status** | Whether the agent is reporting normally; see [Health status](#health-status) | +| **Last Heartbeat** | When the agent last reported in to the server; a dash means no heartbeat has been recorded | +| **Last Updated** | When the agent's record last changed | +| **Actions** | **Edit** for every agent; **Delete** for deployed agents only | + +The list is sorted by **Last Updated**, newest first, and you can sort by **Name** and **Health Status** as well. It shows 25 agents per page (you can pick 10, 25, or 50) and refreshes every 60 seconds on its own, pausing while the **Deploy agent** or **Edit agent** panel is open. + +The **Search agents…** field matches an agent's name, a label key, a label value, or a `key:value` pair, so `region:us-east` finds every agent carrying that label. **Clear filters** resets the search. **Deploy agent** starts the deployment flow. + +### Health status + +| Status | Meaning | What to do | +|---|---|---| +| **Healthy** | The agent is connected and reporting to the server | Nothing; scans routed to it run normally | +| **Offline** | The server has stopped hearing from the agent | Check the host and its connection to the server | + +The heartbeat is the agent's regular check-in with the server. **Last Heartbeat** shows the time of the most recent one, so a stale value alongside **Offline** tells you roughly when the agent went offline. Scan executions routed to an offline agent wait for it to come back and are marked **Failed** if it stays offline for about two hours; see [When no agent matches](agent-labels.md#when-no-agent-matches). + +Offline agents also surface on the Home page. The **Needs attention** panel counts them ("1 agent is offline.") and its **Check agents** link opens the Agents page. + +### Actions + +**Edit** lets you change the agent's name and labels; on the System agent both are locked. **Delete** appears only for deployed agents. See [Edit an agent](deploy-agent.md#edit-an-agent) and [Remove an agent](deploy-agent.md#remove-an-agent). diff --git a/docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md b/docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md deleted file mode 100644 index d204601af0..0000000000 --- a/docs/accessanalyzer/26.1/configurations/activity-monitor-integration.md +++ /dev/null @@ -1,311 +0,0 @@ ---- -title: "Activity Monitor Integration" -description: "Configure Netwrix Activity Monitor to stream real-time file system, SharePoint, and Copilot activity events into Access Analyzer" -sidebar_position: 85 ---- - -# Activity Monitor Integration - -## Overview - -Access Analyzer integrates with **Netwrix Activity Monitor (NAM)** to ingest real-time file system, SharePoint Online, and Microsoft 365 Copilot activity events. After you configure the integration, these events populate the activity reports in AA26.1 and power anomaly detection and sensitive data activity tracking. - -The integration works through a built-in TCP listener that NAM agents connect to over a secure, mutually authenticated TLS 1.3 channel. Events stream continuously from NAM agents into AA26.1's analytics database (ClickHouse), where they become available in reports. - -### Architecture - -``` -NAM Agent(s) - │ - │ TLS 1.3 (default port 4504) - │ mTLS — client certificate required - ▼ -AA26.1 NAM Listener (core-api) - │ - │ Validated & buffered in memory - ▼ -ClickHouse (analytics database) - │ - ▼ -AA26.1 Reports (file system activity, SharePoint, Copilot) -``` - -### Event Types - -| Event Type | Content | -| --- | --- | -| **File System Events** | SMB/CIFS file access, reads, writes, renames, permission changes | -| **SharePoint Online Events** | SharePoint file and folder activity | -| **Copilot Events** | Microsoft 365 Copilot interactions — accessed resources | - -### Security Model - -Authentication uses **mutual TLS with Subject Public Key Info (SPKI) hash pinning**: - -- AA26.1 requires TLS 1.3 and rejects older protocol versions. -- Both products perform mutual authentication by matching hashes of each other's certificate public key (SPKI hash) against a persistent allowlist in their configuration. - -SPKI hashes survive certificate renewal as long as the key pair is unchanged. Re-enroll only when an agent generates a new key pair. - ---- - -## Prerequisites - -Before connecting NAM agents to AA26.1: - -- **Netwrix Activity Monitor** must be installed and monitoring the hosts or services for which you want real-time activity in AA26.1. Confirm monitoring is active before adding the AA26.1 output. -- **TLS certificates** must be provisioned on the AA26.1 server. The environment variables `SYSLOG_TLS_CERT_PATH` and `SYSLOG_TLS_KEY_PATH` specify the server certificate and private key paths. Contact your infrastructure team if the listener isn't starting. -- **Network connectivity** must allow NAM agents to reach AA26.1 on TCP port 4504 (default) through any firewalls or network policies. -- You must have **Administrator** access to AA26.1 to generate enrollment tokens and view enrolled agents. - -:::note -Activity data flows from NAM to AA26.1 — AA26.1 doesn't initiate the connection. Ensure firewalls allow outbound traffic from each NAM agent host to the AA26.1 server on the configured listener port. -::: - ---- - -## Setup - -### Step 1 — Verify the Listener Is Running - -The listener starts automatically when AA26.1 starts, provided TLS certificates are present and the `enable_activitymonitor_ingestion` feature flag is enabled (it is by default). - -To confirm it is active: - -1. Go to **Configuration > Application Settings > Feature Flags**. -2. Verify `enable_activitymonitor_ingestion` is set to `true`. - -If the listener isn't running, check the application logs for the reason — missing certificate, disabled feature flag, or a startup error. - -### Step 2 — Generate an Enrollment Token - -1. Go to **Configuration > Application Settings**. -2. Scroll to the **Activity Monitor** section. -3. Under **Enrollment Token**, click **Generate Token**. -4. Copy the token using the clipboard icon. - -:::note -Tokens expire after **1 hour**. Generating a new token immediately invalidates any previously issued token. A single token can enroll multiple agents and outputs simultaneously — plan your enrollment session and generate the token immediately before you begin. -::: - -### Step 3 — Add the AA26.1 Output in Netwrix Activity Monitor - -Add an AA26.1 output to each monitored host or service in NAM you want to stream into AA26.1. - -:::note -The following steps describe the general configuration flow. Exact menu labels and field names in the NAM console may differ depending on your NAM version. Verify the steps against the NAM documentation for your installed version. -::: - -1. Open the Netwrix Activity Monitor console. -2. Navigate to the monitored host or service. -3. Add a new output and select the **Netwrix Access Analyzer 26** output type. -4. Enter the hostname or IP address of your AA26.1 instance and the listener port (default: 4504). -5. Enter the enrollment token you generated in Step 2 and select **Enroll**. Ensure the connection is successful. -6. Save the output configuration. -7. Repeat for each monitored host or service. - -:::note -You can add an output in bulk by selecting multiple hosts/services and selecting **Add Output**. -::: - -The NAM agent connects to AA26.1, validates AA26.1's certificate by comparing it to the hash embedded in the enrollment token, -presents its client certificate, and sends an enrollment request. AA26.1 validates the token, adds the agent's SPKI hash to the trusted agents allowlist, and confirms enrollment. -The NAM agent also adds AA26.1's SPKI hash to the allowlist. -After that, the agent reconnects and begins streaming events. You no longer need the enrollment token unless the agent generates a new key pair. - -### Step 4 — Verify Enrollment - -After enrollment, the agent appears in AA26.1's trusted agents list. You can view enrolled agents via the API: - -``` -GET /api/v1/nam-listener/agents -``` - -Each entry shows the agent's hostname, source IP, and enrollment timestamp. - -To confirm AA26.1 is receiving events: - -1. Log in to Access Analyzer. -2. Navigate to the resource or host that NAM is monitoring. -3. Review the activity data for recent file events. - -If no events appear after a few minutes, see [Troubleshooting](#troubleshooting). - ---- - -## Application Settings Reference - -All Activity Monitor settings are at **Configuration > Application Settings > Activity Monitor**. Settings take effect immediately when you save them — no restart required. Each setting shows its current value, default, and an **Overridden** badge when changed from the default. Use the reset (↺) button to restore an individual setting to its default. - -### Connection Settings - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| `activitymonitor_tcp_port` | 4504 | 1 – 65535 | TCP port the listener binds to. Must match the port configured in NAM agent settings. | -| `activitymonitor_max_connections` | 100 | 10 – 1000 | Maximum simultaneous agent connections. AA26.1 rejects connections beyond this limit at the TCP layer. | -| `activitymonitor_connection_timeout` | 900 | 5 – 3600 | Seconds of inactivity before AA26.1 drops an idle agent connection. Set this to be comfortably longer than your NAM polling interval. | - -### Performance and Throughput Settings - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| `activitymonitor_reactor_threads` | 0 (auto) | 0 – 32 | Async input/output threads for handling connections. `0` automatically uses one thread per CPU core — correct for almost all deployments. | -| `activitymonitor_buffer_threads` | 8 | 1 – 16 | Writer threads that drain the in-memory event buffer to ClickHouse. More threads help sustain high write rates. | -| `activitymonitor_buffer_max_size` | 10,000 | 1,000 – 500,000 | Maximum events held in memory at once. When full, AA26.1 holds new arrivals at the TCP layer (backpressure to agents) rather than dropping them. | -| `activitymonitor_batch_size` | 100 | 10 – 1,000 | Events grouped per internal processing batch. | -| `activitymonitor_batch_interval_seconds` | 10 | 1 – 60 | Maximum seconds between batch flushes to ClickHouse. The primary control for **data freshness** — lower values mean events appear in reports sooner, at the cost of more frequent small writes. | -| `activitymonitor_clickhouse_batch_size` | 10,000 | 1,000 – 100,000 | Events per ClickHouse write operation. Larger batches are more efficient but increase memory usage during the write. | -| `activitymonitor_max_concurrent_jobs` | 3 | 1 – 10 | Maximum parallel batch processing jobs. | - -### Security and Enrollment Settings - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| `activitymonitor_enrollment_first_message_timeout_seconds` | 10 | 5 – 60 | Seconds AA26.1 waits for the first message after a new connection is established. AA26.1 closes connections that send nothing within this window. | -| `activitymonitor_enrollment_ban_duration_seconds` | 10 | 5 – 300 | Seconds AA26.1 blocks a source IP after a protocol violation (invalid enrollment code, malformed JSON, or unexpected message format). | -| `activitymonitor_max_message_size` | 16,777,216 (16 MB) | 65,536 – 67,108,864 | Maximum byte size of a single message from a NAM agent. If a message exceeds this size without a line delimiter, AA26.1 drops the connection. | - -### Shutdown Settings - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| `activitymonitor_shutdown_drain_timeout_seconds` | 300 | 10 – 3,600 | Maximum seconds AA26.1 waits for buffered events to finish writing to ClickHouse during a graceful shutdown. After this window, AA26.1 force-terminates remaining writer threads and loses any events still in the buffer. | - ---- - -## Best Practices - -### Port Configuration - -Use the default port (4504) unless you have a conflict. If you must change it: - -- Update NAM agent configuration to match **before** saving the new port in AA26.1. -- Update firewall rules and network policies before making the change. -- Changing the port requires all connected agents to reconnect. - -### TLS Certificate Management - -- **Monitor certificate expiration.** AA26.1 logs a warning when the server certificate is within 30 days of expiry, and again within 7 days. Treat the 30-day warning as actionable. -- **NAM agents use self-signed certificates by default** — this is expected and supported. If you replace them with CA-signed certificates, re-enroll the agent. -- **Key pair rotation requires re-enrollment.** If a NAM agent generates a new key pair, its previous SPKI hash entry will no longer match. Re-enroll the agent using a new enrollment token. Remove the stale entry via the API: `DELETE /api/v1/nam-listener/agents/:spki_hash`. - -### Enrollment Token Practices - -- **Generate the token immediately before enrollment.** The 1-hour window is intentionally short. -- **Don't share tokens in email or chat.** Treat enrollment tokens like temporary passwords — use a secure transfer method. -- **For bulk enrollment**, all agents can use the same token as long as they enroll within the 1-hour window. -- **Revoke stale entries** when decommissioning a NAM agent host. An enrolled agent with a stale SPKI entry poses no security risk, but maintaining a clean allowlist helps with auditing. - -### Performance Tuning - -Start with defaults. Only adjust if you observe specific symptoms. - -**If events appear in reports with high latency (> 30 seconds):** -- Lower `activitymonitor_batch_interval_seconds` (for example, from 10 to 5). -- Check `activitymonitor_buffer_max_size` — if the buffer is routinely full, ClickHouse writes may be the bottleneck. - -**If you have a high-volume environment (many agents, high event rate):** -- Increase `activitymonitor_buffer_max_size` to 50,000 – 100,000 to absorb burst traffic. -- Increase `activitymonitor_clickhouse_batch_size` to 25,000 – 50,000 to reduce write frequency. -- Increase `activitymonitor_buffer_threads` to 12 – 16 to parallelize writes. -- Leave `activitymonitor_reactor_threads` at `0` (auto). - -**If you have many agents connecting simultaneously:** -- Raise `activitymonitor_max_connections` to at least the number of expected concurrent agents, with 20–30% headroom. - -**Don't lower `activitymonitor_connection_timeout` below your NAM polling interval.** If NAM sends events every 5 minutes and the timeout is less than 300 seconds, AA26.1 drops agents between batches and forces them to reconnect constantly. The default of 900 seconds provides safe headroom for most polling configurations. - -### Kubernetes Shutdown Considerations - -The `activitymonitor_shutdown_drain_timeout_seconds` setting (default: 300 seconds) controls how long AA26.1 waits during graceful shutdown to flush buffered events to ClickHouse. - -In Kubernetes deployments, the pod's `terminationGracePeriodSeconds` must be greater than this value plus a small buffer for the rest of the shutdown sequence. If `terminationGracePeriodSeconds` is less than the drain timeout, Kubernetes will force-kill the pod before drain completes, losing any buffered events. - -### Disabling the Integration - -To temporarily disable ingestion without removing agent configurations: - -1. Go to **Configuration > Application Settings > Feature Flags**. -2. Set `enable_activitymonitor_ingestion` to `false` and save. - -The listener stops accepting new connections. Existing agents will see their connections close and queue events locally per NAM's own buffering. When you re-enable ingestion, agents reconnect and resume streaming. - -:::note -Disabling and re-enabling doesn't cause data loss for events that occurred while disabled, as long as NAM agents have sufficient local buffering. -::: - ---- - -## Troubleshooting - -### The listener isn't starting - -- Verify `enable_activitymonitor_ingestion` is `true` in **Configuration > Application Settings > Feature Flags**. -- Verify the TLS certificate environment variables (`SYSLOG_TLS_CERT_PATH`, `SYSLOG_TLS_KEY_PATH`) are set and the files are readable. The application logs report a specific error if a certificate is missing, unreadable, or expired. -- Verify another process isn't already using the configured port. - -The listener retries startup up to 5 times with exponential backoff (starting at 0.5s, capping at 30s). Check logs for `"Failed to start NAM Listener"` messages with retry counts. - -### A NAM agent can't connect - -- Verify network connectivity from the agent host to AA26.1 on the configured port (default: 4504). -- Verify the agent is configured with the correct hostname and port. The port in NAM agent configuration must match `activitymonitor_tcp_port`. -- Verify the agent has a valid TLS client certificate. AA26.1 rejects connections without a client certificate and temporarily bans the source IP. - -### An agent connected but isn't sending data - -- Verify the agent enrolled successfully. AA26.1 silently rejects data connections from agents that have not completed enrollment because their SPKI hash isn't in the allowlist. Re-enroll using a new token. -- Verify `activitymonitor_connection_timeout` isn't shorter than the agent's event polling interval. If agents idle longer than the timeout, AA26.1 drops them between batches and they must reconnect. - -### Events aren't appearing in reports - -- Verify ClickHouse is healthy and reachable from AA26.1. Writer threads log errors if ClickHouse writes fail. -- Check `activitymonitor_batch_interval_seconds` — at the default of 10 seconds, there is a short delay between an event occurring and appearing in a report. -- Check application logs for buffer queue depth statistics. If the buffer is full, ClickHouse writes may be lagging — consider increasing `activitymonitor_buffer_max_size` or `activitymonitor_clickhouse_batch_size`. - -### An agent keeps getting banned - -Protocol violations trigger repeated IP bans (governed by `activitymonitor_enrollment_ban_duration_seconds`): invalid enrollment codes, malformed JSON, or unexpected message formats. - -- Verify the agent is sending the correct enrollment payload. The agent should be a supported Netwrix Activity Monitor version. -- Verify the enrollment token has not expired (1-hour TTL). An expired token causes an invalid-code rejection and a short ban. Generate a new token and retry. - -Bans are short (default: 10 seconds) and reset on pod restart. For persistent issues, check NAM agent logs for the specific error response AA26.1 sends during enrollment. - -### Enrolled agents list has stale entries - -Decommissioned or reinstalled agents may leave stale entries in the allowlist. These are harmless — the old SPKI hash will never match a new agent's certificate. Remove them using the API: - -``` -DELETE /api/v1/nam-listener/agents/:spki_hash -``` - -List all enrolled agents at: - -``` -GET /api/v1/nam-listener/agents -``` - ---- - -## Settings Quick Reference - -| Scenario | Setting | Recommended Change | -| --- | --- | --- | -| High event volume | `activitymonitor_buffer_max_size` | Increase to 50,000 – 100,000 | -| High event volume | `activitymonitor_clickhouse_batch_size` | Increase to 25,000 – 50,000 | -| High event volume | `activitymonitor_buffer_threads` | Increase to 12 – 16 | -| Many agents (> 100) | `activitymonitor_max_connections` | Set to agent count + 30% headroom | -| Improve report freshness | `activitymonitor_batch_interval_seconds` | Decrease to 3 – 5 | -| Long agent idle intervals | `activitymonitor_connection_timeout` | Increase to 1800 – 3600 | -| Kubernetes slow shutdown | `activitymonitor_shutdown_drain_timeout_seconds` | Decrease; align `terminationGracePeriodSeconds` | -| Maintenance window | `enable_activitymonitor_ingestion` | Set to `false`, re-enable when done | -| Port conflict | `activitymonitor_tcp_port` | Change to available port; update NAM agents and firewall rules first | - ---- - -## Related Resources - -- [Netwrix Activity Monitor Documentation](https://docs.netwrix.com/docs/activitymonitor) -- [Hardware and System Requirements](/docs/accessanalyzer/26_1/install/system/requirements) -- [Network and Port Requirements](/docs/accessanalyzer/26_1/install/system/network) diff --git a/docs/accessanalyzer/26.1/configurations/application-settings.md b/docs/accessanalyzer/26.1/configurations/application-settings.md deleted file mode 100644 index 2fb8eb5235..0000000000 --- a/docs/accessanalyzer/26.1/configurations/application-settings.md +++ /dev/null @@ -1,106 +0,0 @@ ---- -title: "Application Settings" -description: "Managing application settings in the Configuration node" -sidebar_position: 80 ---- - -# Application Settings - -The Application Settings page exposes configurable options that control scan behavior, file scanning limits, feature availability, Activity Monitor integration, and application branding. Navigate to **Configuration** > **Application Settings** to view and modify these settings. - -:::note -This page is available to users with the **Administrator** role only. -::: - -## Setting categories - -| Category | What it controls | -| --- | --- | -| **Feature Flags** | Enable or disable product features and integrations | -| **Scanning** | Execution history retention for scans and identity syncs | -| **File Scanning** | File size limits and excluded extensions for SMB and SharePoint scans | -| **Activity Monitor** | TCP listener behavior and enrollment token for Netwrix Activity Monitor (NAM) agent connections | -| **Branding** | Company name and support email displayed in the application | - -## Feature Flags - -Feature flags enable or disable specific product capabilities. Changes take effect immediately — no restart required. - -| Flag | Default | Description | -| --- | --- | --- | -| **MIP Labeling** | Enabled | Enables Microsoft Information Protection (MIP) sensitivity label management for SMB file shares and SharePoint Online. When disabled, the label handling options on the Sensitive Data page are hidden and no labels are applied to or read from files during scans. | - -:::note -Disabling MIP Labeling doesn't remove existing labels from files. It stops Access Analyzer from applying or updating labels in future scans. -::: - -## File Scanning - -These settings control which files are included in content classification during sensitive data scans. Adjusting them can reduce scan duration in environments with large binary or media files. - -:::note -Access Analyzer always collects file metadata — name, size, permissions, and owner — regardless of file size or extension settings. These limits apply only to content classification during sensitive data scans. -::: - -### SMB / CIFS - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| **Maximum file size** | 10 MB | 1–100 MB | Files larger than this limit are skipped during content classification. | -| **Excluded extensions** | `.exe, .msi, .bat, .png, .jpg, .jpeg, ...` | — | Comma-separated list of file extensions to skip. Add extensions to reduce scan time on known binary or media content. | - -### SharePoint Online - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| **Maximum file size** | 1 MB | 1–50 MB | Files larger than this limit are skipped during content classification. | -| **Excluded extensions** | `.exe, .msi, .bat, .png, .jpg, .jpeg, ...` | — | Comma-separated list of file extensions to skip. | - -## Scanning — Execution History Retention - -Access Analyzer automatically purges old execution records on a nightly schedule based on these thresholds. - -| Setting | Default | Range | Description | -| --- | --- | --- | --- | -| **Scan execution retention** | 90 days | 7–365 days | How long scan execution records are retained before automatic deletion. | -| **Sync execution retention** | 90 days | 7–365 days | How long identity sync execution records are retained before automatic deletion. | - -:::note -Reducing retention frees database storage. Increasing it extends the history available in **Configuration** > **Source Groups** > **Scan Executions**. -::: - -## Activity Monitor - -The Activity Monitor category contains settings for the built-in TCP listener and the enrollment token used when connecting NAM agents to Access Analyzer. - -### Enrollment Token - -The enrollment token is a short-lived credential that NAM agents present during their first connection to Access Analyzer. You generate it here and paste it into the NAM agent output configuration. - -1. Scroll to the **Activity Monitor** section and locate **Enrollment Token**. -2. Click **Generate Token**. -3. Copy the token using the clipboard icon. -4. Paste the token into your NAM agent output configuration before it expires. - -:::note -Tokens expire after **1 hour**. Generating a new token immediately invalidates any previously issued token. A single token can enroll multiple agents simultaneously — generate it immediately before starting your enrollment session. -::: - -For the full step-by-step setup walkthrough, see [Activity Monitor Integration](activity-monitor-integration.md). - -### Listener settings - -The remaining settings in the Activity Monitor category control TCP listener behavior — connection limits, batch sizes, buffer sizes, and timeouts. The defaults are appropriate for most deployments. For a description of each setting and guidance on tuning, see the [Activity Monitor Integration — Application Settings Reference](activity-monitor-integration.md#application-settings-reference) section. - -## Branding - -| Setting | Default | Description | -| --- | --- | --- | -| **Company name** | Netwrix | Displayed in the application interface. | -| **Support email** | support@netwrix.com | Email address shown to users when they need assistance. Update this to your internal helpdesk address after initial setup. | - -## Resetting and cache behavior - -**Resetting to default:** Each setting has a reset action that restores the factory default value. Resetting one setting doesn't affect any other settings. - -**Cache:** Access Analyzer caches Application Settings for up to 5 minutes. Changes take effect immediately on the instance that applied them. Other running instances pick up the change within 5 minutes. To force an immediate refresh across all instances, click **Refresh Cache** at the top of the page. diff --git a/docs/accessanalyzer/26.1/configurations/identity-provider.md b/docs/accessanalyzer/26.1/configurations/identity-provider.md deleted file mode 100644 index afdab8dac3..0000000000 --- a/docs/accessanalyzer/26.1/configurations/identity-provider.md +++ /dev/null @@ -1,137 +0,0 @@ ---- -title: "Identity Provider" -description: "Configure single sign-on with an external Identity Provider in Access Analyzer" -sidebar_position: 75 ---- - -# Identity Provider - -Access Analyzer supports federation with your organization's identity system so that users can sign in with their existing corporate credentials. Your identity provider handles authentication; you manage roles and permissions within Access Analyzer. - -Setting up an identity provider connection is a two-part process: first you configure the integration in your identity system, then you prepare user accounts inside Access Analyzer. - -:::note -Before continuing, confirm that the infrastructure and network requirements for your identity provider (IdP) type are in place. See [Network and Port Requirements](../install/system/network.md) and [TLS Certificate Requirements](../install/system/certificates.md). -::: - -## Supported integration types - -| Type | Description | -| --- | --- | -| **Active Directory** | Access Analyzer connects directly to your Active Directory over LDAPS. Users enter their directory credentials on the Access Analyzer login page — no redirect occurs. | -| **Entra ID** | Access Analyzer redirects users to Microsoft Entra ID (formerly Azure AD) to authenticate, then signs them in on return. | - -## Setting up an identity provider - -The installer provisions a local administrator account so you can sign in and start using Access Analyzer immediately — you don't need to connect an identity provider to complete installation. See [Quick Install](../install/quickinstall.md) for the installation steps. - -On first sign-in, the setup wizard prompts you to connect Active Directory or Entra ID: - -- **Connect now** — select **Active Directory** or **Entra ID** and complete the fields in [Part 1](#part-1-configure-your-identity-provider). -- **Set up later** — skip the wizard and go directly into the app using the local admin account. You keep full access, and you can revisit the wizard anytime at `/setup`. - -## Part 1: Configure your identity provider - -### Active Directory - -Active Directory doesn't require an application registration. Prepare the following before connecting. - -**Service account:** Create a dedicated, read-only service account in your directory. Access Analyzer never writes to your directory. - -**Certificate:** Have the CA certificate that issued your domain controller's LDAPS certificate ready as a PEM file. The setup wizard requires it to complete the connection test. - -**Network access:** The Access Analyzer cluster must be able to reach a domain controller in your AD forest over LDAPS (port 636). - -Collect the following values: - -| Value | Description | -| --- | --- | -| **AD domain name** | Fully qualified domain name of your AD forest — for example, `corp.example.com`. Access Analyzer connects over LDAPS (port 636) automatically. | -| **Service account** | A read-only service account, in User Principal Name (UPN) format — for example, `aa26-svc@corp.example.com` | -| **Service account password** | — | -| **AD authentication certificate** | The CA certificate (PEM) that issued the domain controller's LDAPS certificate | - -You don't need to look up the users base DN or the email attribute yourself. After you enter the domain, service account, and certificate, the wizard tests the connection and discovers both automatically. - -### Entra ID - -Complete the following steps in the Azure Portal before connecting Access Analyzer. - -1. Open **Azure Portal** > **Entra ID** > **App registrations** > **New registration**. -2. Name the application and click **Register**. -3. Open the registration > **Authentication** > **Add a platform** > **Web**, and add two redirect URIs: - - The URI shown on the Access Analyzer setup wizard's **Entra ID** step (`https:///setup/entra-consent-callback`) — used once, during the admin-consent step. - - `https:///idps/callback` — used every time a user signs in with Entra ID. -4. Go to **Certificates & secrets** > **New client secret**. Set an expiry that fits your rotation policy and copy the value immediately — the portal shows it only once. - -Collect the following values: - -| Value | Where to find it | -| --- | --- | -| **Tenant ID** | Azure Portal > Entra ID > Overview > Directory (tenant) ID — the GUID, not the primary domain | -| **Application (client) ID** | App registration > Overview > Application (client) ID | -| **Client secret** | Created in step 4 | - -Enter these values in the Access Analyzer setup wizard and click **Sign in with Microsoft and continue**. A popup prompts a **Global Administrator** or **Privileged Role Administrator** to sign in and grant consent for Access Analyzer to read the directory. - -:::note -Register both redirect URIs before anyone signs in with Entra ID. The setup wizard's callback completes the connection; `/idps/callback` is Microsoft's redirect target for every subsequent sign-in — omitting it lets you finish setup but blocks sign-in with an `AADSTS50011` redirect URI mismatch. -::: - -## Part 2: Prepare Access Analyzer - -### First sign-in - -The installer provisions a local first administrator account during installation — the person whose email you entered at the **First Admin Email** prompt can sign in immediately using the temporary password shown in the installation summary. See [First admin account](../install/quickinstall.md#first-admin-account). - -Navigate to `https://` and sign in with the first admin's email and temporary password, then set a new password when prompted. The setup wizard then prompts you to connect Active Directory or Entra ID — or select **Set up later** to go directly into the app and revisit the wizard anytime at `/setup`. - -### Pre-provision user accounts - -Before a user can sign in through the identity provider, their account must exist in Access Analyzer. The application successfully authenticates them against your IdP but denies access if no matching account exists. - -:::note -The email address you enter during pre-provisioning must exactly match the address the IdP sends or the address in the LDAP `mail` attribute, including case. A mismatch causes sign-in to fail. -::: - -1. Navigate to **Configuration** > **Users**. -2. Click **Add User**. -3. Enter the user's **Name** and **Email** address. -4. Select a **Role**: **Administrator**, **User Admin**, or **Viewer** (see [Roles](#roles)). -5. Click **Create User**. - -Pre-provisioned accounts don't require a password. For details on managing users, see [Users](users.md). - -### Roles - - - - -Access Analyzer has three roles. The installer assigns the first admin account the Administrator role, so it can pre-provision the rest of your users. - -| Role | Description | -| --- | --- | -| **Administrator** | Full access: system configuration (sources, scans, connectors, application settings) and user management (create, edit, activate, deactivate, and delete users; assign roles; pre-provision federated users). | -| **User Admin** | User and role management rights only: create, edit, activate, deactivate, and delete users; assign roles; pre-provision federated users. Does **not** have system configuration rights. | -| **Viewer** | Read-only access to data and reports. No configuration or user management rights. | - - - -## How sign-in works after IdP configuration - -When identity provider integration is active, the Access Analyzer login page presents a credential form that validates against your directory. - -On first sign-in, Access Analyzer matches the email address from the IdP token or LDAP directory to the pre-provisioned account and permanently links the IdP identity to that account. On all subsequent sign-ins, Access Analyzer uses the user's unique IdP identifier directly. - -Sessions are valid for up to 8 hours from sign-in and expire after 4 hours of inactivity. - -## Constraints - -| Item | Detail | -| --- | --- | -| **Pre-provisioning required** | Users must have an account in Access Analyzer before their first sign-in. | -| **Email must match exactly** | The email you enter during pre-provisioning must match what the IdP or LDAP directory sends, including case. | -| **Roles managed in Access Analyzer** | You set roles and permissions in Access Analyzer, not in your IdP or directory. | -| **Local accounts coexist** | The administrator account created at deployment remains a local account and continues to sign in with a password. | -| **Password reset unavailable for federated accounts** | The **Reset Password** action in the Users page is available for local accounts only. Federated users manage their credentials through your IdP. | -| **Name and email locked after first sign-in** | Once a user has signed in at least once, their name and email come from the IdP token; you can't change them in the Access Analyzer UI. Update them in your IdP instead. | diff --git a/docs/accessanalyzer/26.1/configurations/logs.md b/docs/accessanalyzer/26.1/configurations/logs.md deleted file mode 100644 index f093db1b9b..0000000000 --- a/docs/accessanalyzer/26.1/configurations/logs.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "System Logs" -description: "Viewing, filtering, and downloading system logs in Access Analyzer" -sidebar_position: 90 ---- - -# System Logs - -The System Logs page displays application-wide log entries that Access Analyzer services generate. Use it to monitor activity, investigate scan failures, and collect diagnostic information for support. - -Navigate to **Configuration** > **System Logs** to open the page. - -## Log entry fields - -Each log entry contains the following fields. - -| Field | Description | -| --- | --- | -| **Timestamp** | The date and time the log entry was generated. | -| **Level** | The severity of the entry: **Error**, **Warn**, **Info**, or **Debug**. | -| **Component** | The internal service that generated the entry (for example, `core-api`, `connector-api`, or `scanner`). Displays **—** if not available. | -| **Source** | The data source associated with the entry, if any. Displays **—** for entries not tied to a specific source. | -| **Message** | The log message text. Hover over a truncated message to see the full text. | - -## Filter logs - -The toolbar above the log table provides five independent filters. All active filters combine — the table shows only entries matching all conditions. The page URL preserves filter state, so you can bookmark or share a filtered view. - -**Search** - -Type in the search field to filter by message text. Results update after a short pause while you type. - -**Level** - -Select a severity level to show only entries at that level. The default shows all levels. - -| Level | Description | -| --- | --- | -| **Error** | Failures that require attention. | -| **Warn** | Conditions that may indicate a problem. | -| **Info** | General operational events. | -| **Debug** | Detailed diagnostic output. | - -**Component** - -Select one or more components to show entries from those services only. The component list includes services that have generated logs. - -**Source** - -Select a data source to show only log entries associated with it. The source list includes sources that have activity in the past seven days. - -**Date range** - -Use the **From** and **To** fields to restrict entries to a specific time window. Both fields are optional — set only one to filter from or until a given time. - -## Sort and paginate - -Access Analyzer sorts the log table by timestamp, newest first by default. Click the **Timestamp** column header to reverse the sort order. - -Use the rows-per-page control to display 10, 25, 50, or 100 entries per page. - -## Download logs - -To export log entries for offline review or to provide to support: - -1. Apply any filters you want to include in the export. -2. Click the **Download** button in the toolbar. -3. Select **JSON** or **CSV** from the dropdown. - -Access Analyzer names the export file `system-logs-{timestamp}`; the file reflects all active filters. Access Analyzer limits exports to 10,000 entries. - -CSV exports include the following columns: Timestamp, Level, Message, Trace ID, Span ID, and Attributes. - -## Common troubleshooting scenarios - -### Investigate a scan failure - -When a scan doesn't complete as expected: - -1. Set the **Source** filter to the data source the scan was running against. -2. Set the **Level** filter to **Error**. -3. Set the **Date range** to the window when the scan ran. -4. Review the **Message** column for error details. - -If no error-level entries appear, clear the **Level** filter and check for **Warn** entries that may indicate a configuration or connectivity issue. - -### Review logs for a specific time window - -1. Enter the start time in the **From** field. -2. Enter the end time in the **To** field. -3. Leave other filters clear to see all activity in that window. - -Use this approach to identify what was happening in the system around the time of an observed issue. - -### Isolate logs from a specific service - -1. Open the **Component** dropdown. -2. Select the service you want to focus on. - -You can select multiple components at the same time to compare activity across services. - -### Collect logs for a support case - -1. Set the **Date range** to cover the period when the issue occurred. -2. If the issue is tied to a specific data source, set the **Source** filter. -3. Click **Download** and select **JSON** to preserve full attribute metadata. - -Provide the downloaded file along with your support request. diff --git a/docs/accessanalyzer/26.1/configurations/sensitive-data.md b/docs/accessanalyzer/26.1/configurations/sensitive-data.md deleted file mode 100644 index c3ac3d023f..0000000000 --- a/docs/accessanalyzer/26.1/configurations/sensitive-data.md +++ /dev/null @@ -1,154 +0,0 @@ ---- -title: "Sensitive Data" -description: "Configure sensitive data scanning settings in Access Analyzer" -sidebar_position: 30 ---- - -# Sensitive Data - -The Sensitive Data configuration page defines which types of sensitive content Access Analyzer identifies during scans, whether to run optical character recognition (OCR) on images, and how Access Analyzer applies Microsoft Information Protection (MIP) sensitivity labels to matching files. These settings apply globally and serve as the default for all sensitive data scans. - -Navigate to **Configuration** > **Sensitive Data** to view and update the configuration. - -The page has two sections: - -- **Microsoft Information Protection (MIP) Configuration** — connects an Entra ID tenant so Access Analyzer can retrieve your organization's MIP sensitivity labels. -- **Sensitive Data Types** — controls which data types are active for scanning and optionally maps each type to a MIP label. - -## MIP configuration - -The MIP configuration section connects Access Analyzer to a Microsoft Entra ID tenant. After you connect a tenant, Access Analyzer retrieves the sensitivity labels defined in your organization's MIP policy and makes them available for mapping in the Sensitive Data Types table. - -### Select a tenant - -1. In the **Tenant ID** dropdown, select the Entra ID source that represents the tenant whose MIP labels you want to use. -2. Click **Save Configuration**. - -The dropdown lists Entra ID source groups that have completed at least one **Users, Groups, and Roles** scan. If the dropdown is empty, either no Entra ID source group exists or the scan has not run yet. Run the scan first, then return to this page to select the tenant. - -After you select a tenant, Access Analyzer retrieves the associated MIP labels. The status bar below the dropdown shows: - -| Indicator | Meaning | -| --- | --- | -| Labels loaded count | The number of MIP labels retrieved from the selected tenant. | -| Invalid mappings count | The number of data types whose previously saved label no longer exists in MIP. | -| Last synced time | How long ago the labels were last synchronized from Entra ID. | - -MIP labels sync automatically from Entra ID at regular intervals. If a label is removed from MIP after you save a mapping, the **MIP Label** column shows the old label name with a warning indicator, and the **Status** column shows **Label Missing**. Update or clear those mappings before saving. - -:::note -The label selector and status badges in the Sensitive Data Types table are disabled until you select a tenant and labels finish loading. -::: - -## Sensitive data types - -The Sensitive Data Types table lists all data types that Access Analyzer can detect. Enable a data type to include it in sensitive data scans. If MIP labels are available, you can also map each data type to a specific label so Access Analyzer applies that label to files that match the data type. - -### Data types - -| Data Type | Description | Includes | -| --- | --- | --- | -| **CCPA** | California Consumer Privacy Act | Social Security numbers, driver's licenses, payment card data, email addresses, IP addresses, personal identifiers for California and Canadian residents | -| **CMMC** | Cybersecurity Maturity Model Certification | Controlled Unclassified Information (CUI) markings, DoD distribution statements (B–F), export control warning labels | -| **Credentials** | Passwords, API keys, and authentication secrets | Private keys (RSA, DSA, EC), passwords, AWS, Azure, and Google Cloud connection strings, PGP key blocks, Kerberos tickets, Slack tokens, SSH authorized keys | -| **Financial Records** | Banking and financial account data | ABA routing numbers, IBAN, SWIFT codes, US bank account numbers | -| **GDPR** | General Data Protection Regulation | National IDs, passports, driver's licenses, and personal identifiers for EU and EEA member states (30 countries including Austria, France, Germany, Italy, Spain, and others) | -| **GDPR Restricted** | Special categories of personal data under GDPR | Health data, political opinions, racial or ethnic origin, religious beliefs, sexual orientation, trade union membership | -| **GLBA** | Gramm-Leach-Bliley Act | Payment card numbers, cardholder names, expiration dates, security codes (Visa, Mastercard, AMEX, Discover, and others), ABA routing numbers, Social Security numbers | -| **HIPAA** | Health Insurance Portability and Accountability Act | ICD-10 diagnosis codes, prescription drug names, medical record numbers, national drug codes, Medicare numbers, Social Security numbers, patient identifiers | -| **PCI DSS** | Payment Card Industry Data Security Standard | Payment card numbers, cardholder names, expiration dates, security codes (Visa, Mastercard, AMEX, Diners Club, Discover, JCB, UnionPay) | -| **PHI** | Protected Health Information | ICD-10 codes, prescription drug names, medical record numbers, country-specific healthcare IDs for 20+ countries including UK NHS numbers, Australian Medicare numbers, and EU health insurance identifiers | -| **PII** | Personally Identifiable Information | Social Security numbers, passports, driver's licenses, full names, dates of birth, home addresses, and national identity documents for 60+ countries | - -### Table columns - -| Column | Description | -| --- | --- | -| Checkbox | Enables or disables the data type for scanning. Select the header checkbox to enable or disable all types at once. | -| **Data Type** | The name of the sensitive data type. | -| **Description** | A short description of what the data type covers. | -| **MIP Label** | The MIP sensitivity label to apply when the data type is detected. Select a label from the dropdown, or select **— No Label —** to detect the data type without applying a label. Available only when a tenant is connected and labels are loaded. | -| **Status** | Reflects the current mapping state for the row. | - -### Status values - -| Status | Color | Meaning | -| --- | --- | --- | -| **No MIP Label** | Gray | No tenant is connected, or labels haven't loaded. No label can be assigned. | -| **Unmapped** | Yellow | A tenant is connected and labels are loaded, but no label is assigned to this data type. | -| **Mapped** | Green | A label is assigned and present in the connected tenant. | -| **Label Missing** | Red | A label was previously assigned but no longer exists in MIP. Update or clear the mapping. | - -### Enable data types - -1. In the Sensitive Data Types table, select the checkbox next to each data type you want to activate. - - To activate all data types at once, select the checkbox in the table header. - - To deactivate all data types at once, clear the header checkbox when all types are selected. -2. Click **Save Configuration**. - -### Assign MIP labels - -You can assign a MIP label to each enabled data type. When Access Analyzer finds a file that matches a data type, it applies the mapped label to that file according to the label handling behavior settings. - -1. Connect a tenant in the MIP Configuration section and wait for labels to load. -2. In the **MIP Label** column for a data type, select a label from the dropdown. - - Labels are grouped into **Default Labels** (Personal, Public, General, Confidential) and **Custom Labels** (labels specific to your organization). - - Select **— No Label —** to detect the data type without applying a label. -3. Repeat for each data type you want to map. -4. Click **Save Configuration**. - -:::note -Enabling a data type and assigning a label are independent. Even without an assigned label, Access Analyzer still detects the data type during scans — it identifies matching files but doesn't apply a MIP label to them. -::: - -## OCR - -The **Run OCR to improve classification of images** option enables optical character recognition during scans. When enabled, Access Analyzer extracts text from images, screenshots, and scanned documents and applies the same classification rules to that text. - -Enabling OCR increases scan processing time. - -1. Select or clear the **Run OCR to improve classification of images** checkbox. -2. Click **Save Configuration**. - -## Label handling behavior - -The **Label Settings** drawer controls whether Access Analyzer writes MIP sensitivity labels back to files during sensitive data scans, and how it handles files that already carry a label. To open it, click **Label Settings** in the upper-right corner of the Sensitive Data Types card. - -These settings apply globally, and you can override them per scan in the scan configuration. - -:::note -Label write-back applies to **File Server and SharePoint Online sensitive data scans only**. Entra ID and Active Directory scans don't support label application. -::: - -:::note -Label write-back only occurs when you meet **both** conditions: you map a MIP label to the detected data type in the Sensitive Data Types table, **and** you enable the relevant option in [Options](#options). All options are off by default, so Access Analyzer detects and classifies files but doesn't write any labels to them. -::: - -### Options - -**Clear label if no longer sensitive** -When enabled, Access Analyzer removes the MIP label from a file if a subsequent scan finds the file no longer matches any enabled sensitive data type. Off by default. - -**Allow overwriting existing labels** -When enabled, Access Analyzer applies the mapped label to files that already have a MIP label assigned. When disabled, Access Analyzer skips files that already carry any MIP label — only unlabeled files receive a label. Off by default. - -- **Allow downgrading labels** *(requires Allow overwriting existing labels to be on)* - When enabled, Access Analyzer can replace a higher-priority label with a lower-priority one (for example, replacing "Confidential" with "General"). When disabled, Access Analyzer applies only upgrades or equal-priority replacements. This option is unavailable when **Allow overwriting existing labels** is off. Off by default. - -To configure label handling: - -1. Click **Label Settings**. -2. Select or clear the options as needed. -3. Click **Done** to close the drawer. -4. Click **Save Configuration** to apply all pending changes. - -## Save and cancel - -The **Save Configuration** and **Cancel** buttons are inactive until you make a change. - -- **Save Configuration** — saves all pending changes, including data type selections, MIP label mappings, the OCR setting, and label handling behavior. -- **Cancel** — discards all pending changes and restores the form to the last saved state. - -:::note -If you navigate away from the page with unsaved changes, Access Analyzer displays a confirmation dialog before leaving. -::: diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json b/docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json deleted file mode 100644 index 25ffc0442b..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Service Accounts", - "position": 10, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md deleted file mode 100644 index 8f8533f3af..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-certificate.md +++ /dev/null @@ -1,40 +0,0 @@ ---- -title: "Client ID/Certificate" -description: "Client ID and certificate credentials for SharePoint Online source groups" -sidebar_position: 4 ---- - -# Client ID/Certificate - -The Client ID/Certificate credential type authenticates with SharePoint Online using certificate-based authentication. Use this credential type when configuring SharePoint Online source groups. - -This requires a registered application in your Entra ID tenant. The source group wizard generates the certificate itself — you don't create or upload it here. - -## Create a Client ID/Certificate service account - -1. Navigate to **Configuration** > **Service Accounts**. -2. Click **Add Service Account**. -3. In the **Name** field, enter a descriptive name for this service account. -4. From the **Service account type** dropdown, select **Client ID/Certificate**. - - ![Add service account form showing Client ID/Certificate fields: name, client application ID, and tenant ID](/images/accessanalyzer/26.1/configurations/add-service-account-certificate.png) - -5. In the **Client Application ID** field, enter the Application (client) ID from your Entra ID app registration. -6. In the **Tenant ID** field, enter the Directory (tenant) ID of your Entra ID tenant. -7. Click **Add account**. - -## Fields - -| Field | Description | -| --- | --- | -| **Name** | A display name that identifies this service account in Access Analyzer. | -| **Client Application ID** | The Application (client) ID of your registered Entra ID application. Find this in the Azure portal under **Azure Active Directory** > **App registrations** > your app > **Overview**. | -| **Tenant ID** | The Directory (tenant) ID of your Entra ID tenant. Find this in the Azure portal under **Azure Active Directory** > **Overview**. | - -## Certificate - -You don't enter the certificate in the service account form. When you set up a SharePoint Online source group, the wizard includes a **Generate and Download Certificate** step that creates the certificate and downloads it to your machine. You then upload the certificate to your registered Entra ID application in the Azure portal before testing the connection. - -If you update the service account on an existing source group, you must upload the new account's certificate to the registered app before saving. - -For steps to register the application and upload the certificate, see [SharePoint Online Connector Requirements](../../connectors/sharepoint-online/overview.md). diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md b/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md deleted file mode 100644 index 7c08f48a0b..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/client-id-secret.md +++ /dev/null @@ -1,34 +0,0 @@ ---- -title: "Client ID/Secret" -description: "Client ID and secret credentials for Entra ID source groups" -sidebar_position: 3 ---- - -# Client ID/Secret - -The Client ID/Secret credential type authenticates with Microsoft Entra ID via the Microsoft Graph API. Use this credential type when configuring Entra ID source groups. - -This requires a registered application in your Entra ID tenant with the appropriate API permissions. - -## Create a Client ID/Secret service account - -1. Navigate to **Configuration** > **Service Accounts**. -2. Click **Add Service Account**. -3. In the **Name** field, enter a descriptive name for this service account. -4. From the **Service account type** dropdown, select **Client ID/Secret**. - - ![Add service account form showing Client ID/Secret fields: name, client application ID, and client secret](/images/accessanalyzer/26.1/configurations/add-service-account-client-secret.png) - -5. In the **Client Application ID** field, enter the Application (client) ID from your Entra ID app registration. -6. In the **Client Secret** field, enter a client secret value generated for the registered application. -7. Click **Add account**. - -## Fields - -| Field | Description | -| --- | --- | -| **Name** | A display name that identifies this service account in Access Analyzer. | -| **Client Application ID** | The Application (client) ID of your registered Entra ID application. Find this in the Azure portal under **Azure Active Directory** > **App registrations** > your app > **Overview**. | -| **Client Secret** | A client secret generated for the registered application. Create one in the Azure portal under your app's **Certificates & secrets**. | - -For steps to register the application and grant the required API permissions, see [Entra ID Requirements](../../connectors/entra-id/overview.md). diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/overview.md b/docs/accessanalyzer/26.1/configurations/service-accounts/overview.md deleted file mode 100644 index ccba4dfcc4..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/overview.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Overview" -description: "How service accounts work in Access Analyzer and which credential type each data source requires" -sidebar_position: 1 ---- - -# Overview - -Service accounts store the credentials Access Analyzer uses to authenticate against data sources during scans. Each data source connector requires a specific credential type, and the source group wizard automatically selects the correct type when you set up a new source group. - -Navigate to **Configuration** > **Service Accounts** to manage service accounts. - -![Service Accounts list showing existing accounts by name, type, source group, and creation date](/images/accessanalyzer/26.1/configurations/service-accounts-list.png) - -## Credential types by data source - -| Data Source | Credential Type | -| --- | --- | -| Active Directory | [Username and Password](./username-password.md) | -| File Server | [Username and Password](./username-password.md) | -| Entra ID | [Client ID/Secret](./client-id-secret.md) | -| SharePoint Online | [Client ID/Certificate](./client-id-certificate.md) | -| SSH-based sources | [SSH Username/Key](./ssh-username-key.md) | - -## Creating a service account - -You can create a service account in two ways: - -- **In advance from Configuration** — Navigate to **Configuration** > **Service Accounts** and click **Add Service Account**. Select the credential type and enter the required fields. -- **Inline during source group setup** — Click **+** next to the **Service Account** field in the source group wizard. The wizard locks the credential type to match the connector being configured. - -## Editing service accounts - -Access Analyzer never pre-populates credential fields — passwords and client secrets — when you edit an existing service account. You must re-enter them each time you save changes. - -Updating the service account on an existing source group replaces the credentials used for all future scans in that source group. Ensure the replacement account has the required permissions before saving. diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md b/docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md deleted file mode 100644 index ce21ae278c..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/ssh-username-key.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: "SSH Username/Key" -description: "SSH username and private key credentials for source groups that require SSH-based authentication" -sidebar_position: 5 ---- - -# SSH Username/Key - -The SSH Username/Key credential type authenticates using an SSH username and private key. Use this credential type for source groups that connect to hosts over SSH. - -## Create an SSH Username/Key service account - -1. Navigate to **Configuration** > **Service Accounts**. -2. Click **Add Service Account**. -3. In the **Name** field, enter a descriptive name for this service account. -4. From the **Service account type** dropdown, select **SSH Username/Key**. - - ![Add service account form showing SSH Username/Key fields: name, SSH username, and SSH key](/images/accessanalyzer/26.1/configurations/add-service-account-ssh.png) - -5. In the **SSH Username** field, enter the username for the SSH account. -6. In the **SSH Key** field, paste the SSH private key. -7. Click **Add account**. - -## Fields - -| Field | Description | -| --- | --- | -| **Name** | A display name that identifies this service account in Access Analyzer. | -| **SSH Username** | The username of the SSH account on the target host. | -| **SSH Key** | The SSH private key used to authenticate. Paste the full private key including the header and footer lines. | diff --git a/docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md b/docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md deleted file mode 100644 index 13d54dd8a7..0000000000 --- a/docs/accessanalyzer/26.1/configurations/service-accounts/username-password.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Username and Password" -description: "Username and password service accounts for Active Directory and file server source groups" -sidebar_position: 2 ---- - -# Username and Password - -Active Directory and file server source groups use the Username and Password credential type. Both require a domain account whose credentials Access Analyzer uses to connect and authenticate during scans. - -## Create a Username/Password service account - -1. Navigate to **Configuration** > **Service Accounts**. -2. Click **Add Service Account**. -3. In the **Name** field, enter a descriptive name for this service account. -4. From the **Service account type** dropdown, select **Username/Password**. - - ![Add service account form showing Username/Password fields: name, username, and password](/images/accessanalyzer/26.1/configurations/add-service-account-username-password.png) - -5. In the **Username** field, enter the domain account in `DOMAIN\username` or `username@domain` format. -6. In the **Password** field, enter the account password. -7. Click **Add account**. - -## Fields - -| Field | Description | -| --- | --- | -| **Name** | A display name that identifies this service account in Access Analyzer. | -| **Username** | The domain user account in `DOMAIN\username` or `username@domain` format. | -| **Password** | The password for the domain account. | - -## Active Directory - -Active Directory source groups use the service account to connect to domain controllers over LDAP or LDAPS and read directory objects. The account must have Read access to the Active Directory directory tree. - -For full permission requirements, see [Active Directory Connector Requirements](../../connectors/activedirectory.md). - -## File Server - -File server source groups use the service account to connect to Windows file servers over SMB and enumerate shares, permissions, and file contents. The account must be a member of the same domain as the target file servers. The specific permissions required depend on the scan types you enable — access scanning and sensitive data scanning have different requirements. - -For full permission requirements, see [CIFS / SMB File Share](../../connectors/file-servers/cifs.md). diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/_category_.json b/docs/accessanalyzer/26.1/configurations/source-groups/_category_.json deleted file mode 100644 index e3bbafe95d..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Source Groups", - "position": 20, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md b/docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md deleted file mode 100644 index cb16302bb1..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scan-executions.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Scan Executions" -description: "Understanding scan execution status and history in Access Analyzer" -sidebar_position: 3 ---- - -# Scan Executions - -A scan execution is a single run of a scan at a specific point in time. Each time Access Analyzer runs a scan — whether triggered by a schedule or manually — it creates a new scan execution record. Access Analyzer retains execution history per source so you can review past run outcomes. - -Scan executions are distinct from scan configurations. The [scan configuration](scans.md) defines what to collect and when. The scan execution records what happened during a specific run. - -## Execution status values - -| Status | Meaning | -| --- | --- | -| **Pending** | The execution is queued and waiting to start. This occurs when the Max Concurrent Scans limit is reached and additional executions are waiting their turn. | -| **Running** | The scanner is actively collecting data from the source. | -| **Pausing** | A pause was requested. The execution is finishing its current operation before pausing. | -| **Paused** | The execution has paused mid-run and can be resumed. | -| **Resuming** | A resume was requested. The execution is restarting from where it paused. | -| **Stopping** | A stop was requested. The execution is finishing its current operation before terminating. | -| **Post-processing** | Data collection is complete. Results are being processed and written to the database. | -| **Completed** | The execution finished successfully. | -| **Stopped** | The execution was manually stopped before completing. Partial results may have been collected. | -| **Cancelled** | The execution was cancelled before it started or early in the run. No results were collected. | -| **Failed** | The execution encountered an error and didn't complete. Check the execution log for details. | - -## Source group scan status - -The source groups list displays an aggregate scan status for each group. Access Analyzer computes this from the most recent scan execution across all sources in the group, using the following priority order: - -1. **Paused** — One or more sources has a paused execution, and none are running. -2. **Running** — One or more sources has an execution in a pending, running, pausing, resuming, stopping, or post-processing state. -3. **Failed** — One or more sources has a failed execution, and none are running or paused. -4. **Completed** — All sources have completed their most recent execution successfully. -5. **Completed with errors** — One or more sources has a stopped or cancelled execution, and none meet the preceding criteria. -6. **Not run yet** — No scan executions exist for any source in the group. - -This means a group shows **Running** even if only one source is actively scanning, and it shows **Failed** only when no scans are still in progress. - -## Blocked operations during active executions - -Access Analyzer blocks several operations while a source has an execution in an active state (pending, running, pausing, paused, resuming, stopping, or post-processing): - -- **Deleting a source group** — Stop all active scans before deleting the group. -- **Removing a source from a group** — Stop the source's active scan before removing it. - -Wait for the execution to reach a terminal state (completed, stopped, cancelled, or failed), or use the **Stop** action to terminate it, before proceeding with the blocked operation. diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md deleted file mode 100644 index 8aab2b0e06..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/best-practices.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: "Scanner Best Practices" -description: "Best practices for configuring and running scanners in Access Analyzer" -sidebar_position: 50 ---- - -# Scanner Best Practices - -## Use scanner labels to isolate scan traffic - -Scanner labels route scan executions to specific scanner pools. Use them to keep scan traffic between environments isolated and prevent resource contention. - -Common labeling patterns: - -| Use case | Example label | -|----------|---------------| -| Separate production and non-production scanning | `environment=production`, `environment=staging` | -| Route by geographic region | `region=us-east`, `region=eu-west` | -| Dedicate scanners to high-sensitivity source groups | `tier=restricted` | - -Define a labeling scheme before deploying scanners and apply it consistently. All scan executions in a source group use the labels assigned to that group — you don't need to set them per source. - -### Label matching behavior - -When a source group has multiple labels configured, Access Analyzer routes a scan to any scanner that matches **at least one** of those label pairs — not all of them. Design your label scheme with this in mind: a scanner carrying `region=us-east` will receive jobs from a source group labeled `region=us-east, tier=restricted` even if the scanner doesn't carry the `tier=restricted` label. - -For strict isolation, use a single label per source group or ensure scanners are labeled precisely to match only the intended groups. - -### Label key and value constraints - -Label keys and values entered in the Deploy Scanner wizard must follow these rules: - -| Field | Allowed characters | Max length | -|-------|-------------------|------------| -| Key | Letters, digits, hyphens | 53 characters | -| Value | Letters, digits, hyphens, underscores, dots | 63 characters | - -Both key and value must start with a letter or digit. Access Analyzer stores labels with a `dspm.netwrix.com/scanner-` prefix internally — you don't need to include this prefix when entering labels in the wizard. - -:::note -Access Analyzer reserves the label `scanner-default` for the built-in system scanner; you can't apply it to custom scanners. -::: - -## Plan for scanner redundancy - -Assign the same label to multiple scanners that cover the same environment. Scanners sharing a label form a pool, and Access Analyzer routes each scan job to any available scanner in the pool. If one scanner is offline, unhealthy, or busy, the job routes to another scanner carrying the same label automatically. - -A single scanner per label is a single point of failure. For production environments, deploy at least two scanners per label. This also distributes scan load across the pool when multiple source groups target the same label simultaneously. - -## Set Workers conservatively - -The **Workers** setting controls the number of concurrent enumeration threads a scan uses when reading from a target. The default is `3` and the valid range is `1–20`. - -Start at the default and increase only after validating that the target environment can handle parallel connections. - -Before increasing Workers: - -- Confirm the domain controller, file server, or other target can sustain simultaneous authenticated connections without degraded performance. -- Verify the network path between the scanner and the target has sufficient bandwidth for parallel data transfer. -- Consider the number of source groups that may run at the same time — multiple groups can run simultaneously across the same scanner, multiplying the actual connection count on the target. - -A safe approach is to increase by 2–3 at a time and monitor scan completion times and target resource utilization before increasing further. - -## Monitor scanner health - -Check the Scanners page regularly to review scanner health status. A scanner in Warning state is under resource pressure — disk, memory, or CPU — and scan performance may degrade. A scanner in Error state has reported health issues and needs investigation before running additional scans. - -Common causes of Warning and Error states: - -- Disk space consumed by k3s container images or log files — clean up unused images if disk pressure is persistent -- Memory pressure from running multiple large scans in parallel — reduce Workers or stagger scan schedules -- Network connectivity issues between the scanner host and the Access Analyzer server on port 6443 - -See [Manage Scanners](./manage-scanners.md) for a full reference of health status values. - -## Group sources by environment and sensitivity - -Group sources that share the same operational profile — same environment (production vs. staging), same geographic location, and similar sensitivity level. Avoid mixing high-sensitivity and low-priority sources in a single group. - -This lets you assign dedicated scanner pools and service accounts to each group based on security requirements, and keeps aggregate scan status meaningful. - -## Use least-privilege service accounts - -Each source group requires a service account for authentication against the targets it scans. Assign an account that has only the permissions required for the connectors in that group. - -- Don't share a single service account across source groups that scan different environments. -- Don't reuse a service account between source groups with different sensitivity levels. -- Review service account permissions when adding new sources to an existing group — the account must have access to each new source. - -## Follow a consistent naming convention - -Source group names appear in the list view, in scan execution logs, and in reporting. A consistent naming convention makes groups easier to identify and manage. - -A useful pattern: `--`. For example: - -- `ad-production-us-east` -- `fileserver-staging-eu-west` -- `fileserver-production-eu-central` - -Names are case-insensitive and must be unique across all source groups. Avoid names that embed credentials, IP addresses, or other values that change over time. diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md deleted file mode 100644 index 3838a52a4c..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/deploy-scanner.md +++ /dev/null @@ -1,77 +0,0 @@ ---- -title: "Deploy a Scanner" -description: "Register a custom scanner node in Access Analyzer" -sidebar_position: 30 ---- - -# Deploy a Scanner - -Deploying a scanner registers a remote Linux host as a custom scanner node in Access Analyzer. After deployment, the scanner appears in the Scanners table and becomes available for selection in source group configuration. - -## Before you begin - -- Confirm the scanner host meets all [requirements](./requirements.md). -- Create an **SSH Username / SSH Key** service account in Access Analyzer with access to the scanner host. You can also create it inline during the wizard — see step 7. -- Have the scanner host's public SSH host key ready. You can retrieve it by running the following command from any machine that can reach the host, replacing `` with the scanner's hostname or IP address: - - ```bash - ssh-keyscan - ``` - - Copy the line that begins with the host's address followed by the key type (for example, `ecdsa-sha2-nistp256`) and the key value. - -## Deploy the scanner - -1. Navigate to **Configuration** > **Scanners**. -2. Click **Deploy Scanner**. The Deploy Scanner drawer opens. -3. In the **Name** field, enter a display name for the scanner (for example, `Production Scanner`). This name identifies the scanner in the Scanners table and in source group configuration. -4. In the **SSH Host** field, enter the hostname or IP address of the scanner host (for example, `node01.company.com` or `192.168.1.50`). -5. In the **SSH Host Key** field, paste the public SSH host key you retrieved during preparation. Access Analyzer uses this key to verify the host identity during registration. -6. In the **SSH Port** field, enter the SSH port if your scanner host uses a non-standard port. Defaults to `22` if left blank. -7. In the **Service Account** dropdown, select the SSH Username / SSH Key account that has access to the scanner host. - - - To create a new service account without leaving the wizard, click **+** next to the dropdown. The wizard pre-sets the account type to SSH Username / SSH Key. After saving, it automatically selects the new account and preserves all other fields. - - To edit the selected account, click the pencil icon. The SSH key field is blank in edit mode — you must re-enter the private key before saving. - -8. Under **Labels**, add at least one label. You must add at least one label before you can deploy the scanner — the **Deploy** button remains disabled until you apply a label. - - - Enter a key and a value, then click **Add**. The label appears as a chip. - - To add additional labels, repeat the process. - - To remove a label, click the **×** on its chip. - - Access Analyzer automatically normalizes label keys and values to lowercase and converts spaces to hyphens. - - :::tip - Previously used labels appear as chips you can click to pre-fill the key and value fields. This helps you apply consistent labels across multiple scanners. - ::: - -9. Optionally, click **Test connection** to verify that Access Analyzer can reach the scanner host over SSH before deploying. A green indicator confirms connectivity; a red indicator with a message identifies the problem. - -10. Click **Deploy**. Access Analyzer connects to the scanner host over SSH and runs the registration script. - -## What happens during registration - -Registration runs automatically and typically completes within five minutes. During registration, Access Analyzer: - -1. Runs a preflight check on the scanner host to verify it meets all requirements (curl, bash, passwordless sudo, disk space, memory, and CPU). -2. Downloads and installs k3s (a lightweight Kubernetes distribution) on the scanner host. -3. Joins the scanner host to the Access Analyzer Kubernetes cluster as a worker node. -4. Applies the labels you specified. - -If registration takes longer than five minutes, check network connectivity and confirm the scanner host can reach `https://get.k3s.io`. Slow networks or resource-constrained hosts may require additional time. - -## After deployment - -The scanner appears immediately in the Scanners table. Its health status shows **Healthy** when the node has fully joined the cluster. - -To use the scanner, assign it to a source group by selecting **Custom scanner** under **Scanner Location** when setting up or editing a source group, and matching its label. See [Set Up File Server Source Group](../../../gettingstarted/file-servers/set-up-source-group.md) or the equivalent guide for your connector. - -## Edit a scanner - -To update a scanner's labels or service account after deployment: - -1. Navigate to **Configuration** > **Scanners**. -2. Click the edit icon on the scanner row. The Deploy Scanner drawer opens with the scanner's current configuration pre-filled. -3. Update the labels or service account as needed. -4. Click **Save Changes**. - -Changes appear immediately in the Scanners table and in the scanner selection dropdown in source group configuration. diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md deleted file mode 100644 index f0461512dd..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/manage-scanners.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "Manage Scanners" -description: "View scanner health, edit scanner configuration, and delete scanners in Access Analyzer" -sidebar_position: 40 ---- - -# Manage Scanners - -The Scanners page lists all registered scanner nodes and their current status. Navigate to **Configuration** > **Scanners** to access it. - -## Scanners table - -Each row in the table represents one registered scanner. - -| Column | Description | -|--------|-------------| -| Name / IP | Hostname or IP address of the scanner host | -| Labels | Labels assigned to the scanner, displayed as chips. If a scanner has more than two labels, the first two are shown with an overflow count (for example, **+3**). Hover over the count to see all labels. | -| Source Groups | Number of source groups that target this scanner | -| Sources | Total number of sources assigned to this scanner | -| Scanning | Number of sources being scanned at this time | -| Health Status | Current health of the scanner node | -| Scan Status | Whether the scanner is idle or actively running a scan | -| Version | Scanner software version. If an update is available, an **Update** action appears. | - -## Health status - -| Status | Color | Meaning | -|--------|-------|---------| -| Healthy | Green | The scanner node is reachable and operating normally | -| Warning | Yellow | The node is reachable but under resource pressure (disk, memory, or CPU) | -| Error | Red | The node is reachable but in an unhealthy state | -| Offline | Gray | The node isn't reachable from the Access Analyzer server | - -Scans may perform poorly on a scanner in Warning state — consider resolving the resource pressure before scheduling large scans. Investigate the scanner host when the status is Error. An Offline scanner can't run scans — source groups that target it will not execute until the scanner comes back online or a different scanner with the matching label becomes available. - -## Scan status - -| Status | Color | Meaning | -|--------|-------|---------| -| Idle | Gray | No scans are running on this scanner | -| In Progress | Blue | One or more scans are running | - -## Search scanners - -Use the search field at the top of the page to filter the scanner list. The search matches against scanner names, IP addresses, and label values. Results update as you type. - -## Connect a scanner to source groups - -If a scanner has no associated source groups, a **+ Connect source** action appears on its row. Click it to assign source groups that will use this scanner. - -To route scans from a source group to a specific scanner or scanner pool, set the scanner location when configuring the source group. Match the source group's scanner selection to the label on the scanner you want to use. - -## Delete a scanner - -:::warning -Deleting a scanner removes it from the cluster. Source groups that target the deleted scanner's labels will not be able to run scans unless another scanner with the same labels is available. -::: - -To delete a scanner: - -1. Navigate to **Configuration** > **Scanners**. -2. Click the delete icon on the scanner row. -3. Confirm the deletion. - -You can only delete a scanner when no scan jobs are running on it. If scans are in progress, wait for them to complete before deleting. You can't delete the system scanner (built-in scanner on the Access Analyzer server). diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md deleted file mode 100644 index a3ff3a1650..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/overview.md +++ /dev/null @@ -1,65 +0,0 @@ ---- -title: "Scanners Overview" -description: "Overview of scanner types, architecture, and how to use them in Access Analyzer" -sidebar_position: 10 ---- - -# Scanners Overview - -Scanners are the execution nodes that run scan workloads in Access Analyzer. Every scan runs on a scanner — either the built-in system scanner or a custom scanner you deploy on a remote host. - -## Scanner types - -Access Analyzer provides two scanner types: - -**System scanner** — The built-in scanner that runs on the Access Analyzer server itself. It's available immediately with no configuration and is the default for all source groups. Use it when the Access Analyzer server can reach your target resources directly over the network. - -**Custom scanners** — Scanners you deploy on separate Linux hosts closer to your data sources. Use custom scanners when: - -- Target file servers or Active Directory domain controllers are in network segments the Access Analyzer server can't reach directly -- You want to reduce scan traffic over wide area network (WAN) links between sites -- You need to distribute scan load across multiple machines for large environments - -## Supported connectors - -Scanners are available for the following connectors: - -- Active Directory -- File Server (all supported file server types) - -Entra ID and SharePoint Online connectors connect directly from the Access Analyzer service and don't use scanners. - -## Architecture - -Scanners run as Kubernetes Jobs — short-lived containers that start on demand to perform a scan and terminate when the scan completes. There is no persistent agent process running on the scanner host between scans. - -Custom scanner hosts join the Access Analyzer Kubernetes cluster as worker nodes during deployment. Access Analyzer schedules scan jobs to those nodes using standard Kubernetes job dispatch. The scanner host needs outbound connectivity to the Access Analyzer server on port 6443 (Kubernetes API) to receive and run jobs. - -This is a different architecture from the Proxy and Applet modes in legacy Netwrix Access Analyzer (NAA) v12: - -| | Legacy NAA (v12) | Access Analyzer | -|---|---|---| -| Distributed scanning | Proxy server / applet deployment | Kubernetes-deployed scanner containers | -| Deployment model | Manual, persistent agent | On-demand Kubernetes Jobs | -| Supported targets | All file system types | Active Directory, all supported file server types | - -## Scanner labels - -Labels are key-value pairs you assign to custom scanners. Source groups use labels to target specific scanners or scanner pools — scans from that source group run only on scanners that carry matching labels. - -Labels let you: - -- Isolate scan traffic by environment (`environment=production`, `environment=staging`) -- Route scans to geographically local scanners (`region=us-east`, `region=eu-west`) -- Dedicate scanners to high-sensitivity source groups (`tier=restricted`) - -Every custom scanner requires at least one label. Multiple scanners can share the same label — when a source group targets a label that multiple scanners carry, any of those scanners can run the job. - -The system scanner doesn't use labels. Selecting **System scanner** in a source group always uses the built-in scanner on the Access Analyzer server. - -## Related pages - -- [Requirements](./requirements.md) — System requirements for deploying a custom scanner -- [Deploy a Scanner](./deploy-scanner.md) — Register a new custom scanner -- [Manage Scanners](./manage-scanners.md) — View health, edit, and delete scanners -- [Best Practices](./best-practices.md) — Labeling schemes, concurrency, and naming conventions diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md b/docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md deleted file mode 100644 index dbb0260d36..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scanners/requirements.md +++ /dev/null @@ -1,77 +0,0 @@ ---- -title: "Scanner Requirements" -description: "System requirements and prerequisites for deploying a custom scanner in Access Analyzer" -sidebar_position: 20 ---- - -# Scanner Requirements - -These requirements apply to any Linux host you want to register as a custom scanner. The system scanner built into Access Analyzer has no additional requirements. - -## Operating system - -Access Analyzer supports any Linux distribution as a scanner host. Netwrix recommends Ubuntu 20.04 LTS or later. - -Access Analyzer registers the scanner by connecting over SSH and running an automated installation script. The script installs [k3s](https://k3s.io/) — a lightweight Kubernetes distribution — and joins the host to the Access Analyzer cluster as a worker node. - -## Hardware - -| Resource | Minimum | -|----------|---------| -| CPU | 2 cores | -| Available RAM | 512 MB | -| Free disk space | 5 GB (on `/`) | - -## Software and access - -The registration script runs automatically over SSH. Before registering a scanner, confirm the following on the target host: - -- `curl` is installed -- `bash` is installed -- The SSH service account used during registration has passwordless `sudo` access - -### Preflight checks - -When you click **Deploy** in the Deploy Scanner wizard, Access Analyzer runs the following preflight checks on the target host before installing k3s. All checks must pass for registration to proceed. - -| Check | Requirement | -|-------|-------------| -| `curl` available | `curl` must be installed and on the system PATH | -| `bash` available | `bash` must be installed and on the system PATH | -| Passwordless sudo | The SSH service account must be able to run `sudo` without a password prompt | -| Internet access | The host must be able to reach `https://get.k3s.io` to download the k3s installer | -| Disk space | At least 5 GB free on `/` | -| Memory | At least 512 MB available RAM | -| CPU | At least 2 CPU cores | - -## Network requirements - -### Ports - -| Port | Protocol | Direction | Purpose | -|------|----------|-----------|---------| -| 22 | TCP | Access Analyzer → Scanner | SSH connection during registration only | -| 6443 | TCP | Scanner → Access Analyzer | Kubernetes API — ongoing job dispatch | - -Access Analyzer only requires port 22 during the initial registration. After registration completes, the scanner host connects outbound to the Access Analyzer server on port 6443 to receive and run scan jobs. You can restrict or close port 22 after registration completes. - -:::note -The SSH port defaults to **22** but is configurable in the Deploy Scanner wizard. If your scanner host runs SSH on a non-standard port, enter it in the **SSH Port** field during deployment. -::: - -### Internet access - -The registration script downloads the k3s installer from `https://get.k3s.io`. The scanner host must be able to reach this URL **during registration only**. After registration completes, normal scan operation doesn't require internet access. - -## Service account - -Scanner deployment requires an **SSH Username / SSH Key** service account in Access Analyzer. This account must: - -- Have SSH access to the scanner host -- Use an **unencrypted** private key in PEM format - -:::warning -Access Analyzer doesn't support passphrase-protected private keys. The registration script will fail if the key requires a passphrase. Use a key generated without a passphrase, or strip the passphrase before creating the service account. -::: - -See [SSH Username / SSH Key](../../service-accounts/ssh-username-key.md) to create this account. You can also create it inline from the Deploy Scanner wizard using the **+** button next to the Service Account field without navigating away. diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/scans.md b/docs/accessanalyzer/26.1/configurations/source-groups/scans.md deleted file mode 100644 index 834c3abccc..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/scans.md +++ /dev/null @@ -1,108 +0,0 @@ ---- -title: "Scans" -description: "Scan types, configuration, scheduling, and scan location in Access Analyzer source groups" -sidebar_position: 2 ---- - -# Scans - -A scan defines what Access Analyzer collects from a source and how often it runs. Each source in a group can have one or more scans, one per scan type. Scans are persistent configurations — each run of a scan produces a [scan execution](scan-executions.md). - -## Scan types - -The scan types available depend on the source type: - -| Source Type | Available Scan Types | -| --- | --- | -| **File Server** | Access Scan, Sensitive Data Scan | -| **SharePoint Online** | Access Scan, Sensitive Data Scan | -| **Active Directory** | Active Directory Inventory | -| **Entra ID** | Users, Groups, and Roles | - -### Access Scan - -Enumerates permissions, folder-level ACLs, sharing links, and access rights across File Server and SharePoint Online sources. Identifies who has access to what across your data sources. - -Access scans include a **concurrent** option that scans multiple file paths or objects within a single source in parallel. Enable this when scanning large file servers or SharePoint sites to reduce total scan time. - -### Sensitive Data Scan - -Classifies file and document content against the detection patterns configured under **Configuration** > **Sensitive Data**. Identifies files containing PII, PHI, credentials, financial records, and other sensitive data across File Server and SharePoint Online sources. - -Sensitive Data Scans include a **concurrent** option that classifies multiple files simultaneously within a single source. Enable this on sources with large file counts to improve throughput. - -### Active Directory Inventory - -Synchronizes users, groups, group memberships, and security-relevant attributes from Active Directory domains. Access Analyzer uses the inventory to resolve identity information across all other scan types and to populate the Active Directory dashboard. - -### Users, Groups, and Roles - -Synchronizes users, groups, and role assignments from your Microsoft Entra ID (Azure AD) tenant. This scan type also collects Microsoft Information Protection (MIP) sensitivity labels applied across the tenant. - -## Scan configuration - -When you create a source group, the setup wizard collects scan parameters on page 3 and creates scan configurations that apply to all sources added to the group. Each scan configuration includes: - -- **Scan type** — the type of scan to run (see [Scan types](#scan-types)) -- **Concurrent** — whether to parallelize scanning within a single source (Access Scan and Sensitive Data Scan only) -- **Scan location** — which scanner handles the scan (see [Scan location](#scan-location)) -- **Schedule** — when and how often the scan runs automatically (see [Schedule](#schedule)) -- **Scan parameters** — source-type-specific settings such as scope, depth, and included paths. These vary by connector. - -Individual sources can override the group-level scan configuration if their requirements differ from the group default. - -## Scan location - -The **Scan location** setting determines which scanner component executes the scan. You configure it per scan type during source group creation. - -| Location | Description | Applicable Source Types | -| --- | --- | --- | -| **System scanner** | The Access Analyzer service connects directly to the source. This is the default and requires no additional configuration. | Entra ID, SharePoint Online | -| **Scanner label** | Routes the scan to a registered edge scanner pool that matches the specified label. The edge scanner connects to the source on behalf of Access Analyzer. | Active Directory, File Server | - -For Active Directory and File Server source groups, selecting a scanner label routes all scans in that group to the matching edge scanner pool. If no edge scanners carry that label, the scan can't run. See [Scanners](scanners/overview.md) for setup and label management. - -:::note -Entra ID and SharePoint Online source groups always use the system scanner. The scan location setting isn't configurable for those source types. -::: - -## Schedule - -The schedule determines when a scan runs automatically. You configure the schedule on page 3 of the source group creation wizard. The same scheduling options are available for all source types and scan types. - -### Scheduling options - -| Option | Description | -| --- | --- | -| **Run scan now** | Starts the scan immediately when you save the source group. No recurring schedule applies. | -| **Run scan at** | Schedules a single one-time run at a specific date and time. The scan doesn't repeat after that run. | -| **Advanced** | Sets a recurring schedule using a cron expression. Use this for daily, weekly, or custom interval schedules. | - -### Cron schedule format - -Advanced scheduling uses standard 5-field cron syntax: - -``` -┌───── minute (0–59) -│ ┌───── hour (0–23) -│ │ ┌───── day of month (1–31) -│ │ │ ┌───── month (1–12) -│ │ │ │ ┌───── day of week (0–6, Sunday = 0) -│ │ │ │ │ -* * * * * -``` - -**Examples:** - -| Expression | Schedule | -| --- | --- | -| `0 2 * * *` | Daily at 2:00 AM | -| `0 2 * * 0` | Weekly on Sunday at 2:00 AM | -| `0 2 1 * *` | Monthly on the 1st at 2:00 AM | -| `0 */6 * * *` | Every 6 hours | - -Access Analyzer evaluates schedule times in the server's local timezone. - -:::note -If you don't configure a schedule, the scan doesn't run automatically. Run it manually from the source groups list using the **Run** action. -::: diff --git a/docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md b/docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md deleted file mode 100644 index 3a208b6b43..0000000000 --- a/docs/accessanalyzer/26.1/configurations/source-groups/source-groups.md +++ /dev/null @@ -1,100 +0,0 @@ ---- -title: "Source Groups" -description: "Managing source groups in Access Analyzer — create, configure, and operate groups of data sources" -sidebar_position: 1 ---- - -# Source Groups - -A source group is a named container that organizes data sources of the same type for coordinated scanning. All sources in a group share a service account, and you can run or stop scans across all sources in the group with a single action. - -Navigate to **Configuration** > **Source Groups** to view, create, and manage source groups. - -## Source groups list - -The source groups list displays all configured source groups. Each row shows: - -| Column | Description | -| --- | --- | -| **Name** | The source group name. | -| **Source Type** | The type of data source in the group (Active Directory, File Server, Entra ID, or SharePoint Online). | -| **Service Account** | The service account used to authenticate scans in this group. | -| **Status** | Whether the group is **Active** or **Inactive**. Inactive groups are excluded from scheduled scan runs. | -| **Scan Types** | The scan types configured for this group. Varies by source type — see [Scan types](scans.md#scan-types). | -| **Scanner Labels** | Key-value labels used to route scans to specific scanner pools. Displayed only for Active Directory and File Server groups. | -| **Last Scan** | The timestamp of the most recent completed scan execution across all sources in the group. | - -Use the search field to filter by name. You can sort by any column and filter by source type, status, service account, or scan status. - -## Create a source group - -1. Click **Add Source Group**. -2. Enter a **Name** and optional **Description**. Names must be unique (case-insensitive) and between 1 and 255 characters. -3. Select the **Source Type**. This value is permanent — you can't change it after you create the group. -4. Select or create a **Service Account**. The wizard filters available accounts to those compatible with the selected source type. To create a new account inline, click **+** next to the field. -5. For Active Directory and File Server groups, optionally add **Scanner Labels** to route scans to a specific scanner pool. See [Scanners](scanners/overview.md). -6. Add sources and configure scan parameters. You can also add sources later from the group detail view. -7. Click **Save**. - -:::warning -You can't change the source type after you create a source group. If you need a different source type, create a new source group and delete the original. -::: - -## Edit a source group - -1. In the source groups list, click the actions menu for a group and select **Edit**. -2. Modify any of the following fields: - - Name and description - - Service account - - Scanner labels - - Status (Active or Inactive) -3. Click **Save**. - -You can't change the source type. If you update the service account, the new credentials apply to all future scans in the group — verify the replacement account has the required permissions before saving. - -## Add sources to a group - -1. In the source groups list, click the actions menu for a group and select **View Sources**. -2. Click **Add Source**. -3. Complete the source configuration form. Required fields vary by source type. -4. Click **Save**. - -Sources you add inherit the group's service account and scan configuration unless you override them at the source level. - -## Remove sources from a group - -1. In the source groups list, click the actions menu for a group and select **View Sources**. -2. In the sources drawer, click the actions menu for a source and select **Remove**. - -You can't remove a source that has a scan in a pending, running, pausing, paused, resuming, stopping, or post-processing state. Wait for the scan to complete or stop it first. - -## Run scans - -To start scans across all sources in a group, click the **Run** button in the actions menu for the group. Access Analyzer queues scan executions for every configured scan in the group. - -To run scans for a single source, open the source from the **View Sources** drawer and use the source-level run action. - -## Stop scans - -To stop all running and pending scans in a group, click **Stop** in the actions menu. Access Analyzer sends a stop signal to every active scan execution in the group. Scans in a stopping or post-processing state continue until they reach a terminal state. - -## Delete a source group - -1. In the source groups list, click the actions menu for a group and select **Delete**. -2. Confirm the deletion. - -:::warning -Deleting a source group permanently deletes all sources it contains. You can't undo this action. -::: - -You can't delete a source group while any of its scans are in a pending, running, pausing, paused, resuming, stopping, or post-processing state. Stop all active scans before deleting. - -## Constraints - -| Setting | Constraint | -| --- | --- | -| **Name** | 1–255 characters; must be unique (case-insensitive) across all source groups | -| **Description** | Maximum 10,000 characters | -| **Source type** | Set at creation; can't be changed afterward | -| **Delete** | Blocked while any source has an active scan execution | -| **Remove source** | Blocked while that source has an active scan execution | diff --git a/docs/accessanalyzer/26.1/configurations/users.md b/docs/accessanalyzer/26.1/configurations/users.md deleted file mode 100644 index 6f9314f0d2..0000000000 --- a/docs/accessanalyzer/26.1/configurations/users.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: "Users" -description: "Managing users in the Configuration node" -sidebar_position: 70 ---- - -# Users - -The Users page lets you create and manage the accounts that have access to Netwrix Access Analyzer. Navigate to **Configuration** > **Users** to view and manage all users. - -:::note -This page is available to users with the **User Admin** or **Administrator** role. Users with the Viewer role can't access this page. -::: - -## Users list - -The users list displays all accounts in the system. Each row shows: - -| Column | Description | -| --- | --- | -| **Username** | The display name for the account. | -| **Email** | The email address used to sign in. | -| **Role** | The account's role: **Administrator**, **User Admin**, or **Viewer**. | -| **Status** | Whether the account is **Active** or **Inactive**. | -| **Last Login** | The date of the most recent successful sign-in, or **Never** if the user hasn't signed in yet. | - -Use the search field to filter by name or email. You can sort by any column. - -## Roles - -Access Analyzer has three roles: - -| Role | Description | -| --- | --- | -| **Administrator** | Full access: system configuration (sources, scans, connectors, application settings) and user management (create, edit, activate, deactivate, and delete users; assign roles; pre-provision federated users). | -| **User Admin** | User and role management rights only: create, edit, activate, deactivate, and delete users; assign roles; pre-provision federated users. Does **not** have system configuration rights. | -| **Viewer** | Read-only access to data and reports. No configuration or user management rights. | - -A user can only hold one role at a time. - -## Bootstrap admin account - -Access Analyzer seeds a built-in account, `admin@dspm.local`, during installation. Access Analyzer assigns this account the **User Admin** role for first-time user provisioning only. - -To retrieve the bootstrap admin password: - -```bash -sudo kubectl get secret -n access-analyzer dspm-bootstrap-admin \ - -o jsonpath='{.data.password}' | base64 -d; echo -``` - -On first login, Access Analyzer prompts you to enroll an authenticator app for MFA and set a display name. Don't change the email address. - -:::note -Keep the bootstrap account active as an emergency recovery account, but don't use it for routine user management. Create at least one named User Admin account during initial setup and use that account for ongoing administration. -::: - -For the full first-login walkthrough, see [Quick Install — Step 6](/docs/accessanalyzer/26_1/install/quickinstall#step-6-sign-in). - -## Recommended initial setup - -After installation, complete the following steps in order before handing the product to your team. - -| Step | Action | Notes | -| --- | --- | --- | -| **1** | Sign in as `admin@dspm.local` | Uses the bootstrap User Admin account. Retrieve the password using the kubectl command in [Bootstrap admin account](#bootstrap-admin-account). | -| **2** | Create at least one named **User Admin** | Provides a dedicated account for user management with no system configuration access. Use this account for ongoing user administration so that routine user changes don't require Administrator accounts. | -| **3** | Create at least one **Administrator** | Grants full access — system configuration and user management. This is typically the person responsible for setting up and maintaining the product. | -| **4** | Create **Viewer** accounts as needed | Optional. Add Viewer accounts for stakeholders who need read-only access to dashboards and reports. | -| **5** | Sign out of the bootstrap account | Do day-to-day work from named accounts. | - -## Add a user - -The form for adding a user differs depending on whether your deployment uses an external Identity Provider (IdP) for authentication. - -### Add a user (local authentication) - -Use this procedure when Access Analyzer manages passwords directly. - -1. Click **Add User**. -2. Enter a **Name**. Names must be between 2 and 100 characters. -3. Enter an **Email** address. Email addresses must be unique across all users (case-insensitive). -4. Select a **Role**: **Administrator**, **User Admin**, or **Viewer**. The default is **Viewer**, an intentionally conservative choice. Only assign Administrator or User Admin after confirming the user's responsibilities. -5. Enter a **Password** and confirm it. -6. Click **Create User**. - -Password requirements for local accounts: - -- Minimum 18 characters -- At least one uppercase letter (A–Z) -- At least one lowercase letter (a–z) -- At least one number (0–9) -- At least one special character (`!@#$%^&*(),.?":{}|<>`) -- Can't contain the user's email address -- Can't be a commonly used password - -### Add a user (Identity Provider) - -When you configure your deployment to use an external Identity Provider, you can pre-provision an account before the user's first sign-in. Access Analyzer creates the account record and links it to the user's IdP identity when they sign in for the first time. - -1. Click **Add User**. -2. Enter a **Name**. Names must be between 2 and 100 characters. -3. Enter an **Email** address. The email must match the address the user has in your IdP exactly, including case. -4. Select a **Role**: **Administrator**, **User Admin**, or **Viewer**. The default is **Viewer**, an intentionally conservative choice. Only assign Administrator or User Admin after confirming the user's responsibilities. -5. Click **Create User**. - -No password is required. The account is ready for the user to sign in through your IdP. - -:::note -If a user authenticates through your IdP without a pre-provisioned account in Access Analyzer, Access Analyzer blocks their sign-in and they see an access error. Pre-provision the account first, then the user can sign in successfully. -::: - -## Edit a user - -1. In the users list, click the actions menu for a user and select **Edit**. -2. Modify the fields as needed. -3. Click **Update User**. - -What you can change depends on the account type: - -| Account type | Editable fields | -| --- | --- | -| Local (password-based) | Name, Email, Role | -| Identity Provider — pre-provisioned (hasn't signed in yet) | Name, Email, Role | -| Identity Provider — provisioned (has signed in at least once) | Role only | - -Access Analyzer locks name and email for provisioned IdP accounts because those values come from the IdP token. To change them, update the user's profile in your IdP. - -## Activate a user - -1. In the users list, click the actions menu for an inactive user and select **Activate**. - -The account becomes active immediately. The user can sign in and use the application according to their assigned role. - -## Deactivate a user - -1. In the users list, click the actions menu for an active user and select **Deactivate**. - -Deactivating a user revokes all of their active sessions immediately. Access Analyzer preserves the account record; you can reactivate it later. - -:::note -You can't deactivate your own account or the last active User Admin account. -::: - -## Reset a user's password - -:::note -The **Reset Password** action is available for local accounts only. It doesn't appear for accounts that authenticate through an Identity Provider. -::: - -1. In the users list, click the actions menu for a user and select **Reset Password**. - -Access Analyzer generates a password reset token for the user. The user must set a new password before they can sign in again. Reset tokens expire after 2 hours. - -## Delete a user - -1. In the users list, click the actions menu for a user and select **Delete**. -2. Confirm the deletion. - -:::warning -Deleting a user is permanent; you can't undo it. -::: - -You can't delete your own account or the last active User Admin account. - -## Constraints - -| Setting | Constraint | -| --- | --- | -| **Name** | 2–100 characters | -| **Email** | Must be unique across all users (case-insensitive); must be a valid email address | -| **Role** | Administrator, User Admin, or Viewer; defaults to Viewer | -| **Password** | Minimum 18 characters; must include uppercase, lowercase, number, and special character; can't match the user's email; can't be a commonly used password | -| **Deactivate** | Blocked for your own account and the last active User Admin | -| **Delete** | Blocked for your own account and the last active User Admin | -| **Reset Password** | Local accounts only; tokens expire after 2 hours | diff --git a/docs/accessanalyzer/26.1/connectors/_category_.json b/docs/accessanalyzer/26.1/connectors/_category_.json deleted file mode 100644 index 67fabb3b53..0000000000 --- a/docs/accessanalyzer/26.1/connectors/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Connector Requirements", - "position": 14, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/connectors/activedirectory.md b/docs/accessanalyzer/26.1/connectors/activedirectory.md deleted file mode 100644 index 481abb347c..0000000000 --- a/docs/accessanalyzer/26.1/connectors/activedirectory.md +++ /dev/null @@ -1,48 +0,0 @@ ---- -title: "Active Directory" -description: "Requirements for the Active Directory connector" -sidebar_position: 30 ---- - -# Active Directory - -The Active Directory connector reads domain controllers remotely over LDAP to collect identity data from your Active Directory domains. The connector doesn't require agent installation on domain controllers. - -The connector collects: - -- Users (including disabled and stale accounts) -- Groups and group memberships (including nested groups and circular membership chains) -- Domains - -## Supported versions - -- Windows Server 2016 and later -- Windows Server 2003 forest functional level or higher - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must be a member of the domain you're scanning and have: - -- Read access to the directory tree -- List Contents and Read Property on the Deleted Objects container - -:::note -For information on granting access to the Deleted Objects container, see the Microsoft [Searching for Deleted Objects](https://technet.microsoft.com/en-us/library/cc978013.aspx) article and [Dsacls](https://technet.microsoft.com/en-us/library/cc771151(v=ws.11).aspx) reference. -::: - -### Ports - -Open the following ports on all domain controllers you want to scan: - -| Port | Protocol | Description | -|------|----------|-------------| -| 389 | TCP | LDAP | -| 636 | TCP | LDAPS (when SSL is enabled) | -| 135–139 | TCP | RPC | -| 49152–65535 | TCP | RPC dynamic ports | - -## Next steps - -After you meet the requirements, see [Set Up Active Directory Source Group](../gettingstarted/active-directory/set-up-source-group.md) to configure your first scan. diff --git a/docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md b/docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md deleted file mode 100644 index 998720b323..0000000000 --- a/docs/accessanalyzer/26.1/connectors/entra-id/app-registration-secret.md +++ /dev/null @@ -1,54 +0,0 @@ ---- -title: "Client Secret Configuration" -description: "Configure a client secret for the Microsoft Entra ID app registration" -sidebar_position: 30 ---- - -# Client Secret Configuration - -Access Analyzer authenticates to Microsoft Entra ID using a client secret. You generate the client secret within your registered Microsoft Entra ID application and provide it to Access Analyzer when configuring the Entra ID connector. - -## Generate a client secret - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. Navigate to **Identity** > **Applications** > **App registrations**. - -3. Click the **All applications** tab and select your registered application. - -4. Click **Certificates & secrets** under the Manage section. - -5. On the **Client secrets** tab, click **New client secret**. - -6. Specify the following: - - - **Description** — Enter a description for the secret - - **Expires** — Select an expiration period - -7. Click **Add**. Access Analyzer displays the client secret value in the **Value** column. - -:::warning -Copy the client secret value immediately. After you navigate away from this page, you can't retrieve the value and you'll need to create a new secret. -::: - -## Assign roles to the app - -You must assign the registered application to the **Global Administrator** role for Entra ID data collection. - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. Navigate to **Identity** > **Applications** > **App registrations**. - -3. Click the **All applications** tab and select your registered application. - -4. Click **Roles and administrators** under the Manage section. - -5. On the All roles page, search for **Global Administrator**. - -6. Click the **Global Administrator** role. The Assignments page opens. - -7. Click **Add assignments** in the top toolbar. - -8. Search for and select your registered application. - -9. Click **Add**. Access Analyzer lists the application on the Assignments page. diff --git a/docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md b/docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md deleted file mode 100644 index aea5e67688..0000000000 --- a/docs/accessanalyzer/26.1/connectors/entra-id/entra-requirements.md +++ /dev/null @@ -1,66 +0,0 @@ ---- -title: "Entra tenant requirements" -description: "Configure Microsoft Entra ID requirements for connectivity" -sidebar_position: 20 ---- - -# Entra tenant requirements - -Access Analyzer connects to Microsoft Entra ID through a registered application using OAuth2 client credentials. You must register a dedicated Microsoft Entra ID application for Access Analyzer and grant it the required permissions before adding Entra ID as a data source. - -:::note -You need a user account with the **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator** role to register an application and grant admin consent for permissions. -::: - -:::note -You must assign the registered application to the **Global Administrator** role for Entra ID data collection. -::: - -## Register an app in Microsoft Entra ID - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. On the left navigation menu, navigate to **Identity** > **Applications** > **App registrations**. - -3. On the App registrations page, click **New registration** in the top toolbar. - -4. Specify the following on the Register an application page: - - - **Name** — Enter a display name for the application, for example, *Access Analyzer Entra ID* - - **Supported account types** — Select **Accounts in this organizational directory only** - - **Redirect URI (optional)** — Leave blank - -5. Click **Register**. - -The Overview page for the newly registered application opens. Copy the following values — you'll need them when configuring the Entra ID connector in Access Analyzer: - -- **Application (client) ID** -- **Directory (tenant) ID** - -## Grant permissions to the app - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. Navigate to **Identity** > **Applications** > **App registrations**. - -3. Click the **All applications** tab and select the application you registered. - -4. Click **API permissions** under the Manage section. - -5. Click **Add a permission**. The Request API permissions pane opens. - -6. Click **Microsoft Graph**, then click the **Application permissions** tab. - -7. Select the required permissions (see [Required permissions](#required-permissions)). - -8. Click **Add Permissions**. - -9. Click **Grant admin consent for ``** to apply the permissions. - -### Required permissions - -| API | Permission | Description | -| --- | --- | --- | -| Microsoft Graph | `Directory.Read.All` | Read directory data — users, groups, and role assignments | -| Microsoft Graph | `Policy.Read.All` | Read your organization's policies | -| Microsoft Graph | `InformationProtectionPolicy.Read.All` | Read your organization's information protection policies — required for MIP label retrieval | diff --git a/docs/accessanalyzer/26.1/connectors/entra-id/overview.md b/docs/accessanalyzer/26.1/connectors/entra-id/overview.md deleted file mode 100644 index fd2a7c368a..0000000000 --- a/docs/accessanalyzer/26.1/connectors/entra-id/overview.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Entra ID" -description: "Requirements for connecting Access Analyzer to Microsoft Entra ID" -sidebar_position: 1 ---- - -# Entra ID - -Access Analyzer connects to Microsoft Entra ID using OAuth2 client credentials through a pre-configured Microsoft Entra ID application. It accesses Entra ID through Microsoft Graph to synchronize users, groups, role assignments, and Microsoft Information Protection (MIP) sensitivity labels. - -Before adding Entra ID as a data source, you must register a dedicated Microsoft Entra ID application and grant it the required permissions. - -## Scan types - -| Scan type | Description | -| --- | --- | -| **Users, Groups, and Roles** | Synchronizes users, groups, and role assignments from the Entra ID tenant. The first scan runs in full; subsequent scans collect only changes since the last run. Also retrieves MIP sensitivity labels automatically when the scan runs. | - -## Before you begin - -You need the following before adding Entra ID as a data source: - -- A user account with the **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator** role in Microsoft Entra ID, to register an application and grant admin consent for permissions -- A registered Microsoft Entra ID application with the required API permissions — see [Entra Tenant Requirements](entra-requirements.md) -- A client secret generated for the registered application — see [Client Secret Configuration](app-registration-secret.md) - -When configuring the Entra ID source in Access Analyzer, you need the following values from your registered application: - -- **Application (client) ID** -- **Directory (tenant) ID** -- **Client secret value** - -## Network requirements - -| Protocol | Port | Destination | -| --- | --- | --- | -| HTTPS | 443 | Microsoft identity platform (`login.microsoftonline.com`) | -| HTTPS | 443 | Microsoft Graph API (`graph.microsoft.com`) | diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/celerra.md b/docs/accessanalyzer/26.1/connectors/file-servers/celerra.md deleted file mode 100644 index 73229e8d4c..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/celerra.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Dell EMC Celerra" -description: "Supported platforms, permissions, and network ports for Dell EMC Celerra CIFS/SMB scanning" -sidebar_position: 50 ---- - -# Dell EMC Celerra - -The Dell EMC Celerra connector reads file shares over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the storage system. - -Dell EMC Celerra serves CIFS/SMB file shares through Data Movers. You must license and configure the CIFS service on each Data Mover you want to scan. - -## Supported versions - -- Celerra series (DART OS 6.x and later) - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -The account can be a local user on the Data Mover or a domain account from an Active Directory domain joined to the Data Mover. - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a Dell EMC Celerra Data Mover to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). Add each Data Mover as a separate server entry using its IP address or hostname. The connector connects to each Data Mover independently. diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/cifs.md b/docs/accessanalyzer/26.1/connectors/file-servers/cifs.md deleted file mode 100644 index 8cd41acaf7..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/cifs.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "CIFS / SMB File Share" -description: "Supported platforms, permissions, and network ports for CIFS/SMB scanning" -sidebar_position: 10 ---- - -# CIFS / SMB File Share - -The CIFS / SMB connector reads file servers over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the target file server. - -## Supported versions - -- Windows Server 2012 R2 and later -- Any SMB-compatible server (Samba, network-attached storage (NAS) appliances) - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a Windows file server or SMB-compatible server to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). - -## DFS namespaces - -For domain-based Distributed File System (DFS) namespaces, the scan targets the default domain controller for the domain. For standalone namespaces or multiple namespaces, add the server or servers hosting the namespace directly to the source group. - -## Sensitive Data Discovery - -The scanner infrastructure handles Sensitive Data Discovery (SDD). The target file server doesn't need additional software. diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md b/docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md deleted file mode 100644 index fe36433953..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/dell-unity.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Dell Unity" -description: "Supported platforms, permissions, and network ports for Dell Unity CIFS/SMB scanning" -sidebar_position: 40 ---- - -# Dell Unity - -The Dell Unity connector reads file shares over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the storage system. - -Dell Unity serves CIFS/SMB shares through NAS servers. You must configure the CIFS protocol on each NAS server you want to scan. - -## Supported versions - -- Unity OE 4.x and later - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -The account can be a local user on the NAS server or a domain account from an Active Directory domain joined to the NAS server. - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a Dell Unity NAS server to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). Add each NAS server as a separate server entry using its IP address or hostname. The connector connects to each NAS server independently. diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md b/docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md deleted file mode 100644 index a1bca8dff4..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/isilon-powerscale.md +++ /dev/null @@ -1,36 +0,0 @@ ---- -title: "Dell Isilon / PowerScale" -description: "Supported platforms, permissions, and network ports for Dell Isilon and PowerScale CIFS/SMB scanning" -sidebar_position: 30 ---- - -# Dell Isilon / PowerScale - -The Dell Isilon / PowerScale connector reads file shares over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the storage system. - -Dell Isilon / PowerScale (based on the OneFS operating system) organizes SMB shares within access zones. You must enable the SMB service on each access zone you want to scan. - -## Supported versions - -- OneFS 8.0 and later - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -The account can be a local user on the OneFS cluster or a domain account from an Active Directory domain joined to the access zone. - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a Dell Isilon / PowerScale access zone to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). Add each access zone as a separate server entry using the access zone's IP address or hostname. The connector connects to each access zone independently. diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/netapp.md b/docs/accessanalyzer/26.1/connectors/file-servers/netapp.md deleted file mode 100644 index 9fb5a87116..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/netapp.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "NetApp ONTAP" -description: "Supported platforms, permissions, and network ports for NetApp ONTAP CIFS/SMB scanning" -sidebar_position: 20 ---- - -# NetApp ONTAP - -The NetApp ONTAP connector reads file shares over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the storage system. - -NetApp ONTAP serves CIFS/SMB shares through Storage Virtual Machines (SVMs). Each SVM has its own CIFS server that the connector connects to independently. You must license and enable the CIFS service on each SVM you want to scan. - -## Supported versions - -- ONTAP 9.0 and later -- ONTAP 8.3 with CIFS license - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -The account can be a local ONTAP user or a domain account from an Active Directory domain joined to the SVM. - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a NetApp ONTAP SVM to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). Add each SVM as a separate server entry using the SVM's CIFS server hostname or IP address. The connector connects to each SVM independently. - -## Known behavior - -NetApp ONTAP may return invalid timestamp values on some systems due to a Year 2038 overflow issue in the ONTAP CIFS implementation. Access Analyzer detects this automatically and records affected timestamps as empty instead of causing a scan error. diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/vnx.md b/docs/accessanalyzer/26.1/connectors/file-servers/vnx.md deleted file mode 100644 index d1d8de521a..0000000000 --- a/docs/accessanalyzer/26.1/connectors/file-servers/vnx.md +++ /dev/null @@ -1,39 +0,0 @@ ---- -title: "Dell EMC VNX" -description: "Supported platforms, permissions, and network ports for Dell EMC VNX file server CIFS/SMB scanning" -sidebar_position: 60 ---- - -# Dell EMC VNX - -The Dell EMC VNX connector reads file shares over SMB to collect share permissions, folder and file ACLs, and file contents for sensitive data classification. The connector doesn't require agent installation on the storage system. - -Dell EMC VNX serves CIFS/SMB file shares through Data Movers. You must license and configure the CIFS service on each Data Mover you want to scan. - -## Supported versions - -- VNX2 series (NAS code 8.x) -- VNX series (NAS code 7.x) - -VNX2 is the second-generation platform; VNX is the original series. Both use the same Data Mover architecture, and you configure them identically in Access Analyzer. - -## Requirements - -### Service account - -The connector authenticates using a service account with a username and password. The account must have: - -- Read access to the shares you want to scan -- Read permission on object security descriptors (to enumerate ACLs) - -The account can be a local user on the Data Mover or a domain account from an Active Directory domain joined to the Data Mover. - -### Ports - -| Port | Protocol | Description | -|------|----------|-------------| -| 445 | TCP | SMB file sharing | - -## Set up - -To add a Dell EMC VNX Data Mover to Access Analyzer, see [Set Up File Server Source Group](../../gettingstarted/file-servers/set-up-source-group.md). Add each Data Mover as a separate server entry using its IP address or hostname. The connector connects to each Data Mover independently. diff --git a/docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json b/docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json deleted file mode 100644 index aebbe26706..0000000000 --- a/docs/accessanalyzer/26.1/connectors/sharepoint-online/_category_.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "label": "SharePoint Online", - "position": 50, - "collapsed": true, - "collapsible": true, - "link": { - "type": "doc", - "id": "connectors/sharepoint-online/overview" - } -} diff --git a/docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md deleted file mode 100644 index 61cfb61677..0000000000 --- a/docs/accessanalyzer/26.1/connectors/sharepoint-online/azure-permissions.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: "App Permissions in Entra" -description: "Configure Microsoft Entra ID app permissions for SharePoint Online connectivity" -sidebar_position: 10 ---- - -# App Permissions in Entra - -Access Analyzer connects to SharePoint Online through a Microsoft Entra ID registered application using certificate-based authentication. You must register a dedicated application for Access Analyzer and grant it the required API permissions before adding SharePoint Online as a data source. - -:::note -You need a user account with the Global Administrator, Application Administrator, or Cloud Application Administrator role to register an application and grant admin consent for permissions. -::: - -## Register an app in Microsoft Entra ID - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. On the left navigation menu, navigate to **Identity** > **Applications** > **App registrations**. - -3. On the App registrations page, click **New registration** in the top toolbar. - -4. Specify the following on the Register an application page: - - - **Name** — Enter a display name for the application, for example, *Access Analyzer SharePoint Online* - - **Supported account types** — Select **Accounts in this organizational directory only** - - **Redirect URI (optional)** — Leave blank - -5. Click **Register**. - -The Overview page for the newly registered application opens. Note the following values — you'll need them when configuring the SharePoint Online connector in Access Analyzer: - -- **Application (client) ID** -- **Directory (tenant) ID** - -## Grant permissions to the app - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. Navigate to **Identity** > **Applications** > **App registrations**. - -3. Click the **All applications** tab and select the application you registered. - -4. Click **API permissions** under the Manage section. - -5. Click **Add a permission**. The Request API permissions pane opens. - -6. Click an API to access its permissions, then click the **Application permissions** tab. - -7. Select the required permissions for each API. See [Required permissions](#required-permissions). - -8. Click **Add Permissions**. - -9. Repeat steps 6–8 for each API listed in the table. - -10. Click **Grant admin consent for ``** to apply the permissions. - -### Required permissions - -| API | Permission | Type | Description | -| --- | --- | --- | --- | -| Microsoft Graph | `Sites.Read.All` | Application | Read items in all site collections | -| Microsoft Graph | `Directory.Read.All` | Application | Read directory data | -| SharePoint | `Sites.FullControl.All` | Application | Full control of all site collections | diff --git a/docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md deleted file mode 100644 index 2e8c60e2fa..0000000000 --- a/docs/accessanalyzer/26.1/connectors/sharepoint-online/overview.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "SharePoint Online" -description: "Requirements for connecting Access Analyzer to SharePoint Online" -sidebar_position: 1 ---- - -# SharePoint Online - -Access Analyzer connects to SharePoint Online using certificate-based authentication through a pre-configured Microsoft Entra ID application. It accesses SharePoint Online through Microsoft Graph and the SharePoint REST API to enumerate sites, libraries, permissions, and sharing links. - -Before adding SharePoint Online as a data source, you must register a dedicated Microsoft Entra ID application, grant it the required permissions, and upload a certificate generated by Access Analyzer. - -## Scan types - -Access Analyzer supports two scan types for SharePoint Online: - -| Scan type | Description | -| --- | --- | -| **Access scan** | Enumerates sites, document libraries, folders, and files. Collects permissions, ACLs, sharing links, and Microsoft Information Protection (MIP) sensitivity labels applied to SharePoint items. The first scan runs in full; subsequent scans collect only changes since the last run. | -| **Sensitive Data scan** | Reads file contents to classify sensitive data. Requires a completed Access scan — it uses the site and file inventory from the Access scan as its input. | - -## Before you begin - -You need the following before adding SharePoint Online as a data source: - -- A user account with the **Global Administrator**, **Application Administrator**, or **Cloud Application Administrator** role in Microsoft Entra ID, to register an application and grant admin consent for permissions -- A registered Microsoft Entra ID application with the required API permissions — see [App Permissions in Entra](azure-permissions.md) -- Access to the Microsoft Entra admin center to upload the certificate generated during source group setup — see [Certificate Configuration](tenant-certificate-config.md) - -When configuring the SharePoint Online source in Access Analyzer, you need the following values from your registered application: - -- **Application (client) ID** -- **Directory (tenant) ID** - -Access Analyzer generates the certificate during source group setup. You download it and upload it to your registered Microsoft Entra ID application before you can test the connection. diff --git a/docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md b/docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md deleted file mode 100644 index eea9bd85ae..0000000000 --- a/docs/accessanalyzer/26.1/connectors/sharepoint-online/tenant-certificate-config.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: "Certificate Configuration" -description: "Upload a certificate to your Microsoft Entra ID app registration for SharePoint Online authentication" -sidebar_position: 20 ---- - -# Certificate Configuration - -Access Analyzer authenticates with SharePoint Online using certificate-based authentication. Access Analyzer generates the certificate during source group setup — you download the public certificate file and upload it to your registered Microsoft Entra ID application. - -## Upload a certificate - -1. Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com/). - -2. Navigate to **Identity** > **Applications** > **App registrations**. - -3. Click the **All applications** tab and select your registered application. - -4. Click **Certificates & secrets** under the Manage section. - -5. Click the **Certificates** tab. - -6. Click **Upload certificate**. - -7. Click the file icon next to the **Select a File** field. - -8. Browse to and select the certificate file you downloaded from Access Analyzer (`.cer` or `.pem`), then click **Open**. - -9. Enter a description for the certificate. - -10. Click **Add** to upload the certificate to the registered application. - -After uploading, return to the Access Analyzer source group wizard and click **Test Connection** to verify the authentication. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/_category_.json b/docs/accessanalyzer/26.1/dashboards-reports/_category_.json index 91e8e50995..e65d897459 100644 --- a/docs/accessanalyzer/26.1/dashboards-reports/_category_.json +++ b/docs/accessanalyzer/26.1/dashboards-reports/_category_.json @@ -1,6 +1,6 @@ { - "label": "Dashboards and Reports", - "position": 50, + "label": "Dashboards and reports", + "position": 80, "collapsed": true, "collapsible": true } diff --git a/docs/accessanalyzer/26.1/dashboards-reports/dashboards/_category_.json b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/_category_.json new file mode 100644 index 0000000000..2dd6d32b73 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/_category_.json @@ -0,0 +1,11 @@ +{ + "label": "Dashboards", + "position": 1, + "collapsed": true, + "collapsible": true, + "link": { + "type": "generated-index", + "description": "The two summary dashboards: Data security for file servers and SharePoint Online, and Active Directory for domains, users, groups, and risks.", + "slug": "/dashboards-reports/dashboards" + } +} diff --git a/docs/accessanalyzer/26.1/dashboards-reports/dashboards/active-directory.md b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/active-directory.md new file mode 100644 index 0000000000..797e072e30 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/active-directory.md @@ -0,0 +1,88 @@ +--- +title: Active Directory dashboard +description: A single-page summary of your Active Directory domains with user, group, and membership counts, privileged accounts, and every detected risk by type, level, and object. +sidebar_position: 2 +--- + +The Active Directory dashboard summarizes what an Identity sync collected from your domains. The top row counts domains, users, and groups. Below it, a **Users** section and a **Groups** section pair headline numbers with a breakdown of the risks found in each, and an **All Risks** section at the bottom lists every detected risk with its level and the object it concerns. + +Open it from **Dashboards > Active Directory**. Users with the Admin or Viewer role can see it. [Dashboards and reports](../index.md) explains the **Refresh** button, how to drill into a chart, and how fresh the numbers are. + +![Active Directory dashboard with Domains, Users, Groups, and risk tiles](/images/accessanalyzer/26.1/dashboards-reports/active-directory-dashboard.webp) + +## Where the data comes from + +Every card reads from an Identity sync on an Active Directory source. The dashboard needs no Access scan or Sensitive data scan, and no card depends on Netwrix Activity Monitor. Until the first Identity sync completes, the tiles show zero and the charts show **No results!**. [Scan types](../../scans/scan-types.md) explains how to run one; [Active Directory](../../sources/active-directory.md) explains the source itself. + +## Filter + +The dashboard has one filter and no tabs. + +| Filter | What it does | +|---|---| +| **Domain** | Restricts every card to one domain, chosen from the synced domains | + +Leave **Domain** empty to see all domains together. Because every card responds to it, the filter is the quickest way to look at one domain at a time. + +## Summary row + +| Card | What it shows | How to read it | +|---|---|---| +| **Domains** | The number of distinct domains synced | Each synced domain counts once | +| **Users** | The number of user objects | Includes disabled accounts | +| **Enabled Users** | The number of users whose account status is Enabled | The difference between this and **Users** is the number of disabled accounts | +| **Groups** | The number of groups | Security groups and distribution lists together | +| **Direct Memberships** | The number of direct group membership entries | Direct means nested membership isn't expanded; **Administrator Accounts** below does expand it | + +## Users section + +| Card | What it shows | How to read it | +|---|---|---| +| **Administrator Accounts** | The number of effective memberships in the built-in privileged groups listed below | Effective means nested membership is followed, so an account inside a group inside Domain Admins counts | +| **User Risks** | A pie chart of user-category risks by risk type | Shows which kind of user risk dominates; [Risk types](#risk-types) explains each type | +| **New Users** | Users created in the past seven days | A quick check on recent provisioning | +| **Users with Associated Risks** | The number of risk entries in the User category | Drill into it, or scroll to **Active Directory Risks**, to see which accounts are involved | + +
+Groups counted by **Administrator Accounts** + +Domain Admins, Enterprise Admins, Schema Admins, Administrators, Account Operators, Backup Operators, Server Operators, Print Operators, Group Policy Creator Owners, Domain Controllers, Read-only Domain Controllers, DnsAdmins, Cert Publishers, Remote Desktop Users, Distributed COM Users, Cryptographic Operators, Pre-Windows 2000 Compatible Access, Replicator, Network Configuration Operators, Performance Monitor Users, Performance Log Users, Windows Authorization Access Group, Terminal Server License Servers, and Incoming Forest Trust Builders. + +
+ +## Groups section + +| Card | What it shows | How to read it | +|---|---|---| +| **Security Groups** | The number of groups whose type is Security | Compare with **DLs** to see how the **Groups** total splits | +| **Group Risks** | A pie chart of group-category risks by risk type | Shows which kind of group risk dominates | +| **DLs** | The number of distribution lists, meaning groups whose type isn't Security | Together with **Security Groups**, this accounts for every group in **Groups** | +| **Groups with Associated Risks** | The number of risk entries in the Group category | Drill into it, or scroll to **Active Directory Risks**, for the group names | + +## All Risks section + +| Card | What it shows | How to read it | +|---|---|---| +| **Risks by Level** | A pie chart of all risks by level: LOW, MEDIUM, or HIGH | Start remediation with the HIGH slice | +| **Riskiest Objects** | A table of risk counts grouped by domain and object name, highest first | The users and groups with the most detected risks | +| **Active Directory Risks** | The full list: one row per detected risk, with the risk type, the object and its domain, when it was detected, additional context, the level, the category, and a description | Use the **Domain** filter to keep this list manageable, then drill into a row | + +## Risk types + +Each row in **Active Directory Risks** carries one of the following risk types. The level and description are what you see in the table. + +| Risk type | Level | Category | Description | +|---|---|---|---| +| Empty Groups | LOW | Group | Groups with no members | +| Single Member Groups | LOW | Group | Groups with exactly one member | +| Large Groups | MEDIUM | Group | Groups exceeding the defined membership threshold | +| Duplicate Groups | LOW | Group | Groups that contain identical effective membership sets | +| Circular Nesting | MEDIUM | Group | Groups that include themselves through recursive membership loops | +| Stale Users | MEDIUM | User | Users who have not logged on within the defined inactivity threshold | +| Very Stale Users | MEDIUM | User | Users who have not logged on within the defined inactivity threshold | +| Isolated Users | LOW | User | Enabled users not present in any group membership record | +| Old Password | HIGH | User | Users whose password age exceeds defined threshold, indicating stale credentials | +| DC Logon Rights | HIGH | User | Users who are direct or indirect members of privileged administrative groups granting Domain Controller logon rights | +| Users Without Logon Record | LOW | User | Users who have never logged on | + +For account-level detail behind any of these, such as password age, last logon, and account status per user, open the **AD Users** report on the [Identity reports](../reports/identity.md#ad-users) page. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/dashboards/data-security.md b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/data-security.md new file mode 100644 index 0000000000..56eb54f1c4 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/dashboards/data-security.md @@ -0,0 +1,67 @@ +--- +title: Data security dashboard +description: Scan coverage, sensitive data findings, and permissions across your File Server and SharePoint Online sources, plus an Activity tab of events from Netwrix Activity Monitor. +sidebar_position: 1 +--- + +The Data security dashboard is the first place to look after a scan. It pulls every File Server and SharePoint Online source into one view: the number of repositories and objects scanned, the sensitive data findings, and the permissions collected, with a table at the bottom that lists each share and site. A second tab shows access events from Netwrix Activity Monitor. + +Open it from **Dashboards > Data security**. Users with the Admin or Viewer role can see it. [Dashboards and reports](../index.md) explains the **Refresh** button, how to drill into a chart, and how fresh the numbers are. + +![Data security dashboard, Scan Overview tab, full page](/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard-full.webp) + +## Data prerequisites + +An Access scan on your File Server and SharePoint Online sources fills the **Scan Overview** tab. Until a Sensitive data scan has run on those sources as well, **Sensitive Data Findings** shows 0, **Sensitive Data by Source** stays empty, and the **Sensitive Files** and **Sensitive Findings** columns of **Data Source Inventory** have nothing to report. The **Activity** tab holds no scan data at all: it shows events from Netwrix Activity Monitor and stays empty until that connection is in place. [Scan types](../../scans/scan-types.md) covers the scans; [Netwrix Activity Monitor](../../integrations/netwrix-activity-monitor.md) covers the feed. + +## Tabs and filters + +The dashboard has two tabs, **Scan Overview** and **Activity**. Each tab has its own filters, shown above its cards, and every filter applies as soon as you change it. + +| Filter | Tab | What it does | +|---|---|---| +| **Data Source** | Scan Overview | Limits every card except **SharePoint Sites by Type** to **File Servers**, **SharePoint Online**, or both | +| **Start Date** | Activity | Earliest event time to include | +| **End Date** | Activity | Latest event time to include | +| **Event Type** | Activity | One or more event types, drawn from the events received | +| **Activity Source** | Activity | **File Servers**, **SharePoint Online**, or **Microsoft Copilot** | +| **User** | Activity | One or more users who performed events | +| **Event Status** | Activity | **Success** or **Failed** | + +All filters are optional and start empty, which means no restriction. + +## Scan Overview tab + +The table lists the cards in the order they appear, top to bottom and left to right. + +| Card | What it shows | How to read it | +|---|---|---| +| **Total Data Repositories** | The number of file shares plus SharePoint Online site collections that have been scanned | The breadth of coverage; if you expect 40 shares and see 12, some sources haven't been scanned yet | +| **Total Objects Scanned** | The number of objects collected from file servers and SharePoint Online | Rises with each newly scanned source | +| **Sensitive Data Findings** | The total number of pattern matches across both source types | Zero until a Sensitive data scan has run; a single file can contribute several matches | +| **Permissions Analyzed** | The number of permission entries collected | A rough measure of how much data the permission reports draw on | +| **Objects by Data Source** | A bar chart comparing object counts for File Servers and SharePoint Online | Shows where the bulk of your data sits | +| **Sensitive Data by Source** | A pie chart splitting the findings between File Servers and SharePoint Online | Shows which platform carries more sensitive content | +| **File Server Objects by Host** | A bar chart of object counts per file server | Picks out the largest servers; each bar is one host | +| **SharePoint Sites by Type** | A pie chart of SharePoint Online sites by site type | Not affected by the **Data Source** filter | +| **Data Source Inventory** | One row per share or SharePoint Online site, with columns **Source Type**, **Location**, **Total Objects**, **Files**, **Folders**, **Sensitive Files**, and **Sensitive Findings** | Sorted by total objects, largest first; shows up to 20,000 rows; shares appear as `\\host\share` paths | + +## Activity tab + +![Data security dashboard, Activity tab, with date, event type, source, user, and status filters](/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard-activity.webp) + +Every card on this tab responds to the six Activity filters. **Start Date** and **End Date** bound the time range; the other four narrow the events further. + +| Card | What it shows | How to read it | +|---|---|---| +| **Total Events** | The number of events in the selected range | Your baseline for the period | +| **Failed Events** | The number of events with status **Failed** | A spike is worth investigating: check which users and resources the failures cluster on | +| **Active Users** | The number of distinct users with at least one event | Compare with **Total Events** to see whether activity is spread out or concentrated | +| **Data Sources with Activity** | How many of the three activity sources reported events | Shows whether every feed you expect is reporting events | +| **Events by Type** | A bar chart of event counts per event type | One bar per event type; pick a single type in **Event Type** to isolate it across the other cards | +| **Activity Over Time** | A line chart of event counts over the range | Look for bursts outside working hours | +| **Events by Data Source** | A pie chart of events per activity source | Shows which platform generates most of the traffic | +| **Top Users by Activity** | A horizontal bar chart of users ranked by event count | The busiest accounts, which are worth checking against their roles | +| **Activity Detail** | The most recent 500 events, with columns **Time**, **Source**, **Event Type**, **User**, **Resource**, **Location**, and **Status** | Narrow the filters until fewer than 500 events match, so the table shows all of them | + +For a closer look at file server activity, open the **Activity Investigation** report from [Data reports](../reports/data.md). It filters by user, path, and event type. **Group By** sets the timeline's unit, day by default. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/index.md b/docs/accessanalyzer/26.1/dashboards-reports/index.md new file mode 100644 index 0000000000..e7280eac64 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/index.md @@ -0,0 +1,56 @@ +--- +title: Dashboards and reports +description: Dashboards summarize what your scans have found, reports answer one question in depth, and both open in the same viewer with filters, drill-down, and a Refresh button. +--- + +Everything a scan collects ends up in one of two places. Dashboards give you the wide view: a page of counts, charts, and a detail table for a whole area of your environment. Reports answer one question at a time, with filters tuned to that question. Both open in the same viewer and behave the same way once they're on screen. + +## Dashboards and reports compared + +There are two dashboards, listed under **Dashboards** in the sidebar: + +- [Data security dashboard](dashboards/data-security.md) covers File Server and SharePoint Online sources: what your scans have covered, where they found sensitive data, how many permissions they analyzed, and, on its **Activity** tab, which users did what. +- [Active Directory dashboard](dashboards/active-directory.md) covers your domains: users, groups, memberships, privileged accounts, and a catalog of detected risks. + +Reports live under **Reports**, on three pages. **Data** lists 11 reports on file servers and SharePoint Online, **Identity** lists three on Active Directory and Entra ID users and groups, and **Compliance** shows eight of the Data reports again, grouped by regulatory framework. Two of the Data entries, both named Share Audit, open the same report. Each report has a description under its name in the list, and all but the two Entra ID reports have filters of their own once open. + +Use a dashboard when you want totals and trends for a whole area. Use a report when you want the reason behind a number, or the specific folders, links, or accounts involved. [Data reports](reports/data.md), [Identity reports](reports/identity.md), and [Compliance reports](reports/compliance.md) describe every report and its cards. + +## Role access + +Users with the Admin or Viewer role see the **Dashboards** section and can open any report. Users with the User admin role don't see **Dashboards**, and although they can open the **Reports** pages, report content doesn't load for their account. [Users and roles](../settings/users.md) explains the three roles. + +## The viewer + +A dashboard or report page has breadcrumbs, a heading, a **Refresh** button at the top right, and the content itself below. Reports also show the report's description under the heading and a **Back to Data reports** or **Back to Identity reports** link that returns you to the list you came from, with the tab and category you had selected. + +Filters sit at the top of the content, inside the dashboard or report rather than in the page header. They apply the moment you change them; there's no Apply button. Where a filter accepts more than one value, you can pick several. Filters go back to their defaults when you click **Refresh** or reload the page. Some content also has tabs of its own: the Data security dashboard has **Scan Overview** and **Activity**, and the Share Audit report has four. + +Drill-down works on any tile, chart segment, bar, or table cell. Click one, and a menu offers ways to break the value down or see the records behind it. Choosing an option opens a detail view with a back button on the left, a title, and controls on the right for filtering, changing the chart type, adjusting settings, opening the query editor, and resetting your changes. You can explore freely but can't save what you build. The back button returns you to the dashboard, which reloads with its filters reset. + +If the content fails to load, the page shows **Dashboard error** and **Unable to load** followed by the dashboard or report name, sometimes with an **Error details** box. Click **Reload dashboard** to reload the page. + +## Data freshness + +Nothing on these pages updates on its own, and dashboard results are cached, so a scan that finished a moment ago may not appear on a dashboard yet. After a scan completes, click **Refresh** to reload the page's data. If a dashboard's figures haven't changed after a refresh, the cached results may not have expired yet; wait and refresh again later. + +## What each dashboard and report needs + +Every dashboard and report appears in the interface from the first sign-in, even when there's no data behind it. Until the right scan has run, tiles show zero or **No results!**, and charts and tables show **No results!**. The table shows which scan, or which event feed, populates each dashboard and group of reports. [Scan types](../scans/scan-types.md) explains the Access scan, Sensitive data scan, and Identity sync; [Sources](../sources/index.md) explains which source types each applies to. + +| To populate | You need | +|---|---| +| Data security dashboard, **Scan Overview** tab | An Access scan on your File Server or SharePoint Online sources, plus a Sensitive data scan for the sensitive data tiles and charts | +| Data security dashboard, **Activity** tab | Netwrix Activity Monitor sending events to Access Analyzer | +| Active Directory dashboard | An Identity sync on an Active Directory source | +| File system permission reports: Broken Inheritance, High Risk ACLs, Open Access, Share Audit | An Access scan on a File Server source, plus a Sensitive data scan for the Open Access cards that show sensitive files and exposed patterns | +| File system sensitive data reports: Sensitive Data Overview, the Share Audit **Sensitive Data** tab | A Sensitive data scan on a File Server source | +| File system activity: Activity Investigation, the Share Audit **Activity** tab | Netwrix Activity Monitor sending events to Access Analyzer | +| SharePoint permission and sharing reports: Shared Links, High-Risk ACLs, Open Access | An Access scan on a SharePoint Online source, plus a Sensitive data scan for the cards that count links or files with sensitive data | +| SharePoint Sensitive Data Overview | A Sensitive data scan on a SharePoint Online source | +| AD Users | An Identity sync on an Active Directory source | +| Entra Users, Entra Groups | An Identity sync on an Entra ID source | + +For the file system permission reports, an Identity sync on the matching Active Directory source turns identifiers into names and expands group membership. The Share Audit **Overview** tab also draws on two other feeds: its Matches card needs a Sensitive data scan, and its Probable Owner card needs Netwrix Activity Monitor events. On the Share Audit **Sensitive Data** tab, the Users by Activity on Sensitive Files card also needs Netwrix Activity Monitor events. + +Activity data doesn't come from a scan. It arrives from Netwrix Activity Monitor, which watches file servers, SharePoint Online, and Microsoft 365 Copilot and streams events to Access Analyzer. [Netwrix Activity Monitor](../integrations/netwrix-activity-monitor.md) covers the connection. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/my-reports.md b/docs/accessanalyzer/26.1/dashboards-reports/my-reports.md deleted file mode 100644 index d661678944..0000000000 --- a/docs/accessanalyzer/26.1/dashboards-reports/my-reports.md +++ /dev/null @@ -1,83 +0,0 @@ ---- -title: "My Reports" -description: "Save, manage, and reload filtered report views in Netwrix Access Analyzer" -sidebar_position: 30 ---- - -# My Reports - -My Reports is a personal workspace for saving filtered report views. When you configure a report with specific filters — a particular share, user, or time range — you can save that configuration as a named report and reload it later without reapplying the filters manually. - -Saved reports are private to the user who created them. Other users can't view or modify your saved reports. - -Navigate to **Reports** > **My Reports** to view your saved reports. - -## Save a report - -You can save any report that has the **Save Report** button in its toolbar. The button appears on File System and SharePoint report pages. - -1. Navigate to the report you want to save — for example, **Reports** > **File System** > **Access**. -2. Select a report type from the selector — for example, **Share Audit**. -3. Apply the filters you want to capture. -4. Click **Save Report** in the toolbar. -5. In the **Save Report** dialog, enter a name for the report. Names are required, must be unique (case-insensitive) within your saved reports, and can't exceed 100 characters. -6. Review the **Current Filters** section to confirm the active filters are correct. -7. Click **Save Report**. - -After you save the report, Access Analyzer redirects you to **My Reports**, where the new report appears in the list. - -:::note -If you don't apply filters before clicking **Save Report**, the dialog indicates that no filters are active. You can still save the report, but it will open with the default unfiltered view. -::: - -## Open a saved report - -1. Navigate to **Reports** > **My Reports**. -2. In the **My Saved Reports** table, click the row for the report you want to open. - -The report opens with its saved filter configuration applied. A banner at the top of the report displays the report name and a **Back to My Reports** button. - -To return to the **My Reports** list, click **Back to My Reports** in the banner. - -## Rename a saved report - -1. Navigate to **Reports** > **My Reports**. -2. In the **Actions** column for the report you want to rename, click the actions icon (**⋮**). -3. Select **Rename**. -4. Edit the name in the inline text field. The name can't exceed 100 characters. -5. Press **Enter** or click the check icon to save the new name. Press **Escape** or click the X icon to cancel. - -## Delete a saved report - -1. Navigate to **Reports** > **My Reports**. -2. In the **Actions** column for the report you want to delete, click the actions icon (**⋮**). -3. Select **Delete**. - -:::warning -Deleting a saved report is permanent. There's no confirmation step and no undo. -::: - -## My Saved Reports table - -The **My Saved Reports** table lists all reports you've saved. - -| Column | Description | -| --- | --- | -| **Name** | The name of the saved report. Click a row to open the report. | -| **Parent Report** | The report type this was saved from — for example, **Share Audit** or **Broken Inheritance**. Displays a dash if the source can't be identified. | -| **Created** | The date the report was saved. | -| **Actions** | Opens a menu with **Rename** and **Delete** options. | - -When you haven't saved any reports yet, the table displays: - -> *You haven't saved any reports yet. Go to Access, Content, or Activity reports, apply filters, and click "Save Report" to save them here.* - -The table paginates when it contains more than 10 reports. You can display 10 or 25 rows per page. - -## Report name constraints - -| Constraint | Detail | -| --- | --- | -| **Required** | A name is required to save a report. | -| **Maximum length** | 100 characters. | -| **Uniqueness** | Names must be unique within your saved reports (case-insensitive). | diff --git a/docs/accessanalyzer/26.1/dashboards-reports/reports.md b/docs/accessanalyzer/26.1/dashboards-reports/reports.md deleted file mode 100644 index fd82bfe7d8..0000000000 --- a/docs/accessanalyzer/26.1/dashboards-reports/reports.md +++ /dev/null @@ -1,76 +0,0 @@ ---- -title: "Reports" -description: "All pre-built dashboards and reports available in Netwrix Access Analyzer" -sidebar_position: 10 ---- - -# Reports - -Netwrix Access Analyzer includes pre-built dashboards and reports that surface findings from your scans. Reports become available after the first scan of a source group completes and update each time a scan runs. - -Reports are organized by data source type and grouped by category in the navigation under **Dashboards** and **Reports**. - -## Dashboards - -| Dashboard | Description | -| --- | --- | -| **Data Security** | An overview of data security posture across all connected data sources. | -| **Active Directory** | An overview of Active Directory scan results for one or more domains. Shows inventory counts for users, groups, and group memberships alongside security risk data, including risk breakdowns by type and severity and a ranked list of the objects with the highest number of associated risks. Filter by domain to focus on a specific part of your environment. | - -## File Server reports - -For full details on these reports, see [File Server Reports](/docs/accessanalyzer/26_1/gettingstarted/file-servers/reports). - -### Access - -| Report | Description | -| --- | --- | -| **Broken Inheritance** | Lists shares and folders where permission inheritance is broken, meaning the folder's ACL no longer follows its parent. Use this report to find locations where custom permission assignments may have introduced inconsistencies or unexpected access. | -| **Domain User ACLs** | Shows share and folder permissions assigned directly to domain user accounts. Use this report to identify accounts with direct ACL entries that should be managed through groups instead. | -| **High Risk ACLs** | Identifies folders where broad trustees such as Everyone, Authenticated Users, or Domain Users appear in the access control list. Use this report to locate and remediate over-permissioned folders that expose data to wide audiences. | -| **Local Administrators** | Lists local administrator accounts and the hosts where they hold that privilege. Use this report to identify non-standard or unauthorized local administrator assignments across your file servers. | -| **Missing Full Control** | Lists folders where no trustee holds Full Control permission. Use this report to identify folders that may lack a clear owner or administrator and address potential access management gaps. | -| **Open Access** | Identifies folders and shares accessible to broad groups or where sensitive data is reachable without restriction. Use this report to prioritize remediation of the most exposed locations in your file server environment. | -| **Probable Owner** | Identifies the most likely owner for each share based on access patterns and file activity. Use this report to assign data ownership and support data governance workflows. | -| **Share Audit** | Provides a detailed breakdown of share-level attributes including scan status, last scanned date, file counts, object counts, and active users. Use this report to confirm scan coverage and review the overall state of each share. | - -### Activity - -| Report | Description | -| --- | --- | -| **Activity Investigation** | Displays file system events filtered by date range, user, path, and event type. Use this report to trace the actions of a specific user or investigate changes to a specific file or folder. | - -### Content - -| Report | Description | -| --- | --- | -| **Empty Shares** | Lists shares that contain no files. Use this report to identify shares that can be reviewed for decommissioning or consolidation. | -| **Largest Shares** | Ranks file shares by total size. Use this report to identify shares that consume the most storage and prioritize them for review or cleanup. | -| **Nested Shares** | Identifies shares nested inside other shares, creating multiple access paths to the same data with potentially different permissions. Use this report to find and resolve configurations that complicate permission management and access auditing. | -| **Stale Content** | Identifies files and shares that haven't been accessed within a configurable threshold. Use this report to locate data that may be a candidate for archiving, deletion, or access review. | - -### Sensitive Data - -| Report | Description | -| --- | --- | -| **Sensitive Data Activity** | Shows file system events involving files that contain sensitive data, filtered by date range, event type, user, and classification taxonomy. Use this report to identify who is reading, modifying, or deleting sensitive files and to detect potential data exfiltration or misuse. | -| **Sensitive Data Overview** | Provides a high-level summary of sensitive data scan findings across CIFS/SMB file shares, including the number of files with matches, classification terms found, and distribution by host and share. Use this report as a starting point for understanding where sensitive data lives in your file server environment. | -| **Share Audit** | Shows share-level details in the context of sensitive data findings, including which shares contain files with sensitive data matches. Use this report to understand sensitive data distribution across shares and prioritize remediation. | -| **Stale Data** | Identifies files containing sensitive data that haven't been accessed recently. Use this report to find aging sensitive content that may no longer be actively used but still carries exposure risk. | - -## SharePoint Online reports - -For full details on these reports, see [SharePoint Online Reports](/docs/accessanalyzer/26_1/gettingstarted/sharepoint-online/reports). - -### Access - -| Report | Description | -| --- | --- | -| **Shared Links Report** | Shows all sharing links across your SharePoint environment, with breakdowns by sharing scope (organization, anonymous, specific people), active status, sensitive data type, and site. Use this report to identify overly broad sharing and links that expose sensitive files. | - -### Content - -| Report | Description | -| --- | --- | -| **ROT Analysis** | Identifies Redundant, Obsolete, and Trivial (ROT) data across your SharePoint sites, including stale files not modified in over a year, duplicate files by content hash, and stale files containing sensitive data. Use this report to prioritize data cleanup and reduce unnecessary exposure of aging content. | -| **Scan Overview** | Summarizes the results of the most recent scan across all sites, including total site count, file count, total storage, and files with sensitive data. Use this report to confirm scan coverage and quickly identify which sites hold the most sensitive content. | diff --git a/docs/accessanalyzer/26.1/dashboards-reports/reports/_category_.json b/docs/accessanalyzer/26.1/dashboards-reports/reports/_category_.json new file mode 100644 index 0000000000..4bcc9daf93 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/reports/_category_.json @@ -0,0 +1,11 @@ +{ + "label": "Reports", + "position": 2, + "collapsed": true, + "collapsible": true, + "link": { + "type": "generated-index", + "description": "The Data, Identity, and Compliance report pages, with the filters and cards of every report.", + "slug": "/dashboards-reports/reports" + } +} diff --git a/docs/accessanalyzer/26.1/dashboards-reports/reports/compliance.md b/docs/accessanalyzer/26.1/dashboards-reports/reports/compliance.md new file mode 100644 index 0000000000..c1993ed5d9 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/reports/compliance.md @@ -0,0 +1,59 @@ +--- +title: Compliance reports +description: How the Compliance page arranges eight of the Data reports under GDPR, HIPAA, PCI DSS, SOX, ISO 27001, NIST CSF, and SOC 2, and what the Primary and Supporting badges mean. +sidebar_position: 3 +--- + +The **Compliance** page is a second way into the Data reports, arranged for someone preparing evidence for an audit rather than investigating an incident. It organizes reports that already exist: it doesn't run checks against a framework, score your environment, or produce findings of its own. What it gives you is a shortlist of the reports worth opening for a given framework, labeled by the control area each one covers. + +Open the page from **Reports > Compliance**. [Data reports](data.md) describes every report the page links to, with its filters and cards. + +![Compliance reports list, All tab](/images/accessanalyzer/26.1/dashboards-reports/reports-compliance.webp) + +## The Compliance page + +The layout matches the other two report pages: a table with **Report** and **Category** columns, tabs above it, and chips under the tabs. Here the tabs are regulatory frameworks and the chips are control areas. + +The first tab, **All**, lists eight reports. One tab per framework follows, in this order: + +| Tab | Framework | +|---|---| +| **GDPR** | General Data Protection Regulation | +| **HIPAA** | Health Insurance Portability and Accountability Act | +| **PCI DSS** | Payment Card Industry Data Security Standard | +| **SOX** | Sarbanes-Oxley Act | +| **ISO 27001** | ISO/IEC 27001 information security management standard | +| **NIST CSF** | National Institute of Standards and Technology Cybersecurity Framework | +| **SOC 2** | System and Organization Controls 2 | + +Every framework tab lists the same eight reports, so each tab shows a count of eight. The frameworks carry no description text of their own; the tab label is all there is. What changes when you pick a framework is the badge next to each report name; see [Primary and Supporting badges](#primary-and-supporting-badges). + +The chips group the eight reports by control area. The counts are the same on every tab. + +| Chip | Reports | +|---|---| +| **Permissions** (3) | [Broken Inheritance](data.md#broken-inheritance), [High Risk ACLs](data.md#high-risk-acls), [Open Access](data.md#open-access) | +| **File share structure** (1) | [Share Audit](data.md#share-audit) | +| **Activity** (1) | [Activity Investigation](data.md#activity-investigation) | +| **Sensitive data** (2) | [Sensitive Data Overview](data.md#sensitive-data-overview), [Share Audit](data.md#share-audit-sensitive-data-entry) (the second Share Audit row on the Data page) | +| **External collaboration** (1) | [Shared Links](data.md#shared-links) | + +Both Share Audit rows from the Data page appear here, under different control areas. They open the same report. Switching tabs clears the selected chip, as on the other report pages. + +## Primary and Supporting badges + +On the **All** tab, report names carry no badge. Select a framework and each name gains a small **Primary** or **Supporting** label. **Primary** means the report is direct evidence for that framework's controls; **Supporting** means it's useful context rather than the main exhibit. + +![Compliance reports list filtered to GDPR](/images/accessanalyzer/26.1/dashboards-reports/reports-compliance-gdpr.webp) + +Only two report-framework pairings carry the **Supporting** badge: the Share Audit row under **File share structure** on the **GDPR** tab and Shared Links under **SOX**. The second Share Audit row, under **Sensitive data**, is **Primary** on every tab, as is every other pairing. The badges are fixed, so they read the same in every deployment; they don't reflect anything about your data. + +## Included and excluded reports + +The eight reports on this page are the seven file server reports from the Data page plus Shared Links, the SharePoint sharing-links report. The page leaves out the Data page's other three SharePoint reports (High-Risk ACLs, Open Access, and Sensitive Data Overview, the SharePoint counterparts of three listed file server reports) and the [Identity reports](identity.md). To use those for compliance work, open them from their own pages. + +## Open a report + +Click a row to open the report exactly as the Data page does, with the same filters and cards. The link at the top of the report reads **Back to Data reports** and takes you to the Data reports page, not back to Compliance. To return to the framework tab you were on, use your browser's Back button or open **Reports > Compliance** again. + +Because the reports are the same ones, the prerequisites are too: an Access scan on your File Server sources for the permission and file share structure reports, a Sensitive data scan for the sensitive data reports, an Access scan on your SharePoint Online sources for Shared Links, and events from Netwrix Activity Monitor for Activity Investigation. [Dashboards and reports](../index.md) has the full table. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/reports/data.md b/docs/accessanalyzer/26.1/dashboards-reports/reports/data.md new file mode 100644 index 0000000000..1e5e0e3e00 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/reports/data.md @@ -0,0 +1,343 @@ +--- +title: Data reports +description: The reports on the Data page, covering permissions, sensitive data, and access activity on File Server and SharePoint Online sources, with the filters and cards of each one. +sidebar_position: 1 +--- + +The **Data** page collects every report about the content of your file servers and SharePoint Online sites: who can reach it, where the sensitive files are, and who has been opening them. Seven reports cover file servers and four cover SharePoint Online. Two of the file server rows, both named Share Audit, open the same report, so the 11 rows lead to 10 distinct reports. + +Open the page from **Reports > Data**. [Dashboards and reports](../index.md) covers what's common to every report: the **Refresh** button, how filters apply, drilling into a chart, and how fresh the data is. + +![Data reports list, All tab](/images/accessanalyzer/26.1/dashboards-reports/reports-data.webp) + +## The Data page + +The page is a table with two columns, **Report** and **Category**. Each row shows the report name with its description underneath, and a category chip on the right. Click anywhere on a row to open the report. + +Above the table, tabs narrow the list by platform and chips narrow it by category. Each tab and chip shows how many reports it contains. + +| Tab | Reports | Category chips | +|---|---|---| +| **All** | 11 | **Permissions** (7), **Activity** (1), **Classification / Stale Data** (3) | +| **File system** | 7 | **Permissions** (4), **Activity** (1), **Classification / Stale Data** (2) | +| **SharePoint** | 4 | **Permissions** (3), **Classification / Stale Data** (1) | + +The first chip in the row, **All**, repeats the tab's total. + +Switching tabs clears the chip you had selected. Clicking a selected chip again clears it. The page has no search box or sort control. + +The rows appear in this order: + +| Report | Tab | Category | +|---|---|---| +| [Broken Inheritance](#broken-inheritance) | File system | Permissions | +| [High Risk ACLs](#high-risk-acls) | File system | Permissions | +| [Open Access](#open-access) | File system | Permissions | +| [Share Audit](#share-audit) | File system | Permissions | +| [Activity Investigation](#activity-investigation) | File system | Activity | +| [Sensitive Data Overview](#sensitive-data-overview) | File system | Classification / Stale Data | +| [Share Audit](#share-audit-sensitive-data-entry), second entry | File system | Classification / Stale Data | +| [Shared Links](#shared-links) | SharePoint | Permissions | +| [High-Risk ACLs](#high-risk-acls-sharepoint) | SharePoint | Permissions | +| [Open Access](#open-access-sharepoint) | SharePoint | Permissions | +| [Sensitive Data Overview](#sensitive-data-overview-sharepoint) | SharePoint | Classification / Stale Data | + +Two names, Open Access and Sensitive Data Overview, appear on both the file system and SharePoint sides, and High Risk ACLs has a SharePoint twin spelled High-Risk ACLs. The **File system** and **SharePoint** tabs keep them apart, and the description under each name tells you which is which. + +## Inside a report + +Every report opens the same way: breadcrumbs **Reports > Data** followed by the report name, a **Back to Data reports** link, the name as the page heading with the description under it, and **Refresh** at the top right. The report's own filters sit at the top of the content and take effect as soon as you change them. Only [Share Audit](#share-audit) and [Activity Investigation](#activity-investigation) have required filters; everywhere else, an empty filter means no restriction. + +**Back to Data reports** returns you to the list with the tab and chip you had selected. + +## File system reports + +These seven reports read from your File Server sources. The permission reports need a completed Access scan on the source. The sensitive data reports need a Sensitive data scan. The activity report and the activity cards in Share Audit need events from Netwrix Activity Monitor. Where a report shows account or group names rather than identifiers, or expands group membership, it relies on an Identity sync of the Active Directory domain those accounts belong to. [Scan types](../../scans/scan-types.md) explains each scan. + +### Broken Inheritance + +"Folders where permission inheritance has been broken and explicit ACEs applied." + +An access control entry (ACE) is one line in a folder's permission list. Folders normally inherit their permissions from the folder above; when someone breaks that inheritance and adds explicit entries, the folder becomes an exception that's easy to overlook. This report finds those folders and shows where they cluster. It needs a completed Access scan on the File Server source. + +![Broken Inheritance report](/images/accessanalyzer/26.1/dashboards-reports/report-broken-inheritance.webp) + +The report shows **Host** and **Share** filters above its cards. + +| Card | What it shows | +|---|---| +| **Top Hosts** | Hosts ranked by the number of folders with broken inheritance | +| **Top Shares** | Shares ranked the same way | +| **Shares with Broken Inheritance** | A pie chart splitting the folders between shares | +| **File System Broken Inheritance Summary** | One row per share, with columns **Folders**, **Folders with Broken Inheritance**, **Percent**, **Explicit Ace Count**, **Explicit Trustee Count**, and **Explicit Deny Count** | + +Needs an Access scan on the File Server source. + +### High Risk ACLs + +"Shares and folders with overly permissive ACLs that expose sensitive data." + +A high-risk entry grants access to an open trustee: a group such as Everyone, Authenticated Users, or Domain Users that effectively means every account in the organization. This report lists the shares and folders where such entries appear. + +![High Risk ACLs report](/images/accessanalyzer/26.1/dashboards-reports/report-high-risk-acls.webp) + +| Filter | What it does | +|---|---| +| **Host** | Limits the report to the selected hosts | +| **Share** | Limits the report to the selected shares | + +| Card | What it shows | +|---|---| +| **Hosts** | The number of hosts with at least one high-risk folder | +| **Shares** | The number of shares with at least one high-risk folder | +| **Folders** | The number of folders with a high-risk entry | +| **Shares by High Risk Folders** | Shares ranked by how many high-risk folders they contain | +| **High Risk Permissions** | A pie chart of the entries by trustee and permission | +| **High Risk ACLs** | The detail list, one row per high-risk entry | + +Needs an Access scan on the File Server source. An Identity sync on the matching Active Directory source lets the report recognize group names. + +### Open Access + +"Shares accessible by Everyone or Domain Users without restrictions." + +Where High Risk ACLs looks at individual permission entries, Open Access resolves effective membership: a folder counts as open when Everyone or Domain Users can reach it directly or through a nested group. It also joins in sensitive data findings, so you can see which open folders hold files that matter. + +![Open Access report](/images/accessanalyzer/26.1/dashboards-reports/report-open-access.webp) + +| Filter | What it does | +|---|---| +| **Host** | Limits the report to the selected hosts | +| **Share** | Limits the report to the selected shares | +| **Pattern** | Limits the report to the selected sensitive data patterns | + +| Card | What it shows | +|---|---| +| **Hosts** | The number of hosts with open folders | +| **Shares** | The number of shares with open folders | +| **Folders** | The number of open folders | +| **Files with Sensitive Data** | The number of files in open folders that matched a sensitive data pattern | +| **Hosts by Open Folders** | A bar chart of open folders per host | +| **Shares by Open Folders** | Shares ranked by open folder count | +| **Exposed Sensitive Data** | A pie chart of the patterns matched in open folders | +| **Folders with Open Access** | The detail list, one row per open folder | + +Needs an Access scan on the File Server source, plus a Sensitive data scan for the two sensitive data cards. The effective membership resolution uses the Identity sync of the Active Directory domain the trustees belong to; without it, access granted through nested groups isn't detected. + +### Share Audit + +"Detailed breakdown of effective permissions on each network share." + +Share Audit is the one report that looks at a single share at a time and covers it from every angle: what's in it, who can reach it, what sensitive data it holds, and who has been using it. The content is split across four tabs inside the report. + +![Share Audit report](/images/accessanalyzer/26.1/dashboards-reports/report-share-audit.webp) + +| Filter | What it does | +|---|---| +| **Share** | Required. Choose the share to audit from the list of scanned shares, shown as `\\host\share` paths. The filter starts at the placeholder `\\Host\Share`, and every card is empty until you pick a real share | +| **Date** | The time range for the **Activity** tab; defaults to the past seven days | +| **Group By** | The unit of time for the **Event Counts** chart on the **Activity** tab | + +**Date** and **Group By** apply only to the **Activity** cards. **Share** applies to everything. + +| Tab | Card | What it shows | +|---|---|---| +| **Overview** | **Last Scanned** | When the share was last scanned | +| **Overview** | **Folders** | The number of folders in the share | +| **Overview** | **Files** | The number of files in the share | +| **Overview** | **File Size** | The total size of those files | +| **Overview** | **Matches** | The number of sensitive data matches found within the share | +| **Overview** | **Last Accessed** | The most recent last-accessed time of any file in the share | +| **Overview** | **Scan Status** | A pie chart of objects by their status from the last scan | +| **Overview** | **Probable Owner** | The account whose activity suggests it owns the share; needs Netwrix Activity Monitor events | +| **Permissions** | **Share Permissions** | The share-level permission list, with trustees resolved to user and group names | +| **Permissions** | **Expanded Permissions** | Effective folder permissions, with group membership expanded | +| **Permissions** | **Broken Inheritance** | Folders in this share whose inheritance has been broken | +| **Sensitive Data** | **Files with Sensitive Data** | The number of files with at least one match | +| **Sensitive Data** | **Patterns Found** | The number of distinct patterns matched | +| **Sensitive Data** | **Pattern Groups Found** | The number of distinct pattern groups matched | +| **Sensitive Data** | **Matches by # of Files** | A pie chart of patterns by how many files matched each | +| **Sensitive Data** | **Users by Activity on Sensitive Files** | A bar chart of users ranked by events on files with sensitive data; needs Netwrix Activity Monitor | +| **Sensitive Data** | **Files with Sensitive Data by Last Accessed** | A bar chart bucketing sensitive files by their last-accessed time | +| **Sensitive Data** | **Sensitive Data Files** | The detail list of files with matches | +| **Activity** | **Active Users** | Users ranked by event count in the selected range | +| **Activity** | **Event Counts** | A bar chart of events over time, grouped by the **Group By** unit | +| **Activity** | **File System Activity** | The event-level list for the share | + +Needs an Access scan on the File Server source for the **Overview** and **Permissions** tabs, a Sensitive data scan for the **Sensitive Data** tab, and Netwrix Activity Monitor events for the **Activity** tab and the **Probable Owner** card. Trustee names on the **Permissions** tab come from the Identity sync of the matching Active Directory source. + +### Activity Investigation + +"Detailed audit trail of file and folder access events for forensic investigation." + +This is the report to open when you need to know what happened to a particular path, or what a particular account did, over a specific window. It reads the file server events that Netwrix Activity Monitor sends to Access Analyzer; no scan produces this data. + +![Activity Investigation report](/images/accessanalyzer/26.1/dashboards-reports/report-activity-investigation.webp) + +| Filter | What it does | +|---|---| +| **Date** | Required. The time range to investigate; defaults to the past seven days | +| **Group By** | Required. The unit of time for the **Activity Timeline**; defaults to day | +| **User** | The accounts that performed the events | +| **Path** | The paths the events touched | +| **Event Type** | The types of event to include | +| **Successful** | Whether to show successful events, failed events, or both | + +| Card | What it shows | +|---|---| +| **Activity Timeline** | A line chart of events over the range, at the **Group By** granularity | +| **Event Type** | A pie chart of events by type | +| **Successful** | A pie chart of successful against failed events | +| **Protocol** | A pie chart of events by the protocol used | +| **Top Users** | Accounts ranked by event count | +| **Top Hosts** | Hosts ranked by event count | +| **Top Shares** | Shares ranked by event count | +| **File System Activity** | The event-level list, one row per event | + +Needs Netwrix Activity Monitor sending file server events to Access Analyzer. [Netwrix Activity Monitor](../../integrations/netwrix-activity-monitor.md) explains the connection. + +### Sensitive Data Overview + +"Summary of sensitive data findings across all scanned file system locations." + +The file server counterpart of the sensitive data tiles on the Data security dashboard, with filters that let you narrow the findings to a host, a share, a pattern group, or a single pattern. [Sensitive data patterns](../../sensitive-data-patterns/index.md) explains what patterns and pattern groups are. + +![Sensitive Data Overview report](/images/accessanalyzer/26.1/dashboards-reports/report-sensitive-data-overview.webp) + +| Filter | What it does | +|---|---| +| **Host** | Limits the report to the selected hosts | +| **Share** | Limits the report to the selected shares | +| **Pattern Group** | Limits the report to matches from the selected pattern groups | +| **Pattern** | Limits the report to matches of the selected patterns | + +| Card | What it shows | +|---|---| +| **Hosts with Sensitive Data** | The number of hosts with at least one match | +| **Shares with Sensitive Data** | The number of shares with at least one match | +| **Files with Sensitive Data** | The number of files with at least one match | +| **Distinct Patterns Found** | How many different patterns matched | +| **Files by Pattern** | A pie chart of files per pattern | +| **Top Shares by Sensitive File Count** | A bar chart of shares ranked by sensitive file count | +| **Sensitive Data File Details** | The detail list, one row per file | + +Needs a Sensitive data scan on the File Server source. + +### Share Audit (Sensitive Data entry) + +"Permission breakdown filtered to shares that contain sensitive data." + +This second Share Audit row sits under the **Classification / Stale Data** category so that it's findable when you're working through sensitive data rather than permissions. It opens the same Share Audit report described [above](#share-audit), with the same filters and tabs; the **Share** filter lists every scanned share, not only those with sensitive data. Pick the share you're interested in and go to the **Sensitive Data** tab. + +![Share Audit report](/images/accessanalyzer/26.1/dashboards-reports/report-share-audit-sensitive.webp) + +## SharePoint reports + +These four reports read from your SharePoint Online sources. Three need an Access scan; the fourth needs a Sensitive data scan. All four share the **Site** and **Site Type** filters, which limit a report to the selected sites or to sites of the selected types. + +### Shared Links + +"Anonymous and company-wide sharing links that expose SharePoint content externally." + +An anonymous link works for anyone who has it; an organization link works for anyone in your tenant. This report counts both kinds, ranks sites by how many they carry, and flags the links that point at files with sensitive data. + +![Shared Links report](/images/accessanalyzer/26.1/dashboards-reports/report-shared-links.webp) + +| Filter | What it does | +|---|---| +| **Active Status** | Limits the report by whether a link is still active | +| **Pattern** | Limits the report to the selected sensitive data patterns | +| **Sharing Scope** | Limits the report to anonymous or organization-wide links | +| **Site** | Limits the report to the selected sites | +| **Site Type** | Limits the report to sites of the selected types | + +| Card | What it shows | +|---|---| +| **Shared Resources** | The number of resources with at least one sharing link | +| **Anonymous Links** | The number of links that work for anyone | +| **Organization Links** | The number of links that work for anyone in the organization | +| **Links with Sensitive Data** | The number of links pointing at files with a sensitive data match | +| **Top Sites by Shared Links** | Sites ranked by link count | +| **Open Access Links with Sensitive Data** | A pie chart of sensitive data in anonymous or organization-scoped links | +| **Shared Links Detail** | The detail list, one row per link | + +Needs an Access scan on the SharePoint Online source; the sensitive data cards also need a Sensitive data scan. + +### High-Risk ACLs (SharePoint) + +"SharePoint sites and libraries with overly permissive access control entries." + +The SharePoint equivalent of the file server High Risk ACLs report. It finds sites and libraries where a broad principal holds a permission, and grades each finding by severity. **Critical** means the principal is anonymous, or an anonymous sharing link, or an Everyone-like principal with write, delete, manage, or admin access. **High** means an Everyone-like principal with read-only access, Authenticated Users with write or delete access, or organization-wide sharing. + +![High-Risk ACLs report](/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-high-risk-acls.webp) + +| Filter | What it does | +|---|---| +| **Access Level** | Limits the report to findings at the selected access levels, such as read or write | +| **Risk Category** | Limits the report to the selected categories of finding | +| **Risk Severity** | **Critical**, **High**, or both | +| **Site** | Limits the report to the selected sites | +| **Site Type** | Limits the report to sites of the selected types | + +| Card | What it shows | +|---|---| +| **Number of High Risk ACLs** | The total number of findings | +| **Critical Findings** | The number of findings graded Critical | +| **High Findings** | The number of findings graded High | +| **Sites Affected** | The number of sites with at least one finding | +| **Findings by Risk Category** | A bar chart of findings per category | +| **Findings by Site Type** | A pie chart of findings per site type | +| **Findings by Access Level** | A bar chart of findings per access level | +| **Findings by Risk Severity** | A bar chart of Critical against High | +| **High-Risk ACL Details** | The detail list, one row per finding | + +Needs an Access scan on the SharePoint Online source. + +### Open Access (SharePoint) + +"SharePoint content accessible by all authenticated users without restrictions." + +Open here means reachable by every signed-in user in the tenant. The report counts the sites and resources in that state and, where a Sensitive data scan has run, the exposed files that contain sensitive data. + +![Open Access report](/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-open-access.webp) + +| Filter | What it does | +|---|---| +| **Site** | Limits the report to the selected sites | +| **Site Type** | Limits the report to sites of the selected types | + +| Card | What it shows | +|---|---| +| **Sites with open resources** | The number of sites with at least one open resource | +| **Open Resources** | The number of open resources | +| **Exposed files with Sensitive Data** | The number of open files with a sensitive data match | +| **Top sites by number of open resources** | Sites ranked by open resource count | +| **Top sites by exposed sensitive data (file count)** | Sites ranked by exposed sensitive file count | +| **Open resource details** | The detail list, one row per open resource | + +Needs an Access scan on the SharePoint Online source, plus a Sensitive data scan for the sensitive data cards. + +### Sensitive Data Overview (SharePoint) + +"Summary of sensitive data classifications found across SharePoint sites." + +The SharePoint counterpart of the file server Sensitive Data Overview: which sites hold sensitive data, how much, and of what kind. + +![Sensitive Data Overview report](/images/accessanalyzer/26.1/dashboards-reports/report-sharepoint-sensitive-data-overview.webp) + +| Filter | What it does | +|---|---| +| **Pattern** | Limits the report to matches of the selected sensitive data patterns | +| **Site** | Limits the report to the selected sites | +| **Site Type** | Limits the report to sites of the selected types | + +| Card | What it shows | +|---|---| +| **Sites with Sensitive Data** | The number of sites with at least one match | +| **Files with Sensitive Data** | The number of files with at least one match | +| **Types of Sensitive Data** | How many different patterns matched | +| **Top Sites by Files with Sensitive Data** | Sites ranked by sensitive file count | +| **Sensitive Data Types by File Count** | A pie chart of patterns by how many files matched each | +| **Sensitive Data Summary by Site** | One row per site with its counts | + +Needs a Sensitive data scan on the SharePoint Online source. diff --git a/docs/accessanalyzer/26.1/dashboards-reports/reports/identity.md b/docs/accessanalyzer/26.1/dashboards-reports/reports/identity.md new file mode 100644 index 0000000000..66c69aa770 --- /dev/null +++ b/docs/accessanalyzer/26.1/dashboards-reports/reports/identity.md @@ -0,0 +1,77 @@ +--- +title: Identity reports +description: The AD Users, Entra Users, and Entra Groups reports on the Identity page, with the filters and columns of AD Users. +sidebar_position: 2 +--- + +The **Identity** page holds the reports about accounts rather than content: one for Active Directory (AD) users; one for Entra ID users, with multi-factor authentication (MFA) status, licenses, and sign-in activity; and one for Entra ID groups, with their membership, types, and licenses. Each is a single table, one row per account or group. Only AD Users has filters at the top; you can drill into all three like any other report table. + +Open the page from **Reports > Identity**. [Dashboards and reports](../index.md) covers what's common to every report: the **Refresh** button, how filters apply, drilling into a table, and how fresh the data is. + +![Identity reports list, All tab](/images/accessanalyzer/26.1/dashboards-reports/reports-identity.webp) + +## The Identity page + +The page is a table with two columns, **Report** and **Category**, and the description sits under each report name, as on the [Data reports](data.md) page. Tabs split the list by directory and chips split it by category; each shows a count. + +| Tab | Reports | Category chips | +|---|---|---| +| **All** | 3 | **Users** (2), **Groups** (1) | +| **Active Directory** | 1 | **Users** (1) | +| **Entra ID** | 2 | **Users** (1), **Groups** (1) | + +Switching tabs clears the selected chip. Click a row to open the report; **Back to Identity reports** at the top of the report returns you to the list with your tab and chip intact. + +| Report | Tab | Category | +|---|---|---| +| [AD Users](#ad-users) | Active Directory | Users | +| [Entra Users](#entra-users) | Entra ID | Users | +| [Entra Groups](#entra-groups) | Entra ID | Groups | + +An Identity sync populates all three: one on an Active Directory source for AD Users, one on an Entra ID source for the other two. [Scan types](../../scans/scan-types.md) explains the Identity sync; [Active Directory](../../sources/active-directory.md) and [Entra ID](../../sources/entra-id.md) explain the sources. + +## AD Users + +One row per user account in your synced domains, with columns covering identity, contact details, password state, logon history, and delegation. The filters at the top narrow the rows. + +![AD Users report](/images/accessanalyzer/26.1/dashboards-reports/report-ad-users.webp) + +Every filter is optional, and all but **Distinguished Name** let you pick several values. + +| Filter | Values | +|---|---| +| **Password Age** | **0–30 days**, **31–90 days**, **91–180 days**, **181–365 days**, **Over 365 days**, **Never set** | +| **Last Modified** | **Last 7 days**, **Last 30 days**, **Last 90 days**, **Last year**, **More than 1 year ago** | +| **Created** | **Last 7 days**, **Last 30 days**, **Last 90 days**, **Last year**, **More than 1 year ago** | +| **Days Since Last Logon** | **0–30 days**, **31–90 days**, **91–180 days**, **181–365 days**, **Over 365 days**, **Never logged on** | +| **Domain** | The synced domains | +| **SAM Account Name** | The account names found in the sync | +| **Distinguished Name** | Free text; matches any account whose distinguished name contains it, ignoring case | +| **Department** | The department values found in the sync | + +**SAM Account Name** is the Security Account Manager (SAM) name: the short logon name, without the domain. **Distinguished Name** is the quickest way to scope to an organizational unit: type part of its distinguished name, such as `OU=Finance`, and every account whose distinguished name contains that text matches. + +The columns, in order: + +
+AD Users columns + +**SAM Account Name**, **Display Name**, **First Name**, **Last Name**, **User Principal Name**, **Distinguished Name**, **Canonical Name**, **Common Name**, **Domain**, **Domain Canonical Name**, **Account Status** (Enabled or Disabled), **Created**, **Last Modified**, **Description**, **Admin Count**, **Email**, **Phone**, **Mobile**, **Office**, **Street Address**, **City**, **State**, **Postal Code**, **Country**, **Job Title**, **Department**, **Company**, **Manager**, **Employee ID**, **Password Last Set**, **Password Age (Days)**, **Password Never Expires**, **Account Expires** (Never when no expiry is set), **Smartcard Required**, **MFA Enforced**, **Last Logon**, **Last Logon Timestamp**, **Days Since Last Logon**, **Bad Password Count**, **Last Bad Password**, **Lockout Time**, **Last Logoff**, **Logon Workstations**, **Allowed to Delegate To**, **Allowed to Act on Behalf Of**, **Service Principal Names**, and **Legacy Exchange DN**. + +
+ +Two columns hold the numbers behind the filters: **Password Age (Days)** behind the **Password Age** buckets, and **Days Since Last Logon** behind the filter of the same name. **Account Status** separates enabled accounts from disabled ones. + +For a risk-oriented view of the same accounts (stale users, old passwords, and privileged group membership), open the [Active Directory dashboard](../dashboards/active-directory.md). + +## Entra Users + +One row per user account in your Entra ID tenant, including its MFA status, the licenses assigned to it, and its sign-in activity. The report has no filters; drill into the table to narrow it. + +![Entra Users report](/images/accessanalyzer/26.1/dashboards-reports/report-entra-users.webp) + +## Entra Groups + +One row per group in your Entra ID tenant, with its type, membership, and any licenses assigned through it. Like Entra Users, it has no filters. + +![Entra Groups report](/images/accessanalyzer/26.1/dashboards-reports/report-entra-groups.webp) diff --git a/docs/accessanalyzer/26.1/gettingstarted/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/_category_.json deleted file mode 100644 index 3cefeac060..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Quick Start Guides", - "position": 20, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json deleted file mode 100644 index 78b3bd0452..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "Active Directory", - "position": 20, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md deleted file mode 100644 index ce3c07fa51..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/active-directory.md +++ /dev/null @@ -1,34 +0,0 @@ ---- -title: "Active Directory Scanning Overview" -description: "Overview of Active Directory scanning capabilities and prerequisites in Access Analyzer" -sidebar_position: 1 ---- - -# Active Directory Scanning Overview - -Access Analyzer scans Active Directory to inventory users, groups, and group memberships across one or more domains. It detects security risks including stale accounts, privileged account exposure, excessive group nesting, and accounts with unusual delegation settings. Findings surface in the AD Scan Summary dashboard, giving security teams a clear picture of their identity posture and the data they need to prioritize remediation. - -## Prerequisites - -Before setting up an Active Directory source group, confirm that your environment meets the following requirements. The source group wizard connects to your domain controllers over LDAP or LDAPS, so the Access Analyzer server must be able to reach them on the network and a domain service account must be available with the appropriate read permissions. - -### Service account - -Access Analyzer uses a domain service account to authenticate against your Active Directory domain controllers and read directory objects. The account must be a member of the domain you're scanning and have read access to the directory tree. - -See [Username and Password](../../configurations/service-accounts/username-password.md) to create the service account and [Active Directory Connector Requirements](../../connectors/activedirectory.md) for the full list of required permissions. - -### Network requirements - -| Port | Protocol | Destination | -| --- | --- | --- | -| 389 | TCP | Domain controllers in the source group (LDAP) | -| 636 | TCP | Domain controllers in the source group (LDAPS, if using SSL) | -| 135–139 | TCP | Domain controllers in the source group (RPC) | -| 49152–65535 | TCP | Domain controllers in the source group (RPC dynamic ports) | - -### Before you begin - -- The fully qualified domain name (FQDN) of each domain controller you plan to add. Access Analyzer doesn't support IP addresses — DIGEST-MD5 authentication requires a resolvable hostname and fails if you provide an IP address. -- A Username and Password service account created in Access Analyzer with Read access to the domain. -- Network connectivity from the Access Analyzer server to port 389 or 636 on each domain controller confirmed. diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md deleted file mode 100644 index bf602f10d4..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/reports.md +++ /dev/null @@ -1,49 +0,0 @@ ---- -title: "Reports" -description: "Pre-built dashboard available for Active Directory source groups in Access Analyzer" -sidebar_position: 50 ---- - -# Reports - -After the first Active Directory scan completes, the **AD Scan Summary** dashboard becomes available under **Dashboards**. Use the **Domain** filter at the top of the dashboard to focus on a specific domain. - -## AD Scan Summary - -The dashboard has four sections: a summary row at the top, a **Users** section, a **Groups** section, and an **All Risks** section. - -### Summary row - -| Card | Description | -|------|-------------| -| **Domains** | Number of domains scanned in this source group. | -| **Users** | Total number of user objects collected. | -| **Enabled Users** | Number of enabled user accounts. | -| **Groups** | Total number of group objects collected. | -| **Direct Memberships** | Total number of direct group membership relationships. | - -### Users - -| Card | Description | -|------|-------------| -| **Administrator Accounts** | Number of accounts with a non-zero `adminCount` attribute, indicating current or past AdminSDHolder protection. | -| **New Users** | Number of user accounts created in the past 7 days. | -| **Users with Associated Risks** | Number of users who have at least one detected risk. | -| **User Risks** | Table listing each user with associated risks, including the user name, domain, and risk count. | - -### Groups - -| Card | Description | -|------|-------------| -| **Security Groups** | Number of security groups collected. | -| **DLs** | Number of distribution lists (DLs) collected. | -| **Groups with Associated Risks** | Number of groups that have at least one detected risk. | -| **Group Risks** | Table listing each group with associated risks, including the group name, domain, and risk count. | - -### All Risks - -| Card | Description | -|------|-------------| -| **Risks by Level** | Pie chart showing the distribution of detected risks by severity level (High, Medium, Low). | -| **Riskiest Objects** | Table ranking users and groups by the number of associated risks. | -| **Active Directory Risks** | Full table of all detected risks. Columns include risk type, entity name, domain, detection timestamp, risk level, risk category, and risk description. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md deleted file mode 100644 index f940fdae3c..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/scanning-options.md +++ /dev/null @@ -1,11 +0,0 @@ ---- -title: "Available Scanning Options" -description: "Available scan types for Active Directory source groups" -sidebar_position: 2 ---- - -# Available Scanning Options - -| Scan Option | Description | Available Configurations | -| --- | --- | --- | -| **Active Directory Inventory** | Scans users, groups, and group memberships from all domain controllers in the source group. The first scan runs in full; subsequent scans run differentially, collecting only changes since the last run. | None | diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md deleted file mode 100644 index 44a6fc5b0f..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/schema-reference.md +++ /dev/null @@ -1,273 +0,0 @@ ---- -title: "Active Directory Schema Reference" -sidebar_position: 40 ---- - -# Active Directory Schema Reference - -Access Analyzer stores Active Directory scan data in the `access_analyzer` ClickHouse database. Access Analyzer creates these tables when you set up an Active Directory source group and run a scan. Use this reference when querying scan data directly or integrating Access Analyzer data with external tools. - -:::note -All tables use the `ReplacingMergeTree` engine. Duplicate rows with the same primary key are deduplicated at merge time. Query the `_latest` views to return only the most recent version of each record. -::: - -## Metadata columns - -All tables include the following columns, which Access Analyzer populates during each scan: - -| Column | Type | Description | -|--------|------|-------------| -| `scan_id` | `String` | Identifier of the source group that produced this record. | -| `scan_execution_id` | `String` | Identifier of the specific scan run. | -| `scanned_at` | `DateTime` | Timestamp when the record was written. | - ---- - -## Tables - -### Active Directory User - -Stores one row per user object discovered in an Active Directory scan. - -**Primary key:** `object_guid` - -#### Core identity fields - -| Column | Type | Description | -|--------|------|-------------| -| `object_guid` | `UUID` | Globally unique identifier for the user object. | -| `object_sid` | `String` | Security identifier (SID) of the user. | -| `distinguished_name` | `String` | Full distinguished name (DN) of the user in the directory. | -| `canonical_name` | `Nullable(String)` | Optional. Canonical form of the distinguished name. | -| `sam_account_name` | `String` | Pre-Windows 2000 logon name (sAMAccountName). | -| `user_principal_name` | `Nullable(String)` | Optional. User principal name (UPN) in `user@domain` format. | -| `display_name` | `Nullable(String)` | Optional. Display name shown in directory listings. | -| `given_name` | `Nullable(String)` | Optional. First name of the user. | -| `surname` | `Nullable(String)` | Optional. Last name of the user. | -| `enabled` | `Bool` | Whether the user account is enabled. | -| `when_created` | `Nullable(DateTime)` | Optional. Timestamp when the account was created in the directory. | -| `when_changed` | `Nullable(DateTime)` | Optional. Timestamp of the most recent change to the account. | -| `description` | `Nullable(String)` | Optional. Description field set on the user object. | -| `admin_count` | `Nullable(Int32)` | Optional. Value of the `adminCount` attribute; non-zero values indicate the account is or was protected by AdminSDHolder. | -| `primary_group_id` | `Nullable(Int32)` | Optional. Relative identifier (RID) of the user's primary group. | -| `domain_name` | `Nullable(String)` | Optional. NetBIOS or DNS name of the domain. | -| `domain_canonical_name` | `Nullable(String)` | Optional. Canonical (DNS) name of the domain. | -| `cn` | `Nullable(String)` | Optional. Common name (CN) attribute of the user object. | - -#### Contact information - -| Column | Type | Description | -|--------|------|-------------| -| `mail` | `Nullable(String)` | Optional. Email address. | -| `telephone_number` | `Nullable(String)` | Optional. Office telephone number. | -| `mobile` | `Nullable(String)` | Optional. Mobile telephone number. | -| `office` | `Nullable(String)` | Optional. Office location. | -| `street_address` | `Nullable(String)` | Optional. Street address. | -| `city` | `Nullable(String)` | Optional. City. | -| `state` | `Nullable(String)` | Optional. State or province. | -| `postal_code` | `Nullable(String)` | Optional. Postal or ZIP code. | -| `country` | `Nullable(String)` | Optional. Country or region. | - -#### Organizational information - -| Column | Type | Description | -|--------|------|-------------| -| `job_title` | `Nullable(String)` | Optional. Job title. | -| `department` | `Nullable(String)` | Optional. Department. | -| `company` | `Nullable(String)` | Optional. Company or organization name. | -| `manager_dn` | `Nullable(String)` | Optional. Distinguished name of the user's manager. | -| `employee_id` | `Nullable(String)` | Optional. Employee identifier. | - -#### Security information - -| Column | Type | Description | -|--------|------|-------------| -| `user_account_control` | `Nullable(Int32)` | Optional. Bitmask value of the `userAccountControl` attribute controlling account behavior and flags. | -| `password_last_set` | `Nullable(DateTime)` | Optional. Timestamp when the password was last changed. | -| `password_never_expires` | `Nullable(Bool)` | Optional. Whether the password is set to never expire. | -| `account_expires` | `Nullable(String)` | Optional. Expiration date of the account, stored as a string representation of the directory value. | -| `logon_hours` | `Nullable(String)` | Optional. Bitmask string representing the hours during which the user is permitted to log on. | -| `logon_workstations` | `Array(String)` | List of workstations the user is permitted to log on to; empty array indicates no restriction. | -| `smartcard_required` | `Nullable(Bool)` | Optional. Whether the account requires a smart card to log on. | -| `mfa_enforced` | `Nullable(Bool)` | Optional. Whether multi-factor authentication is enforced for this account. | -| `is_deleted` | `Boolean` | Whether the user object has been soft-deleted. Rows where `is_deleted = 1` are excluded from the `active_directory_user_latest` view. | - -#### Activity information - -| Column | Type | Description | -|--------|------|-------------| -| `last_logon` | `Nullable(DateTime)` | Optional. Most recent logon timestamp from the domain controller that serviced the last logon. Not replicated across domain controllers. | -| `last_logon_timestamp` | `Nullable(DateTime)` | Optional. Replicated logon timestamp (`lastLogonTimestamp`); updated at intervals and may lag behind the actual last logon by up to 14 days. | -| `bad_pwd_count` | `Nullable(Int32)` | Optional. Number of consecutive failed logon attempts. | -| `bad_password_time` | `Nullable(DateTime)` | Optional. Timestamp of the last failed logon attempt. | -| `lockout_time` | `Nullable(DateTime)` | Optional. Timestamp when the account was locked out; `NULL` or zero indicates the account isn't locked. | -| `last_logoff` | `Nullable(DateTime)` | Optional. Timestamp of the last logoff. | - -#### Delegation information - -| Column | Type | Description | -|--------|------|-------------| -| `ms_ds_allowed_to_act_on_behalf_of` | `Array(String)` | List of security descriptors for accounts permitted to delegate to this account using resource-based constrained delegation. | -| `ms_ds_allowed_to_delegate_to` | `Array(String)` | List of service principal names (SPNs) this account is permitted to delegate to using constrained delegation. | -| `ms_ds_supported_encryption_types` | `Nullable(Int32)` | Optional. Bitmask of Kerberos encryption types supported by this account. | -| `service_principal_name` | `Array(String)` | List of SPNs registered to this account. | -| `legacy_exchange_dn` | `Nullable(String)` | Optional. Legacy Exchange distinguished name, used for mail routing compatibility. | -| `ms_ds_user_account_control_computer` | `Nullable(Int32)` | Optional. Computer-specific `userAccountControl` flags stored on the user object in hybrid environments. | - -**Relations** - -| Related table | Join column | Description | -|---|---|---| -| `active_directory_group_membership` | `object_sid` via `foreign_sid` | Resolves groups that include this user when the user was added by SID from a foreign domain. | -| `active_directory_group_membership` | `distinguished_name` via `member_dn` | Resolves groups that include this user when the user was added by DN. | -| `active_directory_user_custom_attribute` | `object_guid` | Returns custom attribute values collected for this user. | -| `active_directory_effective_group_membership` | `object_guid` via `member_object_guid` | Returns all groups this user belongs to, including nested memberships. | - ---- - -### Active Directory Group - -Stores one row per group object discovered in an Active Directory scan. - -**Primary key:** `object_guid` - -| Column | Type | Description | -|--------|------|-------------| -| `object_guid` | `UUID` | Globally unique identifier for the group object. | -| `object_sid` | `String` | Security identifier (SID) of the group. | -| `distinguished_name` | `String` | Full distinguished name (DN) of the group in the directory. | -| `sam_account_name` | `Nullable(String)` | Optional. Pre-Windows 2000 name of the group. | -| `name` | `Nullable(String)` | Optional. Display name of the group. | -| `group_scope` | `Nullable(String)` | Optional. Scope of the group: `DomainLocal`, `Global`, or `Universal`. | -| `group_type` | `Nullable(String)` | Optional. Type of the group: `Security` or `Distribution`. | -| `admin_count` | `Nullable(Int32)` | Optional. Value of the `adminCount` attribute; non-zero values indicate the group is or was protected by AdminSDHolder. | -| `primary_group_id` | `Nullable(Int32)` | Optional. Relative identifier (RID) associated with this group when it is used as a primary group. | -| `domain_name` | `Nullable(String)` | Optional. NetBIOS or DNS name of the domain. | -| `domain_canonical_name` | `Nullable(String)` | Optional. Canonical (DNS) name of the domain. | -| `cn` | `Nullable(String)` | Optional. Common name (CN) attribute of the group object. | -| `mail` | `Nullable(String)` | Optional. Email address associated with the group. | -| `is_deleted` | `Boolean` | Whether the group object has been soft-deleted. Rows where `is_deleted = 1` are excluded from the `active_directory_group_latest` view. | - -**Relations** - -| Related table | Join column | Description | -|---|---|---| -| `active_directory_group_membership` | `distinguished_name` via `group_dn` | Lists the direct members of this group. | -| `active_directory_effective_group_membership` | `object_guid` via `group_object_guid` | Lists all effective members of this group, including nested members. | - ---- - -### Active Directory Group Membership - -Stores one row per direct membership relationship between a group and a member object (user or group). Nesting isn't flattened in this table; use `active_directory_effective_group_membership` for flattened membership. - -**Primary key:** `(group_dn, member_dn)` - -| Column | Type | Description | -|--------|------|-------------| -| `group_dn` | `String` | Distinguished name (DN) of the group. | -| `member_dn` | `String` | Distinguished name (DN) of the member object. | -| `foreign_sid` | `Nullable(String)` | Optional. SID of the member when the member is from a foreign (trusted) domain and a DN isn't available. | - -**Relations** - -| Related table | Join column | Description | -|---|---|---| -| `active_directory_group` | `group_dn` = `distinguished_name` | Resolves the group record for this membership row. | -| `active_directory_user` | `member_dn` = `distinguished_name` | Resolves the user record for this membership row when the member is a user. | -| `active_directory_group` | `member_dn` = `distinguished_name` | Resolves the group record for this membership row when the member is a nested group. | -| `active_directory_user` | `foreign_sid` = `object_sid` | Resolves a foreign-domain user by SID when `foreign_sid` is set. | -| `active_directory_group` | `foreign_sid` = `object_sid` | Resolves a foreign-domain group by SID when `foreign_sid` is set. | - ---- - -### Active Directory User Custom Attribute - -Stores custom Active Directory attribute values collected for user objects during a scan. Each row represents one attribute key-value pair for one user. An attribute with no value produces a row with `attr_value = NULL`. - -**Primary key:** `(object_guid, attr_name)` - -| Column | Type | Description | -|--------|------|-------------| -| `object_guid` | `UUID` | Globally unique identifier of the user object. Joins to `active_directory_user.object_guid`. | -| `attr_name` | `String` | LDAP attribute name, as configured in the source group settings. | -| `attr_value` | `Nullable(String)` | Optional. String representation of the attribute value. | - -**Relations** - -| Related table | Join column | Description | -|---|---|---| -| `active_directory_user` | `object_guid` | Returns the full user record for this custom attribute row. | - ---- - -### Active Directory Effective Group Membership - -Stores the fully flattened, transitively resolved group membership graph. The `active_directory_effective_group_membership_mv` materialized view populates this table and refreshes on a schedule after each scan. Each row represents one effective membership relationship at a given nesting depth. - -**Engine:** `MergeTree` (not `ReplacingMergeTree`). Access Analyzer rebuilds the table on each refresh rather than deduplicating it by version. - -**Primary key:** `(group_object_guid, member_object_guid)` - -| Column | Type | Description | -|--------|------|-------------| -| `group_object_guid` | `UUID` | Globally unique identifier of the group. Joins to `active_directory_group.object_guid`. | -| `member_object_guid` | `UUID` | Globally unique identifier of the effective member (user or group). Joins to `active_directory_user.object_guid` or `active_directory_group.object_guid`. | -| `nesting_level` | `Int32` | Depth of the membership relationship. A value of `0` indicates direct membership; higher values indicate the number of intermediate groups. | - -**Relations** - -| Related table | Join column | Description | -|---|---|---| -| `active_directory_group` | `group_object_guid` = `object_guid` | Resolves the group name and attributes for this membership row. | -| `active_directory_user` | `member_object_guid` = `object_guid` | Resolves the user record when the effective member is a user. | -| `active_directory_group` | `member_object_guid` = `object_guid` | Resolves the group record when the effective member is a nested group. | - ---- - -## Views - -Access Analyzer creates views that simplify common queries. Use views in preference to querying base tables directly. - -### Deduplication views - -These views apply `FINAL` to the underlying `ReplacingMergeTree` tables to return only the most recent version of each record. Use these as the starting point for any query against Active Directory data. - -| View | Base table | Description | -|------|------------|-------------| -| `active_directory_user_latest` | `active_directory_user` | Returns the most recent version of each user record, deduplicated by `object_guid`, excluding soft-deleted users (`is_deleted = 1`). | -| `active_directory_group_latest` | `active_directory_group` | Returns the most recent version of each group record, deduplicated by `object_guid`, excluding soft-deleted groups (`is_deleted = 1`). | -| `active_directory_group_membership_latest` | `active_directory_group_membership` | Returns the most recent version of each group membership row, deduplicated by `(group_dn, member_dn)`. | -| `active_directory_user_custom_attribute_latest` | `active_directory_user_custom_attribute` | Returns the most recent version of each custom attribute row, deduplicated by `(object_guid, attr_name)`. | - -### Resolution views - -These views resolve raw membership data into UUID-keyed relationships. - -| View | Description | -|------|-------------| -| `active_directory_group_membership_resolved` | Joins `active_directory_group_membership_latest` to the user and group tables to produce a resolved membership graph keyed by `(group_object_guid, member_object_guid)`. Handles both same-domain members (matched by DN) and foreign-domain members (matched by SID). Excludes deleted objects. Used as the source for `active_directory_effective_group_membership_mv`. | - -### Risk views - -These views surface specific account and group hygiene conditions. Each view returns rows in a common shape: `risk_type`, `entity_id`, `entity_name`, `domain`, `detection_timestamp`, and `additional_context`. The `active_directory_risks_summary` view aggregates all risk views into a single result set enriched with catalog metadata. - -| View | Description | -|------|-------------| -| `active_directory_empty_groups` | Groups that have no effective members. | -| `active_directory_single_member_groups` | Groups that have exactly one effective member. | -| `active_directory_large_groups` | Groups that have more than 500 effective members. | -| `active_directory_duplicate_groups_mv` | Groups whose effective membership set is identical to that of at least one other group. | -| `active_directory_circular_nesting_mv` | Groups involved in circular nesting or with a nesting depth of 10 or more. | -| `active_directory_stale_users` | Enabled user accounts with no logon activity in the past 90 to 365 days. | -| `active_directory_very_stale_users` | Enabled user accounts with no logon activity for more than 365 days. | -| `active_directory_isolated_users` | Enabled user accounts that belong to no groups. | -| `active_directory_no_logon_users` | Enabled user accounts with no recorded logon timestamp. | -| `active_directory_password_never_expires` | Enabled user accounts configured with a non-expiring password. | -| `active_directory_password_not_required` | Enabled user accounts where the `PASSWD_NOTREQD` flag is set in `user_account_control`. | -| `active_directory_old_passwords` | Enabled user accounts whose password has not changed in more than 90 days. | -| `active_directory_dc_logon_rights` | Enabled users who are effective members of privileged groups that grant domain controller logon rights (for example, Domain Admins, Enterprise Admins). | -| `active_directory_risks_summary_mv` | Union of all individual risk views. Returns one row per detected risk. | -| `active_directory_risks_summary` | Enriches `active_directory_risks_summary_mv` with risk level, category, and description from the `active_directory_risk_catalog` reference table. Use this view to query all risks with their human-readable metadata. | -| `active_directory_risks_by_domain` | Aggregates risk counts by domain and risk type, sourced from `active_directory_risks_summary_mv`. | -| `active_directory_group_member_counts` | Returns the total effective member count for each group. Intermediate view used by the group risk views. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md deleted file mode 100644 index 4304eb9741..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/active-directory/set-up-source-group.md +++ /dev/null @@ -1,41 +0,0 @@ ---- -title: "Set Up Active Directory Source Group" -description: "Configure an Active Directory source group in Access Analyzer" -sidebar_position: 3 ---- - -# Set Up Active Directory Source Group - -1. Navigate to **Configuration** > **Source Groups** and click **Add Source**. The source group wizard opens. -2. Select **Active Directory** and click **Next**. -3. Enter a **Source Group Name**. -4. Select a service account from the **Service Account** dropdown, or click **+** to create one inline. Service accounts store the credentials Access Analyzer uses to connect to your domain controllers. See [Service Accounts](../../configurations/service-accounts/overview.md) for details. -5. Click **Add** under **Domain Controllers**, then select **Add Manually**. -6. Enter the following for each domain controller: - - **Server Name / IP** — The fully qualified domain name (FQDN) of the domain controller (for example, `dc01.corp.example.com`). Access Analyzer doesn't support IP addresses. To add multiple domain controllers, separate entries with a comma or press **Enter** after each one. - - **Domain** — The DNS domain name (for example, `corp.example.com`). Applies to all domain controllers you added in this step. - - **Port** — The LDAP port. Default is `389`. Use `636` for LDAPS. -7. Click **Add domain controller**, then click **Done**. Repeat steps 5–7 for each additional domain. -8. If your domain controllers use self-signed certificates on port 636, select **Ignore SSL errors**. -9. Click **Test Connection** to verify connectivity. Each domain controller displays a **Connected** or **Failed** status. Resolve any failures before proceeding. -10. Click **Next**. -11. Under **Scanner Location**, select **System scanner** to run scans from the Access Analyzer service, or select **Custom scanner** to use a deployed scanner. See [Scanners](../../configurations/source-groups/scanners/overview.md) for details. -12. Under **Scan Schedule**, select when to run the scan: - - **Now** — Starts the scan immediately after setup completes. - - **At** — Runs the scan once at a specific date and time. - - **Advanced** — Runs the scan on a recurring schedule defined by a cron expression. -13. Click **Complete Setup**. - -## What happens next - -Access Analyzer creates the source group and a scan for each domain controller you added. If you selected **Now**, the Active Directory Inventory scan starts immediately. - -To check scan progress, navigate to **Configuration** > **Scan Executions**. - -## Edit a source group - -To modify an existing Active Directory source group, navigate to **Configuration** > **Source Groups**, select the source group, and click **Edit**. The wizard reopens with your current configuration pre-populated. You can update the source group name, service account, domain controllers, and scan schedule. - -:::note -Updating the service account affects all domain controllers in the source group, as they share a single set of credentials. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md deleted file mode 100644 index 0ff6b763f0..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/entra-id/entra-id.md +++ /dev/null @@ -1,38 +0,0 @@ ---- -title: "Entra ID Scanning Overview" -description: "Overview of Entra ID scanning capabilities and prerequisites in Access Analyzer" -sidebar_position: 1 ---- - -# Entra ID Scanning Overview - -Access Analyzer connects to Microsoft Entra ID to synchronize users, groups, role assignments, and Microsoft Information Protection (MIP) sensitivity labels from your tenant. Access Analyzer retrieves MIP labels — defined in Microsoft Purview — during the scan and makes them available in the Sensitive Data configuration, where you can map them to sensitive data types for use in file server and SharePoint Online scans. - -:::note -Access Analyzer collects MIP sensitivity labels during the Entra ID sync, and they become available for use in **File Server** and **SharePoint Online** Sensitive Data scans. Run the Entra ID scan at least once before enabling MIP label detection in those source groups. -::: - -## Prerequisites - -Before setting up an Entra ID source group, confirm that your environment meets the following requirements. The source group wizard connects to Microsoft Entra ID over HTTPS using a registered application's client credentials, so the Access Analyzer server must be able to reach the Microsoft identity platform, and you must configure an app registration in your tenant with the required API permissions. - -### Service account - -Access Analyzer uses a Client ID and Secret service account to authenticate with Microsoft Entra ID via the Microsoft Graph API. This requires a registered application in your Entra ID tenant with the appropriate API permissions granted and a client secret generated for that application. - -See [Client ID/Secret service account](../../configurations/service-accounts/client-id-secret.md) to create the service account and [Entra ID](../../connectors/entra-id/overview.md) for instructions on registering the application and granting the required permissions. - -### Network requirements - -| Protocol | Port | Destination | -| --- | --- | --- | -| HTTPS | 443 | Microsoft identity platform (`login.microsoftonline.com`) | -| HTTPS | 443 | Microsoft Graph API (`graph.microsoft.com`) | - -### Before you begin - -- A registered application in your Entra ID tenant with the required API permissions granted, including `InformationProtectionPolicy.Read.All` for MIP label retrieval. -- The application's **Tenant ID** and **Client ID**. -- A client secret generated for the application. -- A Client ID and Secret service account created in Access Analyzer. -- Network connectivity from the Access Analyzer server to port 443 confirmed. diff --git a/docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md deleted file mode 100644 index b829ef2d77..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/entra-id/reports.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "Reports" -description: "Pre-built dashboard available for Entra ID source groups in Access Analyzer" -sidebar_position: 50 ---- - -# Reports - -After the first Entra ID scan completes, the **Entra ID Scan Summary** dashboard becomes available under **Dashboards**. Use the **Tenant** filter at the top of the dashboard to focus on a specific Entra ID tenant. - -## Entra ID Scan Summary - -The dashboard is organized into three sections: a summary row at the top, an **Identities** section, and a **MIP Labels** section. - -### Summary row - -| Card | Description | -|------|-------------| -| **Users** | Total number of user objects synced from the tenant. | -| **Groups** | Total number of group objects synced from the tenant. | -| **Roles** | Total number of Azure AD role definitions retrieved. | -| **MIP Labels** | Total number of Microsoft Information Protection (MIP) sensitivity labels retrieved from the tenant. | - -### Identities - -| Card | Description | -|------|-------------| -| **Guest Users** | Number of user accounts with `userType = Guest`. | -| **MFA Configured** | Number of users with multi-factor authentication configured. | -| **Group Memberships** | Total number of direct group membership records. | -| **Role Assignments** | Total number of role assignment records (user or group assigned to a role). | - -### MIP Labels - -| Card | Description | -|------|-------------| -| **Active Labels** | Number of sensitivity labels active in the tenant. | -| **Label List** | Table listing all retrieved labels, including label name, classification level, and whether the label is active. | - -:::note -You can find the MIP labels retrieved here under **Configuration** > **Sensitive Data**, where you can map them to sensitive data types for use in File Server and SharePoint Online scans. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md deleted file mode 100644 index 85098ecc6d..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/entra-id/scanning-options.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -title: "Scanning options" -description: "Available scan types for Entra ID source groups" -sidebar_position: 2 ---- - -# Scanning options - -| Scan type | Description | -| --- | --- | -| **Users, Groups, and Roles** | Synchronizes users, groups, and role assignments from the Entra ID tenant. The first scan runs in full; subsequent scans collect only changes since the last run. Access Analyzer automatically retrieves Microsoft Information Protection (MIP) sensitivity labels as part of every scan. | - -## MIP label retrieval - -When an Entra ID source group runs, Access Analyzer automatically retrieves Microsoft Information Protection (MIP) sensitivity labels defined in the tenant. You can find these labels on the **Configuration** > **Sensitive Data** page, where you can map them to sensitive data types for use in file server and SharePoint Online scans. - -There are no per-source-group configuration options for MIP label retrieval — it runs automatically as part of every scan. To configure how labels are applied to files, see [Sensitive Data Configuration](../../configurations/sensitive-data.md). diff --git a/docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md deleted file mode 100644 index e558b9fa2a..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/entra-id/schema-reference.md +++ /dev/null @@ -1,122 +0,0 @@ ---- -title: "Schema reference" -sidebar_position: 40 ---- - -# Entra ID schema reference - -Access Analyzer stores Entra ID scan data in the `access_analyzer` ClickHouse database. Access Analyzer populates the following tables when you set up an Entra ID source group and run a scan. Use this reference when querying scan data directly or integrating Access Analyzer data with external tools. - -Access Analyzer stores Entra ID data in shared tables that serve multiple connector types. The `tenancyReference` column scopes each row to your tenant and corresponds to your Entra ID tenant. - -:::note -All tables use the `ReplacingMergeTree` engine, which deduplicates rows with the same primary key at merge time. Use the `FINAL` keyword or query the available `_latest` views to return only the most recent version of each record. -::: - -## Metadata columns - -All tables include the following columns populated by Access Analyzer during each scan: - -| Column | Type | Description | -|--------|------|-------------| -| `tenancyReference` | `UUID` | Identifier of the Entra ID tenant that produced this record. | -| `connectorReference` | `UUID` | Identifier of the connector job run. | -| `fullCrawlTimestampUtc` | `DateTime64(6)` | Timestamp of the most recent full sync for this tenant. | -| `crawlTimestampUtc` | `DateTime64(6)` | Timestamp when this record was written. Used as the version column for deduplication. | - ---- - -## Tables - -### principals - -Stores users, groups, and roles synced from the Entra ID tenant. Each row represents one identity object. - -**Primary key:** `entityId` - -#### Core identity fields - -| Column | Type | Description | -|--------|------|-------------| -| `entityId` | `UUID` | Unique identifier for this identity object within Access Analyzer. | -| `sourceSystemId` | `String` | Object ID from Entra ID (the Azure AD `objectId`). | -| `name` | `String` | Internal name of the object. | -| `displayName` | `String` | Display name as it appears in Entra ID. | -| `emailAddress` | `Nullable(String)` | Optional. Primary email address. | -| `firstName` | `Nullable(String)` | Optional. Given name (users only). | -| `lastName` | `Nullable(String)` | Optional. Surname (users only). | -| `isDeleted` | `Bool` | Whether the object has been soft-deleted. | -| `deletedDate` | `Nullable(DateTime64(6))` | Optional. Timestamp when the object was deleted. | -| `lastModified` | `Nullable(DateTime64(6))` | Optional. Timestamp of the most recent change. | -| `lastActive` | `Nullable(DateTime64(6))` | Optional. Timestamp of the most recent sign-in activity. | - -#### User-specific fields - -| Column | Type | Description | -|--------|------|-------------| -| `azureAdUserPrincipalName` | `Nullable(String)` | Optional. User principal name (UPN) in `user@domain` format. | -| `azureAdUserType` | `Nullable(String)` | Optional. Type of user account: `Member` or `Guest`. | -| `azureAdMfaConfigured` | `Nullable(Bool)` | Optional. Whether MFA is configured for the user. | -| `disabled` | `Nullable(Bool)` | Optional. Whether the user account is disabled. | -| `department` | `Nullable(String)` | Optional. Department attribute from Entra ID. | -| `jobTitle` | `Nullable(String)` | Optional. Job title attribute from Entra ID. | -| `lastDirSyncTime` | `Nullable(DateTime64(6))` | Optional. Last directory sync timestamp for hybrid-joined accounts. | - -#### Group-specific fields - -| Column | Type | Description | -|--------|------|-------------| -| `azureAdGroupType` | `Nullable(String)` | Optional. Group type: `Security`, `Distribution`, or `M365`. | -| `isSecurityEnabled` | `Nullable(Bool)` | Optional. Whether the group is security-enabled. | -| `isMailEnabled` | `Nullable(Bool)` | Optional. Whether the group is mail-enabled. | -| `memberCount` | `Nullable(Int32)` | Optional. Number of direct members. | -| `dynamicMembershipEnabled` | `Nullable(Bool)` | Optional. Whether the group uses dynamic membership rules. | - -#### Role-specific fields - -| Column | Type | Description | -|--------|------|-------------| -| `azureRoleTemplateId` | `Nullable(String)` | Optional. Stable template ID for built-in roles (consistent across tenants). | -| `azureRoleAllowedPrincipalTypes` | `Nullable(String)` | Optional. Principal types that can be assigned to this role. | - ---- - -### memberships - -Stores group membership records — both direct and nested. Each row represents one membership relationship. - -**Primary key:** `(groupId, memberId, role)` - -| Column | Type | Description | -|--------|------|-------------| -| `groupId` | `UUID` | `entityId` of the group. Joins to `principals.entityId`. | -| `memberId` | `UUID` | `entityId` of the member (user, group, or service principal). Joins to `principals.entityId`. | -| `membershipSource` | `String` | How the membership was established: `Direct`, `Nested`, or `Dynamic`. | -| `role` | `String` | Role of the member within the group: `Owner`, `Member`, or `Guest`. | -| `expandedFromGroupId` | `Nullable(UUID)` | Optional. For nested memberships, the intermediate group through which this membership was resolved. | -| `isDeleted` | `Bool` | Whether this membership record has been removed. | - ---- - -### sensitivity_labels - -Stores Microsoft Information Protection (MIP) sensitivity labels retrieved from the tenant during an Entra ID scan. - -**Primary key:** `sensitivitylabelId` - -| Column | Type | Description | -|--------|------|-------------| -| `sensitivitylabelId` | `UUID` | Unique identifier for this label within Access Analyzer. | -| `name` | `String` | Internal name of the label. | -| `displayName` | `String` | Display name shown to users in Microsoft 365 applications. | -| `description` | `Nullable(String)` | Optional. Description of the label's purpose. | -| `isActive` | `Bool` | Whether the label is active in the tenant. | -| `isDeleted` | `Bool` | Whether the label has been deleted. | -| `classificationLevel` | `Nullable(String)` | Optional. Classification level assigned to the label. | -| `priority` | `Int32` | Display order priority. Lower values appear first. | -| `parentLabelId` | `Nullable(UUID)` | Optional. For sublabels, the `sensitivitylabelId` of the parent label. | -| `labelId` | `Nullable(String)` | Microsoft GUID for the label as defined in Microsoft Purview. | - -:::note -Labels stored here are the source data for MIP label mapping in **Configuration** > **Sensitive Data**. After you map labels to sensitive data types, they are available for detection during File Server and SharePoint Online scans. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md deleted file mode 100644 index 62e5af73db..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/entra-id/set-up-source-group.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: "Set up an Entra ID source group" -description: "Configure an Entra ID source group in Access Analyzer" -sidebar_position: 3 ---- - -# Set up an Entra ID source group - -1. Navigate to **Configuration** > **Source Groups** and click **Add Source**. The source group wizard opens. - -2. Select **Entra ID** and click **Next**. - -3. Enter a **Source Group Name**. - -4. Select a service account from the **Service Account** dropdown, or click **+** to create one inline. Entra ID requires a **Client ID and Secret** service account type. See [Service Accounts](../../configurations/service-accounts/overview.md) for details. - -5. Enter the **Tenant ID** for your Entra ID directory. This must be a valid UUID (for example, `550e8400-e29b-41d4-a716-446655440000`). - -6. Click **Test Connection** to verify that Access Analyzer can authenticate to your Entra ID tenant. Resolve any failures before proceeding. - -7. Click **Next**. - -8. Under **Scan Schedule**, select when to run the scan: - - - **Now** — Starts the scan immediately after setup completes. - - **At** — Runs the scan once at a specific date and time. - - **Advanced** — Runs the scan on a recurring schedule defined by a cron expression. - -9. Click **Complete Setup**. - -## What happens next - -Access Analyzer creates the source group and begins syncing users, groups, and roles from your Entra ID tenant. If you selected **Now**, the scan starts immediately. Access Analyzer retrieves Microsoft Information Protection (MIP) sensitivity labels automatically as part of the scan. - -To check scan progress, navigate to **Configuration** > **Scan Executions**. - -## Edit a source group - -To modify an existing Entra ID source group, navigate to **Configuration** > **Source Groups**, select the source group, and click **Edit**. The wizard reopens with your current configuration pre-populated. You can update the source group name, service account, tenant ID, and scan schedule. - -:::note -Updating the service account replaces the client credentials used to authenticate with Entra ID. Ensure the new service account has the required API permissions before saving. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json b/docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json deleted file mode 100644 index dbe2c40136..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/_category_.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "label": "File Servers", - "position": 30, - "collapsed": true, - "collapsible": true -} diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md deleted file mode 100644 index 6c7dcf2971..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/file-servers.md +++ /dev/null @@ -1,50 +0,0 @@ ---- -title: "File Server Scanning Overview" -description: "Overview of file server scanning capabilities and prerequisites in Access Analyzer" -sidebar_position: 1 ---- - -# File Server Scanning Overview - -Access Analyzer scans file servers over SMB to map share permissions, folder-level ACLs, and file ownership across your environment. It can also scan file contents to locate sensitive data and, if you configure activity monitoring, track file access events over time. Reports surface open access, broken inheritance, direct user permissions, and sensitive data exposure — giving security and compliance teams the visibility they need to reduce unnecessary access and meet data protection requirements. - -## Supported platforms - -Access Analyzer scans any SMB-compatible file server. For platform-specific requirements, see the connector page for your environment: - -- [CIFS / SMB File Share](../../connectors/file-servers/cifs.md) — Windows file servers and Samba -- [NetApp ONTAP](../../connectors/file-servers/netapp.md) -- [Dell Isilon / PowerScale](../../connectors/file-servers/isilon-powerscale.md) -- [Dell Unity](../../connectors/file-servers/dell-unity.md) -- [Dell EMC VNX](../../connectors/file-servers/vnx.md) -- [Dell EMC Celerra](../../connectors/file-servers/celerra.md) - -## Prerequisites - -Before setting up a file server source group, confirm that your environment meets the following requirements. The source group wizard connects to your file servers over SMB, so the Access Analyzer server must be able to reach them on the network and a service account must be available with read access to the shares you want to scan. - -### Service account - -Access Analyzer uses a service account with a username and password to authenticate against your file servers over SMB and enumerate shares, permissions, and file contents. The account needs read access to the shares and permission to read object security descriptors. - -See [Username and Password](../../configurations/service-accounts/username-password.md) to create the service account and [CIFS / SMB File Share](../../connectors/file-servers/cifs.md) for the full permission requirements. - -### Network requirements - -| Port | Protocol | Destination | -|------|----------|-------------| -| 445 | TCP | File servers in the source group | - -### Before you begin - -- The hostname or IP address of each file server you plan to add. -- A Username and Password service account created in Access Analyzer with read access to the target file servers. -- Network connectivity from the Access Analyzer server to port 445 on each file server confirmed. - -:::note -When you add a file server source group, Access Analyzer automatically creates a **Local Users and Groups** scan for each host. This scan collects local user and group accounts directly from the file server and runs alongside your Access and Sensitive Data scans. -::: - -:::note -File activity reports — including open, modify, and delete events, and anomaly detection — require a separate **Netwrix Activity Monitor** deployment. Without Activity Monitor, activity-related reports will show no data. See [File Activity Monitoring](../../index.md#key-capabilities) for details. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md deleted file mode 100644 index 6cc8fd73ac..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/reports.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -title: "Reports" -description: "Pre-built reports available for File Servers source groups in Access Analyzer" -sidebar_position: 50 ---- - -# Reports - -File Servers source groups include a set of pre-built reports that answer common security questions about permissions, sensitive data exposure, access patterns, and data content across your CIFS/SMB file shares. Reports are available under the Reports section after the first scan completes and update each time a scan runs. - -:::note -Activity reports (Activity Investigation and Sensitive Data Activity) require you to configure Netwrix Activity Monitor (NAM) so it streams events to Access Analyzer. See [Activity Monitor Integration](../../configurations/activity-monitor-integration.md) for setup instructions. -::: - -## Available reports - -| Location | Report | Description | -|----------|--------|-------------| -| Access / Broken Inheritance | Broken Inheritance | Lists shares and folders with broken permission inheritance, meaning the folder's ACL no longer follows its parent. Use this report to find locations where custom permission assignments may have introduced inconsistencies or unexpected access. | -| Access / Domain User ACLs | Domain User ACLs | Shows share and folder permissions assigned directly to domain user accounts. Use this report to identify accounts with direct ACL entries that should be managed through groups instead. | -| Access / High Risk ACLs | High Risk ACLs | Identifies folders where broad trustees such as Everyone, Authenticated Users, or Domain Users appear in the access control list. Use this report to locate and remediate over-permissioned folders that expose data to wide audiences. | -| Access / Local Administrators | Local Administrators | Lists local administrator accounts and the hosts where they hold that privilege. Use this report to identify non-standard or unauthorized local administrator assignments across your file servers. | -| Access / Missing Full Control | Missing Full Control | Lists folders where no trustee holds Full Control permission. Use this report to identify folders that may lack a clear owner or administrator and address potential access management gaps. | -| Access / Open Access | Open Access | Identifies folders and shares accessible to broad groups or where sensitive data is reachable without restriction. Use this report to prioritize remediation of the most exposed locations in your file server environment. | -| Access / Probable Owner | Probable Owner | Identifies the most likely owner for each share based on access patterns and file activity. Use this report to assign data ownership and support data governance workflows. | -| Access / Share Audit | Share Audit | Provides a detailed breakdown of share-level attributes including scan status, last scanned date, file counts, object counts, and active users. Use this report to confirm scan coverage and review the overall state of each share. | -| Activity / Activity Investigation | Activity Investigation | Displays file system events filtered by date range, user, path, and event type. Use this report to trace the actions of a specific user or investigate changes to a specific file or folder. | -| Content / Empty Shares | Empty Shares | Lists shares that contain no files. Use this report to identify shares that can be reviewed for decommissioning or consolidation. | -| Content / Largest Shares | Largest Shares | Ranks file shares by total size. Use this report to identify shares that consume the most storage and prioritize them for review or cleanup. | -| Content / Nested Shares | Nested Shares | Identifies shares that nest inside other shares, creating multiple access paths to the same data with potentially different permissions. Use this report to find and resolve configurations that complicate permission management and access auditing. | -| Content / Stale Content | Stale Content | Identifies files and shares that haven't been accessed within a configurable threshold. Use this report to locate data that may be a candidate for archiving, deletion, or access review. | -| Sensitive Data / Sensitive Data Activity | Sensitive Data Activity | Shows file system events involving files that contain sensitive data. You can filter results by date range, event type, user, and classification taxonomy. Use this report to identify who is reading, modifying, or deleting sensitive files and to detect potential data exfiltration or misuse. | -| Sensitive Data / Sensitive Data Overview | Sensitive Data Overview | Provides a high-level summary of sensitive data scan findings across CIFS/SMB file shares, including the number of files with matches, classification terms found, and distribution by host and share. Use this report as a starting point for understanding where sensitive data lives in your file server environment. | -| Sensitive Data / Share Audit | Share Audit | Shows share-level details in the context of sensitive data findings, including which shares contain files with sensitive data matches. Use this report to understand sensitive data distribution across shares and prioritize remediation. | -| Sensitive Data / Stale Data | Stale Data | Identifies files containing sensitive data that haven't been accessed recently. Use this report to find aging sensitive content that may no longer be actively used but still carries exposure risk. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md deleted file mode 100644 index 6fb261c24a..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/scanning-options.md +++ /dev/null @@ -1,29 +0,0 @@ ---- -title: "Available Scanning Options" -description: "Available scan types and configuration options for file server source groups" -sidebar_position: 2 ---- - -# Available Scanning Options - -| Scan Option | Description | Available Configurations | -| --- | --- | --- | -| **Access** | Scans file server permissions and access controls to identify who has access to what. | Share selection (all shares or custom), file-level permissions, concurrent workers (1–20), scan depth | -| **Sensitive Data** | Scans file contents for sensitive data patterns such as personally identifiable information (PII), credentials, protected health information (PHI), and financial records. The first scan runs in full; subsequent scans run differentially, collecting only changes since the last run. | Share selection (all shares or custom), sensitive data types, optical character recognition (OCR), differential scan | - -## Scan Configuration - -**Access** - -- **Include Shares** — Select **All shares** to scan every share on the server, or **Custom selection** to specify which shares to include. -- **Exclude Shares** — Enter share paths to skip. This field supports wildcards (for example, `\\fileserver\*\temp*`). -- **Hidden shares** — Select **Automatically enumerate hidden shares** to include hidden shares. Use **Exclude Hidden Shares** to skip specific ones (for example, `ADMIN$, C$, IPC$`). -- **File-level permissions** — Select **Include file-level permission data** to collect permissions at the individual file level in addition to folder level. This increases scan time. -- **Workers** — Sets the number of concurrent enumeration threads. Default is `3`; valid range is `1–20`. Increase to improve scan speed; decrease to reduce load on the file server. -- **Scan Depth** — Sets the maximum number of directory levels the scan traverses. Default is `50`. Reduce this value to limit scanning to the top levels of a directory tree. - -**Sensitive Data** - -- **Include/Exclude Shares** — Same share selection options as the Access scan. -- **Sensitive data types** — Select **Inherit from Global Settings** to use the system-wide classification configuration, or disable this option to configure types for this source group. Enable each type you want to detect and assign a classification label. -- **OCR** — Select **Run OCR** to scan images, screenshots, and scanned documents for sensitive text using optical character recognition. This increases processing time. diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md deleted file mode 100644 index 7f0b247ea4..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/schema-reference.md +++ /dev/null @@ -1,201 +0,0 @@ ---- -title: "File Servers Schema Reference" -sidebar_position: 40 ---- - -# File Servers Schema Reference - -Access Analyzer stores File Server scan data in the `access_analyzer` ClickHouse database. Setting up a File Server source group and running a scan creates the following tables. Use this reference when querying scan data directly or integrating Access Analyzer data with external tools. - -:::note -All tables use the `ReplacingMergeTree` engine. The engine deduplicates rows with the same primary key at merge time. Query the `_latest` views to return only the most recent version of each record. -::: - -## Metadata columns - -All tables include the following columns, which Access Analyzer populates during each scan: - -| Column | Type | Description | -|--------|------|-------------| -| `scan_id` | `String` | Identifier of the source group that produced this record. | -| `scan_execution_id` | `String` | Identifier of the specific scan run. | -| `scanned_at` | `DateTime` | Timestamp when the record was written. | - ---- - -## Tables - -### CIFS Object - -Stores the file system inventory collected during a scan — one row per file, directory, or share discovered on a file server. - -| Column | Type | Description | -|--------|------|-------------| -| `host` | `String` | Hostname of the file server. | -| `share_name` | `String` | Name of the share on the file server. | -| `share_path` | `String` | Universal Naming Convention (UNC) path of the share root. | -| `path` | `String` | Full path of the object within the share. | -| `object_type` | `Enum8('FILE', 'DIRECTORY', 'SHARE')` | Whether the object is a file, directory, or share. | -| `parent_path` | `String` | Full path of the parent directory. | -| `name` | `String` | Name of the file or directory. | -| `file_extension` | `String` | File extension, if applicable. Empty string for directories and shares. | -| `file_size` | `UInt64` | Size of the file in bytes. Zero for directories and shares. | -| `owner_sid` | `String` | Security identifier (SID) of the file or directory owner. | -| `group_owner_sid` | `String` | SID of the primary group owner. | -| `created_time` | `Nullable(DateTime)` | Optional. Timestamp when the object was created. | -| `modified_time` | `Nullable(DateTime)` | Optional. Timestamp when the object was last modified. | -| `accessed_time` | `Nullable(DateTime)` | Optional. Timestamp when the object was last accessed. | -| `scan_status` | `Enum8('SUCCESS', 'ERROR')` | Whether the object was scanned successfully. | -| `error_message` | `String` | Error detail if `scan_status` is `ERROR`. Empty string on success. | -| `attributes` | `Array(Enum8('DIRECTORY', 'READONLY', 'HIDDEN', 'SYSTEM', 'ARCHIVE', 'COMPRESSED', 'ENCRYPTED'))` | Windows file attributes applied to the object. | -| `inheritance_flags` | `UInt16` | Bitmask representing ACL inheritance settings on the object. | -| `is_protected` | `Nullable(Bool)` | Optional. Whether the object's ACL is protected from inheritance. | -| `is_world_readable` | `Nullable(Bool)` | Optional. Whether any well-known open SID (for example, Everyone) has read access. | -| `is_world_writable` | `Nullable(Bool)` | Optional. Whether any well-known open SID has write access. | -| `is_admin_only` | `Nullable(Bool)` | Optional. Whether access is restricted to administrative accounts only. | -| `has_explicit_deny` | `Nullable(Bool)` | Optional. Whether the object has at least one explicit deny ACE. | -| `permission_count` | `UInt16` | Total number of ACEs on the object. | -| `unique_trustees_count` | `UInt16` | Number of distinct trustees with permissions on the object. | -| `permission_flags` | `UInt16` | Bitmask summarizing the permission state of the object. | -| `is_complete` | `Bool` | Whether the scan fully enumerated this object's permissions before the scan completed. | -| `hard_delete` | `Bool` | Internal flag used by `ReplacingMergeTree` to exclude deleted rows. Rows where `hard_delete = 1` are suppressed at query time when querying with `FINAL`. | - -**Relations** - -| Related table | Join column | Description | -|---------------|-------------|-------------| -| `cifs_permission` | `host`, `share_name`, `path` | Resolves NTFS permissions assigned to this file or directory. | -| `cifs_sensitive_data` | `host`, `share_name`, `path` | Resolves sensitive data findings for this file. | - ---- - -### CIFS Permission - -Stores NTFS access control entries (ACEs) for files and directories — one row per trustee per path. - -| Column | Type | Description | -|--------|------|-------------| -| `trustee_sid` | `String` | SID of the user or group that this ACE grants or denies access to. | -| `host` | `String` | Hostname of the file server. | -| `share_name` | `String` | Name of the share containing the object. | -| `path` | `String` | Full path of the object this ACE applies to. | -| `permissions` | `Array(Enum8('FILE_READ_DATA', 'FILE_WRITE_DATA', 'FILE_APPEND_DATA', 'FILE_READ_EA', 'FILE_WRITE_EA', 'FILE_EXECUTE', 'FILE_DELETE_CHILD', 'FILE_READ_ATTRIBUTES', 'FILE_WRITE_ATTRIBUTES', 'DIR_LIST', 'DIR_ADD_FILE', 'DIR_ADD_SUB_DIR', 'DIR_DELETE_CHILD', 'DELETE', 'READ_CONTROL', 'WRITE_DAC', 'WRITE_OWNER', 'GENERIC_ALL', 'GENERIC_EXECUTE', 'GENERIC_WRITE', 'GENERIC_READ'))` | Individual permission flags included in this ACE. | -| `normalized_permissions` | `FixedString(6)` | Six-character string encoding the effective permissions (for example, `RWXDMC`) for use in summary queries. | -| `access_type` | `Enum8('ALLOW', 'DENY')` | Whether this ACE allows or denies access. | -| `access_mask` | `UInt32` | Raw Windows access mask bitmask for this ACE. | -| `inheritance_flags` | `UInt16` | Bitmask describing how this ACE propagates to child objects. | -| `is_inherited` | `Bool` | Whether this ACE was inherited from a parent object rather than set explicitly. | -| `mip_label_id` | `Nullable(String)` | Optional. Microsoft GUID of the MIP sensitivity label applied to this object. | -| `mip_label_name` | `Nullable(String)` | Optional. Display name of the MIP sensitivity label applied to this object. | -| `hard_delete` | `Bool` | Internal flag used by `ReplacingMergeTree` to exclude deleted rows. | - -**Relations** - -| Related table | Join column | Description | -|---------------|-------------|-------------| -| `cifs_object` | `host`, `share_name`, `path` | Resolves file system object details for this ACE. | -| `cifs_share_permission` | `host`, `share_name` | Resolves the share-level permissions that apply in combination with this NTFS ACE. | - ---- - -### CIFS Share Permission - -Stores share-level ACEs — one row per trustee per share. Share permissions apply in addition to NTFS permissions; the effective access a user has is the intersection of both. - -| Column | Type | Description | -|--------|------|-------------| -| `trustee_sid` | `String` | SID of the user or group that this share ACE grants or denies access to. | -| `host` | `String` | Hostname of the file server. | -| `share_name` | `String` | Name of the share this ACE applies to. | -| `permissions` | `Array(Enum8('FILE_READ_DATA', 'FILE_WRITE_DATA', 'FILE_APPEND_DATA', 'FILE_READ_EA', 'FILE_WRITE_EA', 'FILE_EXECUTE', 'FILE_DELETE_CHILD', 'FILE_READ_ATTRIBUTES', 'FILE_WRITE_ATTRIBUTES', 'DIR_LIST', 'DIR_ADD_FILE', 'DIR_ADD_SUB_DIR', 'DIR_DELETE_CHILD', 'DELETE', 'READ_CONTROL', 'WRITE_DAC', 'WRITE_OWNER', 'GENERIC_ALL', 'GENERIC_EXECUTE', 'GENERIC_WRITE', 'GENERIC_READ'))` | Individual permission flags included in this share ACE. | -| `normalized_permissions` | `FixedString(6)` | Six-character string encoding the effective permissions for use in summary queries. | -| `access_type` | `Enum8('ALLOW', 'DENY')` | Whether this ACE allows or denies access at the share level. | -| `access_mask` | `UInt32` | Raw Windows access mask bitmask for this share ACE. | -| `mip_label_id` | `Nullable(String)` | Optional. Microsoft GUID of the MIP sensitivity label applied to this share. | -| `mip_label_name` | `Nullable(String)` | Optional. Display name of the MIP sensitivity label applied to this share. | -| `hard_delete` | `Bool` | Internal flag used by `ReplacingMergeTree` to exclude deleted rows. | - -**Relations** - -| Related table | Join column | Description | -|---------------|-------------|-------------| -| `cifs_permission` | `host`, `share_name` | Resolves NTFS ACEs that apply within this share. | - ---- - -### CIFS Sensitive Data - -Stores sensitive data classification findings — one row per taxonomy term match per file path. - -| Column | Type | Description | -|--------|------|-------------| -| `host` | `String` | Hostname of the file server. | -| `share_name` | `String` | Name of the share containing the file. | -| `path` | `String` | Full path of the file where sensitive data was detected. | -| `taxonomy_name` | `String` | Name of the taxonomy that contains the matched term (for example, `PII`). | -| `term_name` | `String` | Name of the classification term that matched (for example, `Social Security Number`). | -| `processing_time_seconds` | `Float32` | Time in seconds to classify the file. | -| `classification_method` | `Nullable(Enum8('SDK_AUTO', 'SDK_CUSTOM'))` | Optional. Whether detection used the built-in automatic classification engine (`SDK_AUTO`) or a custom classification configuration (`SDK_CUSTOM`). | -| `scan_status` | `Enum8('SUCCESS', 'ERROR')` | Whether the file was processed successfully. `SUCCESS` indicates the file was read and classified, regardless of whether sensitive data was found. `ERROR` indicates a processing failure such as a file conversion error, encryption, or unsupported format. | -| `error_message` | `Nullable(String)` | Optional. Error detail when `scan_status` is `ERROR`. Null on success. | -| `hard_delete` | `Bool` | Internal flag used by `ReplacingMergeTree` to exclude deleted rows. | - -**Relations** - -| Related table | Join column | Description | -|---------------|-------------|-------------| -| `cifs_object` | `host`, `share_name`, `path` | Resolves file system object details for this finding. | -| `cifs_sensitive_data_mip_labels` | `host`, `share_name`, `path` | Resolves MIP sensitivity label decisions applied to this file. | - ---- - -### CIFS Sensitive Data MIP Labels - -Stores Microsoft Information Protection (MIP) sensitivity label decisions for files that contain sensitive data findings. Each row records the label action Access Analyzer determined for a file based on its classification results. Access Analyzer sources MIP labels from an Entra ID source group configured in the same Access Analyzer instance and uses that source group to resolve label definitions and apply or recommend label changes. - -:::note -This table uses `ReplacingMergeTree(decision_timestamp)` rather than `scanned_at`. At merge time, the engine keeps the most recent decision per file (identified by `source_id`, `host`, `share_name`, and `path`). -::: - -| Column | Type | Description | -|--------|------|-------------| -| `source_id` | `UUID` | Identifier of the Entra ID source group used to resolve MIP label definitions. | -| `host` | `String` | Hostname of the file server. | -| `share_name` | `String` | Name of the share containing the file. | -| `path` | `String` | Full path of the file this label decision applies to. | -| `mip_is_protected` | `Bool` | Whether the file is protected by MIP encryption. | -| `taxonomy_id` | `Nullable(UUID)` | Optional. Identifier of the taxonomy that triggered this label decision. | -| `action` | `Enum8('upgrade', 'keep', 'downgrade', 'clear', 'none')` | The label action Access Analyzer determined: `upgrade` applies a higher-sensitivity label, `downgrade` applies a lower-sensitivity label, `keep` leaves the current label unchanged, `clear` removes the label, and `none` indicates no action was taken. | -| `label_id` | `Nullable(UUID)` | Optional. UUID of the MIP sensitivity label selected by the action. | -| `label_name` | `Nullable(String)` | Optional. Display name of the MIP sensitivity label selected by the action. | -| `reason` | `Nullable(String)` | Optional. Explanation of why this label action was chosen. | -| `decision_timestamp` | `DateTime` | Timestamp when Access Analyzer made this label decision. | -| `scanned_at` | `DateTime` | Timestamp when the record was written. | -| `applied_at` | `Nullable(DateTime)` | Optional. Timestamp when the label was successfully applied to the file. Null if not yet applied. | -| `apply_error` | `String` | Error message if the label application failed. Empty string when no error occurred. | -| `apply_attempts` | `UInt8` | Number of times Access Analyzer has attempted to apply this label decision. | -| `created_at` | `DateTime` | Timestamp when this record was first created. | -| `updated_at` | `DateTime` | Timestamp when this record was last updated. | - -**Relations** - -| Related table | Join column | Description | -|---------------|-------------|-------------| -| `cifs_sensitive_data` | `host`, `share_name`, `path` | Resolves the sensitive data findings that triggered this label decision. | - ---- - -## Views - -Access Analyzer creates views that simplify common queries. Use views instead of querying base tables directly. - -| View | Base table | Description | -|------|------------|-------------| -| `cifs_object_latest` | `cifs_object` | Returns the most recent version of each file system object, using `FINAL` to suppress duplicates. | -| `cifs_permission_latest` | `cifs_permission` | Returns the most recent version of each NTFS ACE, using `FINAL` to suppress duplicates. | -| `cifs_share_permission_latest` | `cifs_share_permission` | Returns the most recent version of each share-level ACE, using `FINAL` to suppress duplicates. | -| `cifs_sensitive_data_latest` | `cifs_sensitive_data` | Returns one aggregated row per file path, combining all taxonomy and term matches for that path. The `taxonomy_names` and `term_names` columns return arrays of distinct values grouped from individual rows. | -| `cifs_sensitive_data_mip_labels_latest` | `cifs_sensitive_data_mip_labels` | Returns the most recent label decision per file, using `FINAL` to suppress duplicates. | -| `cifs_sensitive_data_mip_labels_summary` | `cifs_sensitive_data_mip_labels` | Returns a summary of label decisions grouped by host, share, action, label name, and protection status. Includes decision counts and the timestamp range of first and last decisions. | -| `cifs_effective_permissions` | `cifs_permission_latest`, `cifs_share_permission_latest` | Joins NTFS and share permissions with resolved principal identities (local users, local groups, Active Directory users, Active Directory groups, and well-known SIDs) to produce one row per principal per path. Use this view to query who has access to a given path by name rather than by SID. | -| `cifs_effective_access` | `cifs_effective_permissions` | Computes the final effective access mask for each principal per path by combining NTFS allow and deny ACEs with share-level permissions. Use this view to determine the actual access a named user or group has to a file or directory. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md deleted file mode 100644 index 14a5a50fba..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/file-servers/set-up-source-group.md +++ /dev/null @@ -1,52 +0,0 @@ ---- -title: "Set Up File Server Source Group" -description: "Configure a file server source group in Access Analyzer" -sidebar_position: 3 ---- - -# Set Up File Server Source Group - -1. Navigate to **Configuration** > **Source Groups** and click **Add Source**. The source group wizard opens. -2. Select **File Server** and click **Next**. -3. Enter a **Source Group Name**. -4. Select a service account from the **Service Account** dropdown, or click **+** to create one inline. See [Service Accounts](../../configurations/service-accounts/overview.md) for details. -5. Optionally, enter a **Domain** name to apply to all file servers in this source group. Leave blank if your servers are in a workgroup or if you want to specify credentials without a domain prefix. -6. Click **Add** under **File Servers** and enter the hostname or IP address of each file server to include. Click **Done** when finished. -7. Click **Test Connection** to verify connectivity. Each server displays a **Connected** or **Failed** status. Resolve any failures before proceeding. -8. Click **Next**. -9. Enable the scan types you want to run: - - **Access scan:** - - - Toggle **Access** to enable scanning of file permissions and access controls. - - Under **Include Shares**, select **All shares** to scan every share on the server, or **Custom selection** to specify a list of shares to include. - - Optionally, add share paths to the **Exclude Shares** field to skip specific locations. The field supports wildcards (for example, `\\fileserver\*\temp*`). - - Select **Automatically enumerate hidden shares** to include hidden shares in the scan. Use the **Exclude Hidden Shares** field to exclude specific hidden shares (for example, `ADMIN$, C$, IPC$`). - - Select **Include file-level permission data** to collect permissions at the file level in addition to folder level. This increases scan time. - - Set **Workers** to control the number of concurrent threads used during enumeration. The default is `3`. The valid range is `1–20`. - - Set **Scan Depth** to limit how many directory levels deep the scan traverses. The default is `50`. - - **Sensitive Data scan:** - - - Toggle **Sensitive Data** to enable scanning of file contents for sensitive data patterns. - - Configure share selection using the same options as the Access scan. - - Select **Inherit from Global Settings** to use the sensitive data types configured at the system level, or disable this option to configure types for this source group specifically. - - If configuring types directly, enable each sensitive data type you want to detect and assign a classification label. - - Select **Run OCR** to scan images, screenshots, and scanned documents for sensitive text using optical character recognition (OCR). This increases processing time. - -10. Under **Scanner Location**, select **System scanner** to run scans from the Access Analyzer service, or select **Custom scanner** to use a deployed scanner. See [Scanners](../../configurations/source-groups/scanners/overview.md) for details. -11. Under **Scan Schedule**, select when to run the scan: - - **Now** — Starts the scan immediately after setup completes. - - **At** — Runs the scan once at a specific date and time. - - **Advanced** — Runs the scan on a recurring schedule defined by a cron expression. -12. Click **Complete Setup**. - -## What happens next - -Access Analyzer creates the source group and a scan for each file server you added. If you selected **Now**, the enabled scans start immediately. - -To check scan progress, navigate to **Configuration** > **Scan Executions**. - -## Edit a source group - -To modify an existing file server source group, navigate to **Configuration** > **Source Groups**, select the source group, and click **Edit**. The wizard reopens with your current configuration pre-populated. You can update the source group name, service account, file servers, and scan settings. diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md deleted file mode 100644 index 0c969c2a49..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/reports.md +++ /dev/null @@ -1,17 +0,0 @@ ---- -title: "Reports" -description: "Pre-built reports available for SharePoint Online source groups in Access Analyzer" -sidebar_position: 50 ---- - -# Reports - -After the first scan of a SharePoint Online source group completes, three pre-built reports become available under the Reports section. These reports help you answer key security questions about your SharePoint environment: which files carry sensitive data, how broadly content is shared, and where stale or redundant data accumulates across your sites. - -## Available reports - -| Location | Report | Description | -|----------|--------|-------------| -| Access / Shared Links Report | Shared Links Report | Shows all sharing links across your SharePoint environment, with breakdowns by sharing scope (organization, anonymous, specific people), active status, sensitive data type, and site. Use this report to identify overly broad sharing and links that expose sensitive files. | -| Content / ROT Analysis | ROT Analysis | Identifies Redundant, Obsolete, and Trivial (ROT) data across your SharePoint sites, including stale files not modified in over a year, duplicate files by content hash, and stale files containing sensitive data. Use this report to prioritize data cleanup and reduce unnecessary exposure of aging content. | -| Content / Scan Overview | Scan Overview | Summarizes the results of the most recent scan across all sites, including total site count, file count, total storage, and files with sensitive data. Use this report to confirm scan coverage and quickly identify which sites hold the most sensitive content. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md deleted file mode 100644 index e3c0f3eab3..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/scanning-options.md +++ /dev/null @@ -1,28 +0,0 @@ ---- -title: "Scanning options" -description: "Available scan types and configuration options for SharePoint Online source groups" -sidebar_position: 2 ---- - -# Scanning options - -| Scan type | Description | -| --- | --- | -| **Access scan** | Enumerates sites, document libraries, folders, and files. Collects permissions, ACLs, sharing links, and Microsoft Information Protection (MIP) sensitivity labels across the tenant. The first scan runs in full; subsequent scans collect only changes since the last run. | -| **Sensitive Data scan** | Reads file contents to classify sensitive data. Requires a completed Access scan — it uses the site and file inventory from the Access scan as its input. | - -## Access scan configuration - -| Option | Description | -| --- | --- | -| **Include site URLs** | Limits the scan to specific site collections. Enter one URL per line. Leave empty to scan all sites in the tenant. | -| **Exclude site URLs** | Excludes specific site collections from the scan. Enter one URL per line. Exclusions take precedence over inclusions. | -| **Scan OneDrive** | When enabled, includes OneDrive personal site collections in the scan. Enabled by default. | - -The Access scan also reads Microsoft Information Protection (MIP) sensitivity labels from SharePoint item metadata and stores them alongside the permission data. Access Analyzer reads existing labels only — it doesn't support writing or modifying MIP labels on SharePoint Online items. - -## Sensitive Data scan - -The Sensitive Data scan reads file contents to detect and classify sensitive information. It runs after the Access scan completes and uses the file inventory collected during that scan. - -You configure sensitive data classification policies, MIP label mappings, and optical character recognition (OCR) settings globally, and they apply to all source groups. To configure them, navigate to **Configuration** > **Sensitive Data**. See [Sensitive Data Configuration](../../configurations/sensitive-data.md) for details. diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md deleted file mode 100644 index 77f65abea0..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/schema-reference.md +++ /dev/null @@ -1,166 +0,0 @@ ---- -title: "Schema reference" -sidebar_position: 40 ---- - -# SharePoint Online schema reference - -Access Analyzer stores SharePoint Online scan data in the `access_analyzer` ClickHouse database. Setting up a SharePoint Online source group and running a scan creates the following tables. Use this reference when querying scan data directly or integrating Access Analyzer data with external tools. - -:::note -All tables use the `ReplacingMergeTree` engine. The engine deduplicates rows with the same primary key at merge time. Query the `_latest` views to return only the most recent version of each record. -::: - -## Metadata columns - -All tables include the following columns, which Access Analyzer populates during each scan: - -| Column | Type | Description | -|--------|------|-------------| -| `scan_id` | `String` | Identifier of the source group that produced this record. | -| `scan_execution_id` | `String` | Identifier of the specific scan run. | -| `scanned_at` | `DateTime` | Timestamp when the record was written. | - ---- - -## Tables - -### sharepoint_online_objects - -Stores one row per scanned SharePoint item — sites, lists, document libraries, and list items (files and folders). - -| Column | Type | Description | -|--------|------|-------------| -| `site_hostname` | `String` | Hostname of the SharePoint site collection (for example, `contoso.sharepoint.com`). | -| `site_id` | `String` | SharePoint identifier of the site collection. | -| `item_id` | `String` | Unique identifier of the item within the site. | -| `site_url` | `String` | Absolute URL of the site collection. | -| `drive_id` | `String` | Microsoft Graph drive identifier for the document library that contains this item. Empty for sites and lists that don't have a drive. | -| `drive_item_id` | `String` | Microsoft Graph drive item identifier. Empty for items that aren't drive items. | -| `item_type` | `Enum8` | Type of SharePoint item. Values: `SITE`, `LIST`, `LIBRARY`, `LIST_ITEM`. | -| `name` | `String` | Display name of the item. | -| `file_extension` | `String` | File extension, including the leading period (for example, `.docx`). Empty for non-file items. | -| `relative_url` | `String` | Server-relative URL path of the item. | -| `file_size` | `Nullable(Int64)` | Optional. File size in bytes. Null for items that aren't files. | -| `created_time` | `DateTime` | Timestamp when the item was created in SharePoint. | -| `created_by_id` | `String` | SharePoint user identifier of the user who created the item. | -| `created_by_email` | `String` | Email address of the user who created the item. | -| `modified_time` | `DateTime` | Timestamp of the most recent modification. | -| `modified_by_id` | `String` | SharePoint user identifier of the user who last modified the item. | -| `modified_by_email` | `String` | Email address of the user who last modified the item. | -| `parent_item_id` | `String` | `item_id` of the parent item. Empty for top-level sites. | -| `scan_status` | `String` | Result of scanning this item. Typical values: `SUCCESS`, `ERROR`. | -| `error_message` | `String` | Error detail when `scan_status` is `ERROR`. Empty on success. | -| `is_complete` | `Boolean` | Indicates whether the scan wrote all expected records for this item. Used internally to support scan resume. | - -**Primary key:** `(site_hostname, site_id, item_id)` - -**Relations** - -| Related table | Join columns | Description | -|---|---|---| -| `sharepoint_online_permissions` | `site_hostname`, `site_id`, `item_id` | All permissions assigned to this item. | -| `sharepoint_online_shared_links` | `site_hostname`, `site_id`, `item_id` | All sharing links created for this item. | -| `sharepoint_online_sensitive_data` | `drive_id`, `drive_item_id` | Classification results for this item. Only populated for drive items. | - ---- - -### sharepoint_online_permissions - -Stores one row per permission assignment. Each row represents a single principal (user or group) having a specific permission on a specific item. - -| Column | Type | Description | -|--------|------|-------------| -| `site_hostname` | `String` | Hostname of the site collection that contains the item. | -| `site_id` | `String` | SharePoint identifier of the site collection. | -| `item_id` | `String` | Identifier of the item this permission applies to. | -| `permission_id` | `String` | SharePoint identifier of the permission entry. | -| `share_id` | `String` | Identifier of the sharing link that granted this permission. Empty for direct permissions. | -| `principal_id` | `String` | Identifier of the user or group that holds the permission. | -| `principal_type` | `Enum8` | Type of the principal. Values: `USER`, `GROUP`, `SITE_USER`, `SITE_GROUP`. | -| `principal_name` | `String` | Display name of the principal. | -| `principal_email` | `String` | Email address of the principal. Empty for groups that don't have an email address. | -| `permission_type` | `Enum8` | How the permission was granted. Values: `DIRECT` (assigned directly to the item), `SHARED` (granted through a sharing link). | -| `permission_levels` | `Array(Enum8)` | Named permission levels assigned to the principal. Values: `OWNER`, `READ`, `WRITE`. | -| `effective_base_permissions` | `Array(Enum8)` | Full set of granular SharePoint base permissions the principal holds. Values include `VIEW_LIST_ITEMS`, `ADD_LIST_ITEMS`, `EDIT_LIST_ITEMS`, `DELETE_LIST_ITEMS`, `MANAGE_LISTS`, `MANAGE_PERMISSIONS`, `MANAGE_WEB`, and others as defined by the SharePoint permission model. | -| `normalized_permissions` | `FixedString(5)` | Compact bitmask representation of the permission levels. Used internally for permission comparison. | -| `parent_site_id` | `String` | Identifier of the site collection from which this permission is inherited. Empty for permissions that aren't inherited. | -| `parent_item_id` | `String` | `item_id` of the item from which this permission is inherited. Empty for permissions assigned directly to this item. | -| `is_site_admin` | `Bool` | `true` if the principal is a site collection administrator. | -| `is_external_user` | `Bool` | `true` if the principal is a guest or external user. | -| `mip_label_id` | `Nullable(String)` | Optional. Microsoft GUID of the Microsoft Information Protection sensitivity label applied to the SharePoint item at the time of the scan. | -| `mip_label_name` | `Nullable(String)` | Optional. Display name of the sensitivity label identified by `mip_label_id`. | - -**Primary key:** `(site_hostname, site_id, item_id, permission_id, principal_id)` - -**Relations** - -| Related table | Join columns | Description | -|---|---|---| -| `sharepoint_online_objects` | `site_hostname`, `site_id`, `item_id` | The item this permission applies to. | -| `sharepoint_online_shared_links` | `site_hostname`, `site_id`, `item_id`, `share_id` | The sharing link that granted this permission, when `permission_type` is `SHARED`. | - ---- - -### sharepoint_online_shared_links - -Stores one row per sharing link. A sharing link may grant access to one or more principals; the corresponding permission rows appear in `sharepoint_online_permissions`. - -| Column | Type | Description | -|--------|------|-------------| -| `site_hostname` | `String` | Hostname of the site collection that contains the item. | -| `site_id` | `String` | SharePoint identifier of the site collection. | -| `item_id` | `String` | Identifier of the item the sharing link points to. | -| `permission_id` | `String` | SharePoint permission identifier associated with the sharing link. | -| `share_id` | `String` | Unique identifier of the sharing link. | -| `link_type` | `Enum8` | Access level granted by the link. Values: `VIEW`, `EDIT`, `EMBED`, `REVIEW`. | -| `link_url` | `String` | Full URL of the sharing link. | -| `link_scope` | `Enum8` | Audience the link is accessible to. Values: `ANONYMOUS` (anyone with the link), `ORGANIZATION` (anyone in the organization), `USERS` (specific users only). | -| `expires_on` | `DateTime` | Expiration timestamp of the link. A zero value indicates the link doesn't expire. | -| `is_password_protected` | `Bool` | `true` if the link requires a password to access. | -| `prevent_download` | `Bool` | `true` if the link prevents recipients from downloading the file. | - -**Primary key:** `(site_hostname, site_id, item_id, permission_id, share_id)` - -**Relations** - -| Related table | Join columns | Description | -|---|---|---| -| `sharepoint_online_objects` | `site_hostname`, `site_id`, `item_id` | The item the sharing link provides access to. | -| `sharepoint_online_permissions` | `site_hostname`, `site_id`, `item_id`, `share_id` | Permissions granted through the sharing link. | - ---- - -### sharepoint_online_sensitive_data - -Stores classification results from the sensitive data scan option. Each row represents one taxonomy term matched in a drive item. Multiple rows may exist for the same item when the item matches terms from multiple taxonomies. - -| Column | Type | Description | -|--------|------|-------------| -| `drive_id` | `String` | Microsoft Graph drive identifier of the document library that contains the item. | -| `drive_item_id` | `String` | Microsoft Graph drive item identifier of the classified file. | -| `taxonomy_name` | `String` | Name of the classification taxonomy (for example, `PII`, `Financial Records`). | -| `term_name` | `String` | Name of the specific classification term within the taxonomy (for example, `Credit Card Number`, `Social Security Number`). | -| `processing_time_seconds` | `Float32` | Time in seconds that the classification engine spent processing this item. | -| `classification_method` | `Nullable(Enum8)` | Optional. Method used to classify this item. Values: `SDK_AUTO` (automatic classification by the built-in engine), `SDK_CUSTOM` (classification using custom rules). | - -**Primary key:** `(drive_id, drive_item_id, taxonomy_name, term_name)` - -**Relations** - -| Related table | Join columns | Description | -|---|---|---| -| `sharepoint_online_objects` | `drive_id`, `drive_item_id` | The scanned item that produced these classification results. | - ---- - -## Views - -Access Analyzer creates views that simplify common queries. Use views instead of querying base tables directly. - -| View | Base table | Description | -|------|------------|-------------| -| `sharepoint_online_objects_latest` | `sharepoint_online_objects` | Returns only the most recent version of each object record, deduplicated by `(site_hostname, site_id, item_id)`. | -| `sharepoint_online_permissions_latest` | `sharepoint_online_permissions` | Returns only the most recent version of each permission record, deduplicated by `(site_hostname, site_id, item_id, permission_id, principal_id)`. | -| `sharepoint_online_shared_links_latest` | `sharepoint_online_shared_links` | Returns only the most recent version of each sharing link record, deduplicated by `(site_hostname, site_id, item_id, permission_id, share_id)`. | -| `sharepoint_online_sensitive_data_latest` | `sharepoint_online_sensitive_data` | Returns one aggregated row per drive item, with `taxonomy_names` and `term_names` as arrays collecting all matched taxonomy and term names. Deduplicated by `(drive_id, drive_item_id)`. | diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md deleted file mode 100644 index 870ea325b1..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/set-up-source-group.md +++ /dev/null @@ -1,61 +0,0 @@ ---- -title: "Set up a SharePoint Online source group" -description: "Configure a SharePoint Online source group in Access Analyzer" -sidebar_position: 3 ---- - -# Set up a SharePoint Online source group - -1. Navigate to **Configuration** > **Source Groups** and click **Add Source**. The source group wizard opens. - -2. Select **SharePoint Online** and click **Next**. - -3. Enter a **Source Group Name**. - -4. Select a service account from the **Service Account** dropdown, or click **+** to create one inline. SharePoint Online requires a **Client ID and Certificate** service account type with specific API permissions. See [Required permissions](../../connectors/sharepoint-online/azure-permissions.md#required-permissions) for the full list of permissions, and [Service Accounts](../../configurations/service-accounts/overview.md) for details on creating a service account. - -5. Enter the **Tenant ID** for your Microsoft Entra ID directory. This must be a valid UUID (for example, `550e8400-e29b-41d4-a716-446655440000`). - -6. Under **Certificate**, click **Generate and Download Certificate** to download a new certificate to your machine. Upload this certificate to your registered Entra ID application before proceeding. See [Certificate Configuration](../../connectors/sharepoint-online/tenant-certificate-config.md) for upload steps. - - :::note - If you click **Regenerate Certificate**, upload the new certificate to your Entra ID App Registration to replace the old one. Removing the old certificate from the App Registration is a manual step in the Azure portal — Access Analyzer can't remove it on your behalf. - ::: - -7. Click **Test Connection** to verify that Access Analyzer can authenticate to your SharePoint Online tenant. Resolve any failures before proceeding. - - :::warning - After you upload a new certificate to your Entra ID application, Microsoft Entra ID can take several minutes to propagate the certificate to its token-issuing endpoints. During that time, **Test Connection** can fail with an error similar to `AADSTS700027: The certificate with identifier used to sign the client assertion is not registered on application`. If that happens, wait a few minutes and try again before troubleshooting further. - ::: - -8. Click **Next**. - -9. Under **Scan Configuration**, configure the options for the scans you want to run: - - - **Include site URLs** — Limits the scan to specific site collections. Enter one URL per line. Leave empty to scan all sites in the tenant. - - **Exclude site URLs** — Excludes specific site collections from the scan. Exclusions take precedence over inclusions. - - **Scan OneDrive** — Includes OneDrive personal site collections in the scan. - - See [Scanning options](./scanning-options.md) for a full description of available scan types and options. - -10. Under **Scan Schedule**, select when to run the scan: - - - **Now** — Starts the scan immediately after setup completes. - - **At** — Runs the scan once at a specific date and time. - - **Advanced** — Runs the scan on the recurring schedule you define with a cron expression. - -11. Click **Complete Setup**. - -## What happens next - -Access Analyzer creates the source group and begins scanning your SharePoint Online environment. If you selected **Now**, the scan starts immediately. - -To check scan progress, navigate to **Configuration** > **Scan Executions**. - -## Edit a source group - -To modify an existing SharePoint Online source group, navigate to **Configuration** > **Source Groups**, select the source group, and click **Edit**. The wizard reopens and displays your current configuration. You can update the source group name, service account, tenant ID, scan configuration, and scan schedule. - -:::note -Updating the service account replaces the certificate that Access Analyzer uses to authenticate with SharePoint Online. Upload the new service account's certificate to your registered Entra ID application before saving. -::: diff --git a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md b/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md deleted file mode 100644 index 39a5e5b55f..0000000000 --- a/docs/accessanalyzer/26.1/gettingstarted/sharepoint-online/sharepoint-online.md +++ /dev/null @@ -1,42 +0,0 @@ ---- -title: "SharePoint Online Scanning Overview" -description: "Overview of SharePoint Online scanning capabilities and prerequisites in Access Analyzer" -sidebar_position: 1 ---- - -# SharePoint Online Scanning Overview - -Access Analyzer scans SharePoint Online sites to map permissions, enumerate sharing links, and locate sensitive data across your tenant's document libraries and sites. It surfaces over-permissioned sites, anonymous and organization-wide sharing links, and files that contain sensitive content — giving security teams the information they need to reduce external exposure, enforce sharing policies, and meet cloud data governance requirements. - -## Prerequisites - -Before setting up a SharePoint Online source group, confirm that your environment meets the following requirements. The source group wizard connects to SharePoint Online over HTTPS using certificate-based authentication, so the Access Analyzer server must be able to reach the Microsoft identity platform, and you must configure an app registration in your tenant. The wizard generates the certificate — you'll need the application's Client ID before you begin. - -### Service account - -Access Analyzer uses a Client ID and Certificate service account to authenticate with SharePoint Online. You enter only the Client ID when creating the service account — Access Analyzer generates the certificate automatically during source group setup when you click **Generate and Download Certificate**. You then upload the certificate to your registered Entra ID application before you can test the connection. - -See [Client ID/Certificate service account](../../configurations/service-accounts/client-id-certificate.md) to create the service account and [SharePoint Online Connector Requirements](../../connectors/sharepoint-online/overview.md) for instructions on registering the application. - -### Network requirements - -| Protocol | Port | Destination | -| --- | --- | --- | -| HTTPS | 443 | Microsoft identity platform (`login.microsoftonline.com`) | -| HTTPS | 443 | Microsoft Graph API (`graph.microsoft.com`) | -| HTTPS | 443 | SharePoint Online (`.sharepoint.com`) | - -### Before you begin - -- A registered application in your Entra ID tenant. -- The application's **Tenant ID** and **Client ID**. -- A Client ID and Certificate service account created in Access Analyzer. -- Network connectivity from the Access Analyzer server to port 443 confirmed. - -:::note -Access Analyzer reads Microsoft Information Protection (MIP) sensitivity labels on SharePoint Online files during Sensitive Data scans. It collects the labels and surfaces them in scan results, and it makes no changes to labels on any scanned file. -::: - -:::note -**Sensitive Data scans require a completed Access scan.** The Access scan builds the site and document library inventory that the Sensitive Data scan uses. Run the Access scan first, then enable Sensitive Data on a subsequent scan. Enabling both on the very first scan is supported but will extend the initial scan duration. -::: diff --git a/docs/accessanalyzer/26.1/connectors/file-servers/_category_.json b/docs/accessanalyzer/26.1/guides/_category_.json similarity index 70% rename from docs/accessanalyzer/26.1/connectors/file-servers/_category_.json rename to docs/accessanalyzer/26.1/guides/_category_.json index 5923518b84..4c8ec4e038 100644 --- a/docs/accessanalyzer/26.1/connectors/file-servers/_category_.json +++ b/docs/accessanalyzer/26.1/guides/_category_.json @@ -1,5 +1,5 @@ { - "label": "File Servers", + "label": "Guides", "position": 20, "collapsed": true, "collapsible": true diff --git a/docs/accessanalyzer/26.1/guides/active-directory.md b/docs/accessanalyzer/26.1/guides/active-directory.md new file mode 100644 index 0000000000..a100a9878c --- /dev/null +++ b/docs/accessanalyzer/26.1/guides/active-directory.md @@ -0,0 +1,108 @@ +--- +title: Scan Active Directory +description: Add a domain as an Active Directory source, run an Identity sync, and use the results in the Active Directory dashboard and in file server permission reports. +sidebar_position: 2 +--- + +Add one Active Directory domain as a source and run an Identity sync, which reads the domain's users, groups, organizational units, and memberships. The results feed the Active Directory dashboard and the AD Users report, and they let file server permission reports show account and group names instead of security identifiers (SIDs). + +One source covers one domain. If you have several domains, repeat the guide for each. + +## Before you start + +### Account + +The Identity sync only reads. A regular domain user with the default read access to the domain is enough. + +### Network + +The Access Analyzer server, or the agent that runs the scan, needs one Lightweight Directory Access Protocol (LDAP) port open to a domain controller. The port you choose decides how the connection is secured. + +| Port | Protocol | Notes | +|------|----------|-------| +| 389 | LDAP with DIGEST-MD5 authentication and StartTLS | Enter the domain controller's fully qualified domain name (FQDN) in **Host**; DIGEST-MD5 authentication requires an FQDN and doesn't work with an IP address. Works with domain controllers that require LDAP signing. | +| 636 | LDAP over TLS (LDAPS) | The server or agent that runs the scan must trust the domain controller's certificate unless you turn on **Ignore SSL errors**. | + +When a connection uses TLS, it uses TLS 1.2. On port 389, Access Analyzer first tries DIGEST-MD5 with encryption over StartTLS; if that attempt fails, it retries with DIGEST-MD5 signing without TLS, and then with a simple bind. Access Analyzer doesn't use Kerberos or the Global Catalog ports (3268 and 3269). + +:::note + +Adding a domain as a source has nothing to do with how people sign in to Access Analyzer. Sign-in with Active Directory credentials is a separate setup task; see [Single sign-on](../settings/single-sign-on.md). + +::: + +## 1. Create the service account + +Active Directory sources use a **Username/password** service account. + +1. Go to **Configuration > Service accounts** and click **Add service account**. +2. In **Name**, enter a unique name, for example `svc-ad-sync`. +3. Leave **Service account type** set to **Username/password**. +4. In **Username**, enter the account's user name only, for example `svc-ad-sync`, without a `DOMAIN\` prefix or `@domain` suffix. Access Analyzer supplies the domain from the source's **Domain** field. +5. In **Password**, enter the password. +6. Click **Add account**. + +![Add service account drawer with the Username/password type selected](/images/accessanalyzer/26.1/service-accounts/add-username-password.webp) + +If you already created a **Username/password** account for a file server in the same domain and its **Username** is a plain user name with no domain prefix, you can reuse it here; the [Username and password](../service-accounts/username-password.md) page covers the details. + +## 2. Add the source + +1. Go to **Configuration > Sources** and click **Add source**. +2. In **Source type**, select **Active Directory**. +3. Under **Details**, enter a **Name** for the source, such as the domain name. +4. Under **Connection**, in **Host**, enter a domain controller, for example `dc01.example.com`. Use the FQDN if you connect on port 389. +5. In **Port**, leave 389 or enter 636 for LDAPS. +6. Leave **Ignore SSL errors** clear. Turn it on only for a lab domain controller with a self-signed certificate on port 636. +7. In **Domain**, enter the DNS name of the domain, for example `corp.example.com`. +8. Under **Access**, in **Service account**, select the service account you created earlier. +9. Click **Test connection**. Access Analyzer binds to the domain controller and reads its root directory entry. Success shows the **Connection successful** message; failure shows a **Connection failed** alert with the reason, including a hint when the port and protocol don't match. +10. Click **Add source**. + +![Add source drawer for an Active Directory source](/images/accessanalyzer/26.1/sources/add-active-directory.webp) + +The [Active Directory](../sources/active-directory.md) source page describes each field and the connection checks in more depth. + +## 3. Create the Identity sync + +Click **Next** to move from one step to the next. + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Identity sync**. + + ![Create scan Type step with the Access, Sensitive data, and Identity sync cards](/images/accessanalyzer/26.1/scans/create-scan-1-type.webp) + +3. On the **Target** step, keep **Specific sources** and select the domain's checkbox. The list shows only sources that support Identity sync. +4. On the **Configure** step, leave **Use default configuration** selected. The default turns on **Enable differential scan**: the first run reads the whole domain; later runs read only the objects that changed since the previous run. +5. On the **Schedule** step, select **On a schedule**. +6. Keep the default **Daily** at 02:00 so group memberships stay current for the reports that depend on them. +7. Leave the agent set to **System agent**. + + ![Create scan Schedule step with a daily schedule selected](/images/accessanalyzer/26.1/scans/create-scan-4-schedule-daily.webp) + +8. On the **Review** step, enter a **Name** such as `corp.example.com - identity sync`. +9. Click **Create & run now**. + +[Schedules](../scans/schedules.md) explains the frequency options and what the **Schedule Status** column shows. + +## 4. Watch the execution + +Go to **Configuration > Scan executions** and find the row for the new scan. The list refreshes on its own and shows the execution's **Status** and its **Objects** count. + +![Scan executions list](/images/accessanalyzer/26.1/scans/executions-list.webp) + +When the sync itself finishes, the execution moves to **Post processing** while Access Analyzer expands nested group memberships in a step named **Refresh Effective Memberships**. The step appears as a child row under the execution; click the arrow at the start of the row to show it. The execution reaches **Completed** once that step is done. + +If the status is **Failed**, open the row's **Actions** menu and click **View logs**. Authentication problems appear in the **Detailed logs** tab. If the message asks for an FQDN, **Host** holds an IP address and the port is 389; enter the domain controller's name instead. + +## 5. Check the dashboard and reports + +Go to **Dashboards > Active Directory** and click **Refresh**. In the **Domain** filter, select the domain you synced. The dashboard opens with counts for **Domains**, **Users**, **Enabled Users**, **Groups**, and **Direct Memberships**, followed by **Users**, **Groups**, and **All Risks** sections that end in the **Active Directory Risks** table. The [Active Directory dashboard](../dashboards-reports/dashboards/active-directory.md) page describes each card. + +![Active Directory dashboard with Domains, Users, Groups, and risk tiles](/images/accessanalyzer/26.1/dashboards-reports/active-directory-dashboard.webp) + +Under **Reports > Identity**, the **Active Directory** tab has the **AD Users** report: every user account with its status, password age, and last logon. The [Identity reports](../dashboards-reports/reports/identity.md) page describes each column. + +![AD Users report](/images/accessanalyzer/26.1/dashboards-reports/report-ad-users.webp) + +The sync also improves reports you may already be using. After it completes, the reports on the **File system** tab under **Reports > Data** resolve SIDs to names, expand group membership, and recognize open access granted through groups such as Domain Users. If you haven't scanned a file server yet, [Scan SMB file servers](./smb-file-servers.md) is the next guide. diff --git a/docs/accessanalyzer/26.1/guides/entra-id.md b/docs/accessanalyzer/26.1/guides/entra-id.md new file mode 100644 index 0000000000..92bb4a23c1 --- /dev/null +++ b/docs/accessanalyzer/26.1/guides/entra-id.md @@ -0,0 +1,104 @@ +--- +title: Scan Entra ID +description: Register an application for Access Analyzer, add the tenant as an Entra ID source, run an Identity sync, and open the Entra ID identity reports. +sidebar_position: 3 +--- + +Connect a Microsoft Entra ID tenant to Access Analyzer and run an Identity sync. The sync reads the tenant's users, groups (including dynamic membership rules), directory roles, and memberships. The results appear in the **Entra Users** and **Entra Groups** reports, and they let SharePoint Online scans of the same tenant calculate effective permissions. + +Access Analyzer signs in to the tenant as an application, not as a user, so the first job is an app registration with a client secret. + +## Before you start + +**In Entra ID.** You need an administrator who can create an app registration and grant admin consent for its permissions. The registration needs Microsoft Graph application permissions that let Access Analyzer read users, groups, and directory roles; the sync never writes to the directory. When you add the source, **Test connection** checks that the app has the permissions it needs. + +**The network.** The Access Analyzer server needs outbound HTTPS (TCP 443) to the Microsoft sign-in and Microsoft Graph endpoints for your tenant's cloud. + +**In Access Analyzer.** Sign in with the Admin role. + +:::note + +Registering this application doesn't let people sign in to Access Analyzer with their Microsoft accounts. Set that up separately under [Single sign-on](../settings/single-sign-on.md). + +::: + +## 1. Register an application in Entra ID + +1. In the Microsoft Entra admin center, create an app registration for Access Analyzer. +2. On the registration's **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**. You need both in later steps. +3. Under **Certificates & secrets**, create a client secret. +4. Copy the secret value; Entra ID shows it only once. +5. Under **API permissions**, add the Microsoft Graph application permissions that grant read access to users, groups, and directory roles. +6. Grant admin consent for the tenant. + +Record the secret's expiry date. When you rotate it, update the service account you create in the next section. + +## 2. Create the service account + +Entra ID sources use a **Client ID/secret** service account. The tenant isn't part of the account; you enter it on the source in the next section. + +1. Go to **Configuration > Service accounts** and click **Add service account**. +2. In **Name**, enter a unique name, for example `entra-access-analyzer-app`. +3. In **Service account type**, select **Client ID/secret**. +4. In **Client (application) ID**, paste the **Application (client) ID** from the registration. +5. In **Client secret**, paste the secret value. +6. Click **Add account**. + +![Add service account drawer with the Client ID/secret type selected](/images/accessanalyzer/26.1/service-accounts/add-client-id-secret.webp) + +The [Client ID and secret](../service-accounts/client-id-secret.md) page covers editing the account when you rotate the secret. + +## 3. Add the source + +1. Go to **Configuration > Sources** and click **Add source**. +2. In **Source type**, select **Entra ID**. +3. Under **Details**, enter a **Name**, such as the tenant's primary domain. +4. Under **Connection**, in **Tenant ID**, paste the **Directory (tenant) ID**. +5. In **Azure cloud**, leave **Azure (Commercial)** selected. If the tenant is in a government or China cloud, select **Azure Government (GCC)**, **Azure Government (GCC High)**, **Azure Government (DoD)**, or **Azure China (21Vianet)** instead. +6. Under **Access**, in **Service account**, select the account you created in the previous section. +7. Click **Test connection**. Access Analyzer signs in as the application and validates its permissions. Success shows a **Connection successful** message; failure shows a **Connection failed** alert with the reason. +8. Click **Add source**. + +![Add source drawer for an Entra ID source](/images/accessanalyzer/26.1/sources/add-entra-id.webp) + +Field details are on the [Entra ID](../sources/entra-id.md) source page. + +## 4. Create the Identity sync + +Click **Next** to move from one step to the next. + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Identity sync**. + + ![Create scan Type step with the Access, Sensitive data, and Identity sync cards](/images/accessanalyzer/26.1/scans/create-scan-1-type.webp) + +3. On the **Target** step, keep **Specific sources** and select the tenant's checkbox. +4. On the **Configure** step, click **Next**. Entra ID syncs have no settings to change. +5. On the **Schedule** step, select **On a schedule**. +6. Keep the default **Daily** at 02:00. +7. Leave the agent set to **System agent**. +8. On the **Review** step, enter a **Name** such as `contoso.onmicrosoft.com - identity sync`. +9. Click **Create & run now**. + +## 5. Watch the execution + +Go to **Configuration > Scan executions** and find the new scan in the list. The list refreshes on its own; the status moves from **Pending** through **Running** to **Completed**, and **Objects** shows how many directory objects the sync read. + +![Scan executions list](/images/accessanalyzer/26.1/scans/executions-list.webp) + +If the status is **Failed**, open the row's actions menu and click **View logs**, then check the **Detailed logs** tab. A sign-in error points at the client ID, secret, or tenant ID; a permission error means the app registration is missing a Graph permission or its admin consent. [Scan executions](../scans/scan-executions.md) lists every status. + +## 6. Check the reports + +Go to **Reports > Identity** and open the **Entra ID** tab. + +![Identity reports page on the Entra ID tab](/images/accessanalyzer/26.1/dashboards-reports/reports-identity-entra-id.webp) + +| Report | What it shows | +|--------|---------------| +| **Entra Users** | User accounts with multi-factor authentication (MFA) status, licenses, and sign-in activity | +| **Entra Groups** | Groups with their membership, type, and assigned licenses | + +Neither report has filters; open one and click **Refresh** to load the latest sync. Entra ID data has no dashboard of its own, and the Active Directory dashboard covers on-premises domains only. + +If you plan to scan SharePoint Online, do it after this sync has completed at least once. The [Scan Microsoft 365](./microsoft-365.md) guide explains how the two fit together. [Identity reports](../dashboards-reports/reports/identity.md) describes each report's columns. diff --git a/docs/accessanalyzer/26.1/guides/index.md b/docs/accessanalyzer/26.1/guides/index.md new file mode 100644 index 0000000000..7ab550cff0 --- /dev/null +++ b/docs/accessanalyzer/26.1/guides/index.md @@ -0,0 +1,17 @@ +--- +title: Guides +description: One guide per platform, taking a new administrator from an empty install to the first populated dashboard or report. +--- + +Each guide covers one platform from start to finish: the service account, the source, the scans, the first run, and where the results appear. Follow a guide once, right after [installing Access Analyzer](../install/index.md). After that, the reference sections for [Sources](../sources/index.md), [Scans](../scans/index.md), and [Dashboards and reports](../dashboards-reports/index.md) cover the day-to-day detail. + +Before you start, ensure you can sign in to Access Analyzer with the [Admin role](../settings/users.md). + +| Guide | Source type label | Service account type | Scans you create | Where results appear | +|-------|-------------------|----------------------|------------------|----------------------| +| [Scan SMB file servers](./smb-file-servers.md) | **File Server** | **Username/password** | Access scan, then Sensitive data scan | Data security dashboard, File system reports | +| [Scan Active Directory](./active-directory.md) | **Active Directory** | **Username/password** | Identity sync | Active Directory dashboard, Active Directory identity reports | +| [Scan Entra ID](./entra-id.md) | **Entra ID** | **Client ID/secret** | Identity sync | Entra ID identity reports | +| [Scan Microsoft 365](./microsoft-365.md) | **SharePoint Online** | **Client ID/certificate** | Access scan, then Sensitive data scan | Data security dashboard, SharePoint reports | + +The guides are independent, but they work best in pairs. File system permission reports show account and group names only after an Active Directory Identity sync has run for the domain, so follow the Active Directory guide alongside the SMB file servers guide. SharePoint permission reports expand group membership using the latest Entra ID Identity sync for the same tenant; without it, permissions are calculated from SharePoint data alone. Pair the Microsoft 365 guide with the Entra ID guide. diff --git a/docs/accessanalyzer/26.1/guides/microsoft-365.md b/docs/accessanalyzer/26.1/guides/microsoft-365.md new file mode 100644 index 0000000000..c7031ddd3b --- /dev/null +++ b/docs/accessanalyzer/26.1/guides/microsoft-365.md @@ -0,0 +1,138 @@ +--- +title: Scan Microsoft 365 +description: Connect a SharePoint Online tenant with a certificate-based app registration, run an Access scan and a Sensitive data scan, and find the results in the SharePoint reports. +sidebar_position: 4 +--- + +Connect one Microsoft 365 tenant's SharePoint Online sites and OneDrive drives to Access Analyzer and run two scans: an Access scan that collects sites, permissions, and sharing links, and a Sensitive data scan that classifies the documents the Access scan found. At the end you'll have data in the Data security dashboard and the SharePoint reports. + +Access Analyzer calls the source type **SharePoint Online**. It signs in to the tenant as an application with a certificate, so setup is a round trip between Access Analyzer and the Microsoft Entra app registration. + +## Before you start + +**In Entra ID.** You need an administrator who can create an app registration, upload a certificate to it, and grant admin consent for its permissions. The registration needs application permissions that let Access Analyzer read SharePoint sites, their permissions, and their files. Don't create a client secret for it: SharePoint Online sources authenticate only with a certificate, and Access Analyzer generates that certificate for you in step 1. + +**The network.** The Access Analyzer server needs outbound HTTPS (TCP 443) to `login.microsoftonline.com`, `graph.microsoft.com`, and your tenant's SharePoint hosts (`.sharepoint.com` and `-my.sharepoint.com`). + +**An Entra ID source for the same tenant.** Effective permissions in SharePoint depend on group membership, and Access Analyzer takes that from the latest completed Entra ID Identity sync of the same tenant. Follow [Scan Entra ID](./entra-id.md) first. Without it, Access Analyzer calculates effective permissions from SharePoint data alone. + +**In Access Analyzer.** Sign in with the Admin role. + +## 1. Create the service account and its certificate + +SharePoint Online sources use a **Client ID/certificate** service account. Unlike an Entra ID source, which records the tenant ID on the source itself, a SharePoint Online source takes the tenant ID from the service account. + +1. In the Microsoft Entra admin center, create an app registration for Access Analyzer. +2. On the registration's **Overview** page, copy the **Application (client) ID** and the **Directory (tenant) ID**. +3. In Access Analyzer, go to **Configuration > Service accounts** and click **Add service account**. +4. In **Name**, enter a unique name, for example `sharepoint-access-analyzer-app`. +5. In **Service account type**, select **Client ID/certificate**. +6. In **Client (application) ID**, paste the **Application (client) ID**. +7. In **Tenant ID**, paste the **Directory (tenant) ID**. +8. Under **Certificate**, leave **Generate for me** selected. When you save the account, Access Analyzer creates a self-signed RSA-2048 certificate that is valid for one year. +9. Click **Add account**. +10. In the **Account created and certificate generated** message, note the thumbprint and expiry date. +11. Click **Download certificate (.pem)** and save the file. +12. Click **Done**. + +![Add service account drawer with the Client ID/certificate type selected](/images/accessanalyzer/26.1/service-accounts/add-client-id-certificate.webp) + +If your organization issues its own certificates, select **Upload my own** instead and provide a `.pem` file, up to 1 MB, that contains both the certificate and its unencrypted private key. Access Analyzer rejects expired certificates and PFX files. The [Client ID and certificate](../service-accounts/client-id-certificate.md) page covers both options and what to do when the certificate is due to expire. + +## 2. Upload the certificate to the app registration + +1. In the Microsoft Entra admin center, open the app registration. +2. Under **Certificates & secrets**, upload the `.pem` file you downloaded. It holds only the public certificate. +3. Check that the thumbprint Entra ID shows matches the one from step 1. +4. Add the application permissions Access Analyzer needs. +5. Grant admin consent for the tenant. + +:::warning + +The generated certificate expires one year after you create the account, and scans fail when it does. When you regenerate or replace it in Access Analyzer, upload the new public certificate to the app registration before the next scan runs. + +::: + +## 3. Add the source + +1. Go to **Configuration > Sources** and click **Add source**. +2. In **Source type**, select **SharePoint Online**. +3. Under **Details**, enter a **Name**, such as the tenant name. +4. Under **Connection**, in **SharePoint domain**, enter the tenant's SharePoint host, for example `contoso.sharepoint.com`. +5. Leave **Azure cloud** at **Azure (Commercial)** unless the tenant is in a government or China cloud. +6. Under **Access**, in **Service account**, select the account from step 1. +7. Click **Test connection**. Access Analyzer signs in with the certificate and checks that the registration can reach the tenant. A **Connection successful** message confirms it; a **Connection failed** alert gives the reason. If it fails, confirm that you uploaded the certificate and granted admin consent. +8. Click **Add source**. + +![Add source drawer for a SharePoint Online source](/images/accessanalyzer/26.1/sources/add-sharepoint-online.webp) + +Field details are on the [Microsoft 365](../sources/microsoft-365.md) source page. + +## 4. Create the Access scan + +Run the Access scan first. The Sensitive data scan in step 6 classifies documents from the inventory this scan builds. + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Access** and click **Next**. + + ![Create scan Type step with the Access, Sensitive data, and Identity sync cards](/images/accessanalyzer/26.1/scans/create-scan-1-type.webp) + +3. On the **Target** step, keep **Specific sources** and select the tenant. +4. On the **Configure** step, leave **Use default configuration** selected for the first run. The defaults are **Workers** 4, **Collect OneDrive** on, and no entries in **Include site collections**, **Exclude site collections**, or **Exclude object URLs**, so the scan covers every site collection and every OneDrive drive. +5. On the **Schedule** step, leave **Manual — run on demand** for the first run. Leave the agent set to **System agent**. +6. On the **Review** step, enter a **Name** such as `Contoso SharePoint - access`. +7. Click **Create & run now**. + +![Create scan Review step with the scan named and the summary shown](/images/accessanalyzer/26.1/scans/create-scan-5-review-named.webp) + +When you're ready to narrow the scan, edit it and select **Customize this source** on the **Configure** step. **Include site collections** limits the scan to the site collections you list and takes no wildcards; **Exclude site collections** and **Exclude object URLs** accept the `*` wildcard. Keep **Workers** at 4 unless the tenant has SharePoint Online prioritization (adaptive throttling) turned on; even then, 32 is the practical maximum before throttling cancels out the gain. Every Access scan is a full crawl of the sites in scope; there is no differential option. [Scan types](../scans/scan-types.md) describes each setting. + +## 5. Watch the execution + +Go to **Configuration > Scan executions**. The list refreshes on its own, and the **Objects** column grows as the scan reads the tenant. A first scan of a large tenant takes a while. + +![Scan executions list](/images/accessanalyzer/26.1/scans/executions-list.webp) + +If the status is **Failed**, open the row's actions menu, click **View logs**, and check the **Detailed logs** tab. A sign-in error points at the certificate or the app registration. [Scan executions](../scans/scan-executions.md) lists every status. + +## 6. Create the Sensitive data scan + +After the Access scan shows **Completed**, create the second scan. It downloads documents from the Access scan's inventory and classifies them against sensitive data patterns. By default the scan skips documents larger than 10 MB and files with excluded extensions; both limits are in [Application settings](../settings/application.md). + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Sensitive data** and click **Next**. +3. On the **Target** step, select the same tenant. +4. On the **Configure** step, under **Sensitive data classification**, choose which pattern groups the scan uses. Leave **Inherit from global configuration** on to use the groups marked **Scanned by default** at **Configuration > Sensitive data patterns**, or turn it off and pick groups under **Sensitive Data Pattern Groups to Classify**. SharePoint Online has no other Sensitive data settings. + + ![Create scan Configure step for a Sensitive data scan showing the classification settings](/images/accessanalyzer/26.1/scans/create-scan-sensitive-3-configure.webp) + +5. On the **Schedule** step, leave **Manual — run on demand**. +6. On the **Review** step, enter a **Name** such as `Contoso SharePoint - sensitive data`. +7. Click **Create & run now**. + +:::note + +On a fresh install no pattern group is marked **Scanned by default**, and a scan with no groups selected classifies against every pattern group. Select the groups you care about before putting the scan on a schedule. + +::: + +[Sensitive data patterns](../sensitive-data-patterns/index.md) describes the built-in groups and confidence levels. + +## 7. Check the dashboards and reports + +Dashboards and reports don't refresh on their own. Open one and click **Refresh** to reload it; results from a scan that has just finished can take some time to appear. + +**Dashboards > Data security** shows the tenant in **Total Data Repositories**, **Total Objects Scanned**, **Permissions Analyzed**, **SharePoint Sites by Type**, and **Data Source Inventory**. After the Sensitive data scan, **Sensitive Data Findings** and **Sensitive Data by Source** include SharePoint too. + +**Reports > Data**, on the **SharePoint** tab, has four reports. + +![Data reports page on the SharePoint tab](/images/accessanalyzer/26.1/dashboards-reports/reports-data-sharepoint.webp) + +| Report | Needs | What it shows | +|--------|-------|---------------| +| **Shared Links** | Access scan | Anonymous and company-wide sharing links that expose content externally | +| **High-Risk ACLs** | Access scan | Sites and libraries with overly permissive access control entries | +| **Open Access** | Access scan | Content that all authenticated users can reach without restriction | +| **Sensitive Data Overview** | Sensitive data scan | Sensitive data classifications across SharePoint sites | + +**Shared Links** also appears under **Reports > Compliance** for each framework. The other three SharePoint reports live only on the **Data** page. [Data reports](../dashboards-reports/reports/data.md) describes every report and its filters, and the [Data security dashboard](../dashboards-reports/dashboards/data-security.md) page covers each card. diff --git a/docs/accessanalyzer/26.1/guides/smb-file-servers.md b/docs/accessanalyzer/26.1/guides/smb-file-servers.md new file mode 100644 index 0000000000..3033246cd9 --- /dev/null +++ b/docs/accessanalyzer/26.1/guides/smb-file-servers.md @@ -0,0 +1,151 @@ +--- +title: Scan SMB file servers +description: Connect a Windows, NetApp, Dell PowerScale, or Nutanix Files server over SMB, run an Access scan and a Sensitive data scan, and find the results. +sidebar_position: 1 +--- + +Connect one SMB file server to Access Analyzer and run the two scans that matter for file data: an Access scan that inventories shares, folders, and permissions, and a Sensitive data scan that classifies the files the Access scan found. At the end you'll have data in the Data security dashboard and the File system reports. + +In the UI the source type is called **File Server**. It covers Windows file servers, NetApp, Dell PowerScale (formerly Isilon), and Nutanix Files over SMB 2 or SMB 3. + +## Before you start + +You need three things: an account that can read the shares, a network path to the server, and the Admin role in Access Analyzer. + +**The account.** Access Analyzer only reads. Give the account NTFS **Read** on every folder and file you want inventoried; the specific rights it needs are List folder / Read data, Read attributes, and Read permissions. The Sensitive data scan reads file contents, which the same Read right covers. + +Making the account a member of the file server's local **Administrators** or **Backup Operators** group lets the scan read folders whose permissions would otherwise lock it out. Without administrative rights the scan still lists every share, but it can't record each share's local path, and any folder it can't open is logged as an error. + +**The network.** The Access Analyzer server, or the agent that runs the scan, needs TCP 445 to the file server. The connection uses SMB 2 or 3 with signing; SMB 1 isn't supported. Authentication uses NT LAN Manager (NTLM). + +| Direction | Port | Purpose | +|-----------|------|---------| +| Access Analyzer or agent to file server | TCP 445 | SMB for share enumeration, permission collection, and file content | + +:::warning + +Keep **Port** at 445. Sensitive data scans read file contents only over port 445, so a File Server source on any other port can run Access scans but not Sensitive data scans. + +::: + +**Names in reports.** The Access scan records permissions as security identifiers (SIDs). To see account and group names in reports, and to expand group membership, add the domain as an Active Directory source and run an Identity sync. The [Scan Active Directory](./active-directory.md) guide covers it; you can do it before or after this guide. + +## 1. Create the service account + +File Server sources use a **Username/password** service account. + +1. Go to **Configuration > Service accounts** and click **Add service account**. +2. In **Name**, enter a unique name, for example `svc-fileserver-scan`. +3. Leave **Service account type** set to **Username/password**. +4. In **Username**, enter the account as `DOMAIN\username`. +5. In **Password**, enter the password. +6. Click **Add account**. + +![Add service account drawer with the Username/password type selected](/images/accessanalyzer/26.1/service-accounts/add-username-password.webp) + +:::tip + +The field accepts `username@domain` too, but Sensitive data scans read only the `DOMAIN\username` form. Use that form for any account that runs both scan types. + +::: + +The [Username and password](../service-accounts/username-password.md) page has the full field reference. + +## 2. Add the source + +1. Go to **Configuration > Sources** and click **Add source**. +2. In **Source type**, select **File Server**. +3. Under **Details**, enter a **Name** for the source. +4. Optionally, add a **Description** and **Labels**. A label is a `key=value` pair such as `env=production`; it lets you target scans at groups of sources later. +5. Under **Connection**, in **Host**, enter the hostname or IP address of the server, for example `fileserver.example.com`. +6. Leave **Port** at 445. +7. In **Domain**, enter the Windows domain or workgroup name. Access Analyzer uses it only when the username doesn't carry a domain, so leave it empty if the service account's username is in the `DOMAIN\username` form. +8. Under **Access**, in **Service account**, select the service account you created earlier. +9. Click **Test connection**. Access Analyzer opens an SMB session and enumerates the shares. Success shows a **Connection successful** message; failure shows a **Connection failed** alert with the reason. +10. Click **Add source**. + +![Add source drawer with File Server selected, showing the Details, Connection, and Access sections](/images/accessanalyzer/26.1/sources/add-file-server.webp) + +To add many servers at once, [import sources from a CSV file](../sources/import-sources.md) instead. Field details and the connection checks are on the [SMB file servers](../sources/smb-file-servers.md) source page. + +## 3. Create the Access scan + +Run the Access scan first. The Sensitive data scan you create in [Create the Sensitive data scan](#5-create-the-sensitive-data-scan) works from the file inventory this scan builds, so there's nothing for it to classify until an Access scan has completed. + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Access** and click **Next**. + + ![Create scan Type step with the Access, Sensitive data, and Identity sync cards](/images/accessanalyzer/26.1/scans/create-scan-1-type.webp) + +3. On the **Target** step, keep **Specific sources** and select the file server you added. Only sources that support Access scans are listed. For a group of servers, select **Sources matching labels** instead and enter the label; the scan picks up any source that carries it at run time. + + ![Create scan Target step with one File Server source selected](/images/accessanalyzer/26.1/scans/create-scan-2-target-selected.webp) + +4. On the **Configure** step, leave **Use default configuration** selected. The defaults are **Workers** 3, **Exclude system shares** on (shares whose names end in `$` are skipped), **Maximum scan depth** 50, and **Enable File-Level Permission Scanning** off, which means permissions are collected for shares and folders but not for individual files. Change these later, after you've seen a first run; [Scan types](../scans/scan-types.md) explains each setting. +5. On the **Schedule** step, leave **Manual — run on demand** for the first run. When the first run looks right, edit the scan and switch to **On a schedule**; the default is **Daily** at 02:00. Leave the agent set to **System agent** unless you have deployed an [agent](../agents/index.md) closer to the file server. +6. On the **Review** step, enter a **Name** such as `Finance file server - access` and check the summary. +7. Click **Create & run now**. + +![Create scan Review step with the scan named and the summary shown](/images/accessanalyzer/26.1/scans/create-scan-5-review-named.webp) + +**Create scan** saves the scan without running it. You can start it any time from **Configuration > Scans** with **Run** in the row's actions menu. + +## 4. Watch the execution + +Go to **Configuration > Scan executions** and find the row for your scan. The list refreshes on its own. + +![Scan executions list showing a completed File Server Access scan](/images/accessanalyzer/26.1/scans/executions-list.webp) + +The status moves from **Pending** to **Running** and ends at **Completed**, **Completed with errors**, or **Failed**. The **Objects** and **Duration** columns fill in as the scan works. To follow along, open the row's actions menu and click **View logs**: the **Overview** tab shows milestones such as when the scan started and how long it took, and the **Detailed logs** tab shows every message. + +![Execution logs dialog on the Overview tab](/images/accessanalyzer/26.1/scans/execution-logs-overview.webp) + +**Completed with errors** means some objects couldn't be read, most often folders the account has no rights to. The data that was collected is kept, and the next run uploads the rest. Check **Detailed logs** for the paths, fix the permissions or add the account to **Backup Operators**, and run the scan again from **Configuration > Scans**. + +[Scan executions](../scans/scan-executions.md) lists every status and the pause, resume, and stop controls. + +## 5. Create the Sensitive data scan + +After the Access scan shows **Completed**, create the second scan. It classifies files from the Access scan's inventory against sensitive data patterns. Files larger than 10 MB and files with excluded extensions are skipped by default; both limits are in [Application settings](../settings/application.md). + +1. Go to **Configuration > Scans** and click **Create scan**. +2. On the **Type** step, select **Sensitive data** and click **Next**. +3. On the **Target** step, select the same file server. +4. On the **Configure** step, under **Sensitive data classification**, select the pattern groups to look for. With **Inherit from global configuration** on, the scan uses the groups marked **Scanned by default** at **Configuration > Sensitive data patterns**. Turn it off to select groups for this scan only, such as **PCI DSS**, **PII**, and **Credentials**, under **Sensitive Data Pattern Groups to Classify**. + + ![Create scan Configure step for a Sensitive data scan showing the classification settings](/images/accessanalyzer/26.1/scans/create-scan-sensitive-3-configure.webp) + +5. Leave the File Server settings at their defaults: **Workers** 3, **Differential scan** off, and **Exclude System Shares** on. Turn **Differential scan** on later so scheduled runs classify only files that changed since the last run. +6. On the **Schedule** step, leave **Manual — run on demand**. +7. On the **Review** step, enter a **Name** such as `Finance file server - sensitive data`. +8. Click **Create & run now**. + +:::note + +On a fresh install no pattern group is marked **Scanned by default**. A scan that inherits the global configuration with no groups enabled, or that has no groups selected, classifies against every pattern group, built-in and custom. Select groups when you want the findings limited to the categories you care about. + +::: + +Follow the run in **Configuration > Scan executions**, as described in [Watch the execution](#4-watch-the-execution). [Sensitive data patterns](../sensitive-data-patterns/index.md) describes the built-in groups and how to add your own patterns. + +## 6. Check the dashboards and reports + +Dashboards and reports don't refresh on their own. Open one and click **Refresh** after a scan completes. + +**Dashboards > Data security** fills in after the Access scan: **Total Data Repositories**, **Total Objects Scanned**, **Permissions Analyzed**, **File Server Objects by Host**, and **Data Source Inventory**. After the Sensitive data scan, **Sensitive Data Findings** and **Sensitive Data by Source** show counts too. The **Data Source** filter narrows the view by source type, **File Servers** or **SharePoint Online**, not to a single server. + +![Data security dashboard with file server data](/images/accessanalyzer/26.1/dashboards-reports/data-security-dashboard.webp) + +**Reports > Data**, on the **File system** tab, has the reports that matter for file servers: + +| Report | Needs | What it shows | +|--------|-------|---------------| +| **Open Access** | Access scan | Shares that Everyone or Domain Users can reach without restriction | +| **High Risk ACLs** | Access scan | Shares and folders with overly permissive ACLs | +| **Broken Inheritance** | Access scan | Folders where inheritance is broken and explicit permissions are applied | +| **Share Audit** | Access scan | Effective permissions on one share; select a **Share** in the filters first | +| **Sensitive Data Overview** | Sensitive data scan | Findings across the scanned locations, filtered by host, share, pattern group, or pattern | + +**Activity Investigation** appears in the same tab but stays empty until you connect [Netwrix Activity Monitor](../integrations/netwrix-activity-monitor.md). **Reports > Compliance** arranges the same reports by framework, so the **GDPR** or **PCI DSS** tabs populate from these two scans as well. + +If the permission reports show SIDs instead of names, follow [Scan Active Directory](./active-directory.md) and run an Identity sync for the domain. [Data reports](../dashboards-reports/reports/data.md) describes every report and its filters. diff --git a/docs/accessanalyzer/26.1/index.md b/docs/accessanalyzer/26.1/index.md index e61df81485..50f8de97a0 100644 --- a/docs/accessanalyzer/26.1/index.md +++ b/docs/accessanalyzer/26.1/index.md @@ -1,67 +1,45 @@ --- -id: access-analyzer -title: "Access Analyzer" -pagination_label: Access Analyzer -keywords: ['access', 'analyzer', 'dspm'] -description: "Netwrix Access Analyzer, an on-premises DSPM product for data security and access analysis" +title: Access Analyzer +description: What Netwrix Access Analyzer does, how its parts fit together, and where to begin. sidebar_position: 1 --- -# Overview +## What Access Analyzer is -Access Analyzer is an on-premises Data Security Posture Management (DSPM) product that helps organizations discover, classify, and report on sensitive data across enterprise file systems. Deployed on your own infrastructure, it provides visibility into data access patterns, identifies compliance risks, and more, all without sending data to the cloud. +Netwrix Access Analyzer is a self-hosted web application that you install on a Linux server you own. It scans your file servers, directories, and Microsoft 365 tenant and builds a picture of where sensitive data lives and who can reach it. It belongs to the data security posture management (DSPM) category of products. [Key concepts](key-concepts.md) defines the terms used throughout. -Today, Access Analyzer has three functional components: +![Access Analyzer Home page with the navigation sidebar and getting-started content](/images/accessanalyzer/26.1/overview/home.webp) -- **Discovery** - Connect to file systems, cloud file sources, and your identity systems to collect metadata about your files and employees -- **Classification** - Detect and classify your data using our pattern classifier -- **Reporting** - Visualize your security posture with built-in dashboards +## What it does -:::note Using an older version? -This documentation covers **Access Analyzer version 26.0**. If you are running a previous Windows-based version, select your version from the following list: +### Sources -- [Access Analyzer 12.0 documentation](https://docs.netwrix.com/docs/accessanalyzer/12_0) -- [Access Analyzer 11.6 documentation](https://docs.netwrix.com/docs/accessanalyzer/11_6) -::: +Access Analyzer collects permissions and inventory from SMB file servers (the **File Server** source type), Active Directory, Entra ID, and Microsoft 365 (the **SharePoint Online** source type). Each connected system is a source, and most sign in with a [service account](service-accounts/index.md). [Sources](sources/index.md) covers each type. -## Discovery +### Scans and agents -One of the three major components to Access Analyzer is discovering the files and other metadata available within your sources. When you add a Service Account & a Source then setup a Scan, Access Analyzer immediately starts pulling in this metadata. +A scan defines what to collect, from which sources, and when. Access scans inventory shares, folders, files, and sites with their permissions; Sensitive data scans read file content; Identity sync pulls users, groups, and memberships from a directory. Scans run on demand or on a schedule. Every scan runs on an agent: the System agent built into the server, or agents you deploy on other Linux hosts and pick with labels. See [Scans](scans/index.md) and [Agents](agents/index.md). -An optional but powerful feature of Access Analyzer is that you can run Access Analyzer Agents anywhere, and these agents can share the load of your scans (or handle them entirely!). This is great to ensure data never leaves certain regions or to improve discovery performance by handling the discovery process close to the source. +### Sensitive data -:::note -The discovery process is a read-only operation. Access Analyzer does not modify objects on a source. It also does not install persistent agents on file servers or domain controllers. -::: +Sensitive data patterns are regular expressions grouped by compliance program or data category, each rated Low, Medium, or High confidence. Access Analyzer ships 139 built-in patterns in 11 groups, and you can add your own. A scan records which patterns matched in a file and how many times, never the matched text. See [Sensitive data patterns](sensitive-data-patterns/index.md). -## Classification +### Dashboards and reports -Once you have gotten the metadata about your information and where it lives you can classify that information by reading it in and classifying that information with known patterns. We do this today with our Pattern Classifier. +Two dashboards, Data security and Active Directory, summarize what your scans have found. Reports under **Data**, **Identity**, and **Compliance** each answer one question, such as which folders have broken permission inheritance or which files contain sensitive data. Both have filters and drill-down. See [Dashboards and reports](dashboards-reports/index.md). -## Reporting +### Activity data -After each scan, Access Analyzer stores results in a high-performance analytics database and makes them available through embedded dashboards and reports. Security teams can filter by domain, file server, site, classification type, and more to drill into specific findings without having to write queries. +Scans show who can reach data. To see who used that access, connect [Netwrix Activity Monitor](integrations/netwrix-activity-monitor.md), which streams the events it records on file servers, SharePoint Online, and Microsoft 365 Copilot to Access Analyzer. They fill the **Activity** tab of the Data security dashboard and the Activity Investigation report. See [Integrations](integrations/index.md). -Below are just a few examples of the reports available: +### Users and sign-in -| Report | Description | -| --- | --- | -| **Sensitive Data Discovery** | Classifies file content across file servers and SharePoint Online against built-in detection patterns for PII, PHI, credentials, and financial data. Access Analyzer maps findings to compliance frameworks including GDPR, HIPAA, PCI DSS, and CCPA. | -| **Access Risk Analysis** | Identifies open access, overly permissive ACLs, broken permission inheritance, and stale entitlements across file shares and SharePoint sites. Shows effective permissions for any user or group. | -| **Identity Inventory** | Continuously syncs users, groups, memberships, and roles from Active Directory and Entra ID. Tracks group nesting, stale accounts, and role assignments across your identity providers. | -| **File Activity Monitoring** | Ingests real-time file system and SharePoint activity events from Netwrix Activity Monitor. Powers activity reports and enables anomaly detection and sensitive data activity tracking. Requires a separate Netwrix Activity Monitor deployment. | +Every user holds one of three roles: Admin, User admin, or Viewer. Admins can change anything, User admins manage accounts only, and Viewers have read-only access. People sign in with a local account or, after you connect a directory, with Active Directory or Entra ID credentials. See [Users and roles](settings/users.md) and [Single sign-on](settings/single-sign-on.md) under [Settings](settings/index.md). -# Supported Source Types +## Where to start -Where can you look for information in your environment? Today, Access Analyzer supports connecting to the following sources types: +Start with [Installation](install/index.md): pick a size, prepare the server, and run the installer. Then [sign in for the first time](install/first-sign-in.md), change the one-time password, and connect a directory or put that off. After that, follow the [Guides](guides/index.md), one per platform, to your first populated dashboard. Before a rollout, read [What's new in 26.1](whats-new.md) and [Known limitations](known-limitations.md). -| Name | Type | Connection Method | -|---|---|---| -| Active Directory | Identity | LDAP/LDAPS | -| Entra ID | Identity | API | -| SMB (generic) | File System | SMB 3.x | -| NetApp | File System | SMB 3.x | -| Dell PowerScale (formerly Isilon) | File System | SMB 3.x | -| Windows File Server | File System | SMB 3.x | -| Nutanix | File System | SMB 3.x | -| Microsoft 365 (M365) | Cloud Storage | API | +## Supported browsers + +Access Analyzer works in any current browser. Internet Explorer isn't supported. diff --git a/docs/accessanalyzer/26.1/install/_category_.json b/docs/accessanalyzer/26.1/install/_category_.json index 4ec6b4da75..dd1605971d 100644 --- a/docs/accessanalyzer/26.1/install/_category_.json +++ b/docs/accessanalyzer/26.1/install/_category_.json @@ -1,6 +1,6 @@ { "label": "Installation", - "position": 12, + "position": 10, "collapsed": true, "collapsible": true } diff --git a/docs/accessanalyzer/26.1/install/first-sign-in.md b/docs/accessanalyzer/26.1/install/first-sign-in.md new file mode 100644 index 0000000000..09d4b5662b --- /dev/null +++ b/docs/accessanalyzer/26.1/install/first-sign-in.md @@ -0,0 +1,81 @@ +--- +title: Sign in for the first time +description: Sign in with the first administrator's one-time password, set a permanent password, and choose whether to connect an identity provider right away or later. +sidebar_position: 3 +--- + +The installer ends by printing a URL, a username, and a one-time password. The username is the email address you gave as the first administrator. Sign in with them once, and Access Analyzer walks you through replacing the password and deciding how everyone else signs in. + +## Sign in + +1. Open `https://` in a browser, using the hostname you gave the installer. +2. In **Username**, enter the first administrator's email address. +3. In **Password**, enter the one-time password from the installer summary. +4. Click **Sign in**. + +![Access Analyzer sign-in page with Username and Password fields](/images/accessanalyzer/26.1/overview/sign-in.webp) + +:::warning + +Three wrong passwords lock the account, and at this point no other administrator exists to unlock it. Paste the one-time password rather than retyping it. If you no longer have it, see [Retrieve the one-time password again](#retrieve-the-one-time-password-again). + +::: + +## Set a new password + +The one-time password works only once, so Access Analyzer immediately asks for a new one, with the message "You must set a new password before continuing." + +1. In **New password**, enter a password of at least 12 characters. There are no other rules about which characters it must contain. +2. In **Confirm password**, enter it again. +3. Click **Change password**. + +The page rejects a new password for one of these reasons: + +| Message | Cause | +|---|---| +| Passwords do not match. | The two entries differ. | +| Password does not meet complexity requirements. | The password has fewer than 12 characters. | +| New password cannot be the same as your current password. | You entered the one-time password again. | + +## Choose how to set up sign-in + +After the password change, Access Analyzer shows a page titled **Connect an identity provider**. It explains that you're signed in with the local administrator account, and that connecting Active Directory or Entra ID lets the rest of your team sign in with the accounts they already have. It offers two buttons. + +![Connect an identity provider page with Set up identity provider and Set up later](/images/accessanalyzer/26.1/integrations/identity-provider-setup.webp) + +### Set up identity provider + +Click **Set up identity provider** to connect your directory right away. The setup runs in three steps, shown across the top of the page as **Identity provider**, **Connect**, and **Admins**. + +1. On **Identity provider**, select **Active Directory** or **Entra ID**. + + ![Identity provider selection step with Active Directory and Entra ID](/images/accessanalyzer/26.1/integrations/identity-provider-choose.webp) + +2. Click **Continue**. +3. On **Connect**, enter the connection details for the provider you chose. Active Directory needs a domain controller, a service account (a read-only account is recommended), and the certificate authority (CA) that issued the domain controller's certificate for Lightweight Directory Access Protocol over TLS (LDAPS). Entra ID needs an app registration and a one-time administrator consent. [Single sign-on](../settings/single-sign-on.md) describes every field and what to prepare on the directory side. +4. Click **Test connection and continue** for Active Directory, or **Sign in with Microsoft and continue** for Entra ID. +5. On **Admins**, add the people who should hold the Admin role, or leave the list empty. +6. Click **Finish setup**. If you added nobody, the button reads **Continue without admins** instead. +7. Wait while Access Analyzer applies the configuration, then click **Login to Access Analyzer**. + +That last click signs you out, because the setup has just changed the sign-in service. Sign in again with the local administrator account. Anyone you added on **Admins** signs in through the directory instead; if you connected Entra ID, the sign-in page also shows **Sign in with Microsoft**. + +### Set up later + +Choose this if you don't have the directory details yet, or if you want to explore the application before inviting anyone else. + +Click **Set up later** to skip straight to the application. The local administrator account keeps working, and Access Analyzer stops redirecting you to this page. You can run the same steps later: go to **Settings > System** and, under **Single sign-on**, click **Go to setup**. + +## Retrieve the one-time password again + +If you closed the terminal before copying the password, you can read it back from the server. The stored password works only until the first administrator replaces it. Run this command on the server as root: + +```bash +kubectl get secret dspm-bootstrap-admin -n access-analyzer -o jsonpath='{.data.password}' | base64 -d +``` + +The command prints the password. + +## The Home page + +After you sign in, the **Home** page greets you by name and offers to connect your first source. The [Guides](../guides/index.md) walk through connecting a source and scanning it. diff --git a/docs/accessanalyzer/26.1/install/identity-provider.md b/docs/accessanalyzer/26.1/install/identity-provider.md deleted file mode 100644 index 46deb34ee0..0000000000 --- a/docs/accessanalyzer/26.1/install/identity-provider.md +++ /dev/null @@ -1,553 +0,0 @@ ---- -title: "Configure Identity Provider" -description: "Deployment steps for connecting an Identity Provider to Access Analyzer using the installer" -sidebar_position: 50 -draft: true ---- - -# Configure Identity Provider - -:::note -This article is for the team performing the Access Analyzer deployment. It covers the installer flags required to connect an identity provider at install time. If you are an application administrator setting up user accounts after the IdP connection is in place, see [Identity Provider](../configurations/identity-provider.md). -::: - -**Related reading:** - -- [Quick Install](quickinstall.md) — Active Directory deployment using environment variables, end-to-end -- [Installer Command Reference](install-commands.md) — full catalog of every installer flag and environment variable -- [TLS Certificate Requirements](system/certificates.md) — certificate formats, SAN rules, CA bundle preparation - -Access Analyzer supports connecting an identity provider (IdP) so users authenticate through your organization's directory rather than with local credentials. IdP federation is **optional** — if you omit `--idp-type` at install time, Access Analyzer deploys without Keycloak and uses local accounts only. - -When you configure `--idp-type`, the installer automatically: - -1. Deploys Keycloak (v26.5.3) as part of the cluster -2. Waits for Keycloak to become healthy -3. Creates the IdP federation using the flags you provided -4. Enables OpenID Connect (OIDC) authentication in the Access Analyzer application - -## Before you begin - -Confirm the following before running the installer with IdP flags: - -- Your infrastructure meets the Access Analyzer cluster system requirements — see [Hardware and System Requirements](system/requirements.md) -- You have prepared and placed TLS certificates on the VM — see [TLS Certificate Requirements](system/certificates.md) -- You have collected the required credentials from the customer's IdP or directory administrator (see [Identity Provider — Part 1](../configurations/identity-provider.md#part-1-configure-your-identity-provider)) -- For LDAP/AD: the Access Analyzer server has network access to the LDAP server on port 636 (LDAPS) or 389 (LDAP) -- For a private CA certificate: you have the PEM file available on the server and will pass `--ca-bundle ` to the installer - -:::warning -`--hostname` is required and must: - -- Be a real DNS hostname (not an IP address — IPs will not work because the browser TLS handshake requires the hostname in the certificate's Subject Alternative Name (SAN)). -- Be lowercase, and match lowercase in the certificate SAN list. Keycloak derives its OIDC issuer URL from this value; a case mismatch between SAN and browser-normalized hostname produces HTTP 401 at sign-in. -- Resolve the same from client browsers and in-cluster pods. The installer configures the in-cluster rewrite automatically; the customer is responsible for the public DNS record or `/etc/hosts` entry that client browsers use. -- Avoid the `.local` and `.localhost` TLDs — both break in-cluster DNS resolution and silently break OIDC login flows. - -For full certificate format and preparation details, see [TLS Certificate Requirements](system/certificates.md). -::: - -## Choosing an IdP type - -| `--idp-type` value | Use case | -| --- | --- | -| `ad` | Active Directory via LDAP (on-premises) | -| `ldap` | Generic LDAP | - - - -:::note -`--idp-alias` must match `[A-Za-z0-9._-]+` — letters, digits, hyphens, underscores, and dots only. Spaces aren't allowed. The alias appears as the label on the login button. -::: - - - -## Configure Active Directory - -:::tip -For a step-by-step end-to-end walkthrough using environment variables (recommended for most customers), see the [Quick Install](quickinstall.md). This section is the flag-level reference. -::: - -**Required flags:** `--idp-type ad`, `--idp-alias`, `--ldap-url`, `--ldap-bind-dn`, `--ldap-users-dn` - -**Optional:** `--ldap-email-attribute` (default: `mail`) - -**Prompted secret:** LDAP bind credential — entered interactively, never written to disk or logs - -If an internal CA not in the OS trust store (typical for on-prem AD) signs your domain controller's LDAPS certificate, pass the root CA cert via `--ca-bundle`. Without it, Keycloak's LDAPS handshake to the DC will fail with a TLS trust error. The CA that signed the DC's LDAPS certificate may be different from the CA that signed your Access Analyzer server's TLS certificate — verify the DC's cert chain specifically. See [TLS Certificate Requirements](system/certificates.md) for details on assembling the CA bundle. - -```bash -export LICENSE_KEY='[YOUR_LICENSE_KEY]' - -curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --hostname aa26.1.corp.example.com \ - --tls-cert /opt/dspm-tls/aa26.1.crt \ - --tls-key /opt/dspm-tls/aa26.1.key \ - --ca-bundle /opt/dspm-tls/ca-bundle.crt \ - --idp-type ad \ - --idp-alias active-directory \ - --ldap-url ldaps://dc.corp.example.com:636 \ - --ldap-bind-dn "CN=svc-dspm,OU=ServiceAccounts,DC=corp,DC=example,DC=com" \ - --ldap-users-dn "OU=Users,DC=corp,DC=example,DC=com" -``` - -Replace the LDAP URL with the customer's domain controller address (LDAPS on port 636 recommended). When prompted, enter the bind account password. - -The `ad` type uses Active Directory–specific defaults: `sAMAccountName` for the username attribute and `objectGUID` for the UUID attribute. - -## Configure Generic LDAP - -Use this type for OpenLDAP and other non-AD LDAP directories. - -**Required flags:** `--idp-type ldap`, `--idp-alias`, `--ldap-url`, `--ldap-bind-dn`, `--ldap-users-dn` - -**Optional:** `--ldap-email-attribute` (default: `mail`) - -**Prompted secret:** LDAP bind credential - -```bash -export LICENSE_KEY='[YOUR_LICENSE_KEY]' - -curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --hostname aa26.1.corp.example.com \ - --tls-cert /opt/dspm-tls/aa26.1.crt \ - --tls-key /opt/dspm-tls/aa26.1.key \ - --ca-bundle /opt/dspm-tls/ca-bundle.crt \ - --idp-type ldap \ - --idp-alias ldap \ - --ldap-url ldaps://ldap.corp.example.com:636 \ - --ldap-bind-dn "CN=svc-dspm,OU=ServiceAccounts,DC=corp,DC=example,DC=com" \ - --ldap-users-dn "OU=Users,DC=corp,DC=example,DC=com" -``` - -As with the Active Directory section, pass `--ca-bundle` with the root CA cert that signed the directory's LDAPS certificate when it isn't in the OS trust store. - -The `ldap` type uses generic LDAP defaults: `uid` for the username attribute and `entryUUID` for the UUID attribute. - -## Recover from a failed IdP configuration - -If IdP configuration fails after the cluster is already running, use `--configure-idp-only` to retry without reinstalling K3s or ArgoCD: - -```bash -curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --configure-idp-only \ - --idp-type ad \ - --idp-alias active-directory \ - --ldap-url ldaps://dc.corp.example.com:636 \ - --ldap-bind-dn "CN=svc-dspm,OU=ServiceAccounts,DC=corp,DC=example,DC=com" \ - --ldap-users-dn "OU=Users,DC=corp,DC=example,DC=com" -``` - -:::note -`--configure-idp-only` doesn't require `--license-key`. It skips all infrastructure provisioning steps and runs only the IdP configuration phase. -::: - -## Next steps - -After the installer completes IdP configuration, the application administrator must pre-provision user accounts in Access Analyzer before any users can sign in. See [Identity Provider](../configurations/identity-provider.md#pre-provision-user-accounts). - -## Manual configuration reference - -The installer automates all of the following steps. Use this section only if you need to reconfigure or troubleshoot an IdP connection on a cluster that is already running, without re-running the installer. - -### Authenticate to the Keycloak Admin CLI - -Run this step before any manual configuration. It authenticates the Keycloak Admin CLI inside the pod using the bootstrap credentials injected at deploy time. - -```bash -kubectl exec -n access-analyzer statefulset/keycloak -- bash -c ' - /opt/keycloak/bin/kcadm.sh config credentials \ - --server http://localhost:8080/auth \ - --realm master \ - --user "$KC_BOOTSTRAP_ADMIN_USERNAME" \ - --password "$KC_BOOTSTRAP_ADMIN_PASSWORD"' -``` - -:::note -Keycloak reads the bootstrap admin credentials from environment variables already present in the pod. Don't pass them as command-line arguments — they would appear in Kubernetes audit logs. -::: - - - -### Configure LDAP / Active Directory — manual - -**Required values:** LDAP server URL, service account DN, service account password, users base DN - -**Step 1 — Create the LDAP User Federation component** - -```bash -LDAP_ID=$(kubectl exec -i -n access-analyzer statefulset/keycloak -- bash <"]' \ - -s 'config.bindDn=[""]' \ - -s 'config.bindCredential=[""]' \ - -s 'config.usersDn=[""]' \ - -s 'config.usernameLDAPAttribute=["sAMAccountName"]' \ - -s 'config.rdnLDAPAttribute=["cn"]' \ - -s 'config.uuidLDAPAttribute=["objectGUID"]' \ - -s 'config.userObjectClasses=["person,organizationalPerson,user"]' \ - -s 'config.searchScope=["2"]' \ - -s 'config.importEnabled=["true"]' \ - -s 'config.syncRegistrations=["false"]' \ - -o --fields id | grep '"id"' | sed 's/.*"id"[[:space:]]*:[[:space:]]*"\([^"]*\)".*/\1/' -EOF -) -``` - -**Step 2 — Add the email attribute mapper** - -```bash -kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh create components -r dspm \ - -s name=email-mapper \ - -s providerType=org.keycloak.storage.ldap.mappers.LDAPStorageMapper \ - -s providerId=user-attribute-ldap-mapper \ - -s "parentId=$LDAP_ID" \ - -s '{"ldap.attribute":["mail"],"is.mandatory.in.ldap":["false"],"always.read.value.from.ldap":["false"],"read.only":["true"],"user.model.attribute":["email"]}' -``` - -**Step 3 — Add the provider attribute mapper** - -```bash -kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh create components -r dspm \ - -s name=ldap-provider-attribute \ - -s providerType=org.keycloak.storage.ldap.mappers.LDAPStorageMapper \ - -s providerId=hardcoded-attribute-mapper \ - -s "parentId=$LDAP_ID" \ - -s '{"attribute.value":["ldap"],"user.model.attribute":["ldap_provider"]}' -``` - -**Step 4 — Add the realm protocol mapper** - -```bash -kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh create protocol-mappers/models -r dspm \ - --body '{ - "name": "ldap-identity-provider-claim", - "protocol": "openid-connect", - "protocolMapper": "oidc-usermodel-attribute-mapper", - "config": { - "user.attribute": "ldap_provider", - "claim.name": "identity_provider", - "jsonType.label": "String", - "id.token.claim": "true", - "access.token.claim": "true", - "userinfo.token.claim": "true" - } - }' -``` - -### Verify the configuration — manual - -**LDAP (component check only):** - -```bash -TYPE=ldap ./scripts/verify-idp-config.sh -``` - -**LDAP (with connectivity test):** - -```bash -TYPE=ldap \ -LDAP_URL= \ -LDAP_BIND_DN= \ -LDAP_BIND_CREDENTIAL= \ -./scripts/verify-idp-config.sh -``` - -## Troubleshooting IdP configuration - -IdP configuration runs as the final step of the installer, after Keycloak is healthy. A failure here means the cluster and applications are running correctly — only the identity federation is missing. - -### Check the installer log - -The installer log contains the full `kcadm.sh` output: - -```bash -grep -A 20 "Configuring IdP federation" /var/log/dspm-installer.log -``` - -### Common error messages - -| Message | Likely cause | -| --- | --- | -| `Failed to authenticate with Keycloak admin CLI` | Keycloak pod not ready; see [Check Keycloak pod health](#check-keycloak-pod-health) | -| `409 Conflict` from `kcadm.sh create` | An IdP with this alias already exists in Keycloak | -| `PKIX path building failed` in Keycloak logs (LDAP sign-ins fail silently) | CA bundle is missing the LDAPS DC's CA — see [TLS Certificate Requirements](system/certificates.md#multi-domain-and-multi-ca-environments) | - -### Check Keycloak pod health - -```bash -# Confirm the pod is running -kubectl get pods -n access-analyzer -l app=keycloak - -# Check for recent errors in the Keycloak logs -kubectl logs -n access-analyzer statefulset/keycloak --tail=50 -``` - -### Retry using --configure-idp-only - -If the cluster is healthy but IdP configuration failed, re-run the installer with `--configure-idp-only`. This skips K3s and ArgoCD entirely and retries only the Keycloak configuration: - -```bash -curl -sLfo - "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-install.sh?auth=license:$LICENSE_KEY" | bash -s -- \ - --configure-idp-only \ - --hostname aa26.1.corp.example.com \ - --ca-bundle /opt/dspm-tls/ca-bundle.crt \ - --idp-type \ - --idp-alias \ - # ...same --idp-* flags used during the original install -``` - -`--configure-idp-only` doesn't require `--license-key`. - -### If retry fails with 409 Conflict - -If a previous partial run created the IdP instance in Keycloak before failing (for example, during mapper creation), the retry fails with a `409 Conflict`. Remove the partial IdP first using `kcadm.sh` inside the Keycloak pod. - -Authenticate first: - -```bash -kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh config credentials \ - --server http://localhost:8080/auth --realm master \ - --user "$KC_BOOTSTRAP_ADMIN_USERNAME" \ - --password "$KC_BOOTSTRAP_ADMIN_PASSWORD" -``` - -For **LDAP or AD** IdPs (child mappers cascade-delete automatically): - -```bash -LDAP_ID=$(kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh get components -r dspm \ - -q name= \ - -q type=org.keycloak.storage.UserStorageProvider \ - --fields id -c \ - | python3 -c "import sys,json; d=json.load(sys.stdin); print(d[0]['id'] if d else '')") - -kubectl exec -n access-analyzer statefulset/keycloak -- \ - /opt/keycloak/bin/kcadm.sh delete components/"${LDAP_ID}" -r dspm -``` - -Replace `` with the value you passed to `--idp-alias` during the failed install. Then re-run `--configure-idp-only`. diff --git a/docs/accessanalyzer/26.1/install/index.md b/docs/accessanalyzer/26.1/install/index.md new file mode 100644 index 0000000000..be28c94c3a --- /dev/null +++ b/docs/accessanalyzer/26.1/install/index.md @@ -0,0 +1,24 @@ +--- +title: Installation +description: How to prepare a Linux server, run the Access Analyzer installer, and sign in for the first time. +--- + +Access Analyzer runs on a single Linux server that you own. You download one installer binary, run it as root, and answer a few prompts. The installer checks the server, sets up every service, and prints the address and credentials you use to sign in. + +An installation takes three steps, each covered on its own page. + +1. [Requirements](requirements.md)—pick a size, confirm the server has enough CPU, RAM, and disk, and gather the license key, hostname, TLS certificate, and first administrator's email address before you start. +2. [Install Access Analyzer](run-the-installer.md)—copy the certificate to the server and run `dspm-installer`, either answering the prompts or passing everything as flags. +3. [Sign in for the first time](first-sign-in.md)—open the web application, change the first administrator's one-time password, and either connect Active Directory or Entra ID or skip that step for later. + +After the first sign-in, the [Guides](../guides/index.md) walk you through scanning your first source. + +## People you need + +You need an administrator with root access to the Linux server, either signed in as root or using `sudo`. The installer writes to `/etc/dspm`, `/var/log`, and `/usr/local/bin`, so a non-root account can't complete it. + +You also need someone who can issue a TLS certificate for the server's hostname and someone who can open firewall ports. The [Requirements](requirements.md) page lists exactly what to ask for. + +## Scripting or troubleshooting an installation + +The [Installer reference](installer-reference.md) lists the flags, environment variables, exit codes, and preflight checks, for when you script an installation or need to find out why one stopped. diff --git a/docs/accessanalyzer/26.1/install/install-commands.md b/docs/accessanalyzer/26.1/install/install-commands.md deleted file mode 100644 index 892905dcc7..0000000000 --- a/docs/accessanalyzer/26.1/install/install-commands.md +++ /dev/null @@ -1,302 +0,0 @@ ---- -title: "Installer Command Reference" -description: "Options you can pass to the Access Analyzer installer to customize your deployment" -sidebar_position: 20 -draft: true ---- - -# Installer Command Reference - -You install Access Analyzer using a single curl command that downloads and runs the installer. You can pass options to this command to customize how the installer deploys the product on your server. Most installations need only a license key and accept all defaults. - -## Before You Run the Installer - -### Set your license key - -Export your license key as an environment variable before running any installer command. This keeps the key out of your shell history and makes it available to the installer automatically. - -```bash -export LICENSE_KEY="[YOUR_LICENSE_KEY]" -``` - -Replace "[YOUR_LICENSE_KEY]" with the license key Netwrix provided. All examples on this page assume you have exported this variable. - -:::warning -Your license key authenticates access to the Netwrix package registry. Don't share it, commit it to version control, or leave it visible in script files. -::: - -### Choose an installer version - -If you don't specify a version, the installer downloads the latest stable release automatically. This is appropriate for initial deployments and any time you want the latest release: - -```bash -# Set the Keygen license key variable -export LICENSE_KEY='[YOUR_LICENSE_KEY]' - -# Download and install the DSPM installer binary for your Linux system architecture (x86_64 or ARM64) using your license key. -ARCH=$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/') -TMP_FILE=$(mktemp) -curl -sLf -o "$TMP_FILE" "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-installer-linux-$ARCH?auth=license:$LICENSE_KEY&channel=stable" -sudo install -m 0755 "$TMP_FILE" "/usr/local/bin/dspm-installer" -rm -f "$TMP_FILE" - -# Launches the installer -sudo dspm-installer -``` - -Run `dspm-installer [command] --help` to view usage and available options for any command. - -Netwrix recommends pinning to a specific release to control when upgrades happen during your organization's patching cycle. **To pin to a specific release**, export the version before downloading and running the installer: - -```bash -# Set the Keygen license key variable -export LICENSE_KEY='[YOUR_LICENSE_KEY]' - -# Pin to a specific release version -export TARGET_REVISION='[VERSION]' - -# Download and install the DSPM installer binary for your Linux system architecture (x86_64 or ARM64) using your license key. -ARCH=$(uname -m | sed 's/x86_64/amd64/;s/aarch64/arm64/') -TMP_FILE=$(mktemp) -curl -sLf -o "$TMP_FILE" "https://raw.pkg.keygen.sh/v1/accounts/netwrix/artifacts/dspm-installer-linux-$ARCH?auth=license:$LICENSE_KEY&channel=stable" -sudo install -m 0755 "$TMP_FILE" "/usr/local/bin/dspm-installer" -rm -f "$TMP_FILE" - -# Launches the installer -sudo dspm-installer -``` - -Run `dspm-installer [command] --help` to view usage and available options for any command. - - -Version strings control which release the installer installs and what auto-upgrades apply: - -| Value | Behavior | -| --- | --- | -| (unset) | Defaults to 1.* — auto-upgrades within the 1.x line; a future 2.x release doesn't install automatically | -| `1.0.8` | Pins to exactly 1.0.8 — no auto-upgrade | -| `1.*` | Auto-upgrades to any 1.x version | - -For most deployments, either omit this variable to stay on the latest release or pin to a specific version, such as `1.0.8`. - -## Environment Variables - -You can set most options as environment variables instead of command-line flags. Netwrix recommends this style for scripted or automated deployments — see the [Quick Install](quickinstall.md) for an end-to-end example. - -Export the variables before running the installer. When you set the same option as both an environment variable and a command-line flag, the flag takes precedence. - -| Environment variable | Equivalent flag | Example | -| --- | --- | --- | -| `LICENSE_KEY` | `--license-key` | `NWRX-XXXX-XXXX-XXXX` | -| `DSPM_HOSTNAME` | `--hostname` | `aa26.1.corp.example.com` | -| `TARGET_REVISION` | `--target-revision` | `1.0.8` (pinned) or omit for latest | -| `SIZE` | `--size` | `small`, `medium` (default), `large`, `enterprise` | -| `TLS_CERT_FILE` | `--tls-cert` | `/opt/dspm-tls/aa26.1.crt` | -| `TLS_KEY_FILE` | `--tls-key` | `/opt/dspm-tls/aa26.1.key` | -| `TLS_CA_BUNDLE_FILE` | `--ca-bundle` | `/opt/dspm-tls/ca-bundle.crt` | -| `IDP_TYPE` | `--idp-type` | `ad`, `ldap` | -| `IDP_ALIAS` | `--idp-alias` | `corporate-ad` (no spaces) | -| `LDAP_URL` | `--ldap-url` | `ldaps://dc01.example.com:636` | -| `LDAP_BIND_DN` | `--ldap-bind-dn` | `CN=svc-dspm,OU=ServiceAccounts,DC=example,DC=com` | -| `LDAP_USERS_DN` | `--ldap-users-dn` | `CN=Users,DC=example,DC=com` | -| `LDAP_EMAIL_ATTRIBUTE` | `--ldap-email-attribute` | `mail` (default) | -| `LDAP_BIND_PASSWORD` | (secret — see Quick Install) | (see Quick Install) | -| `POSTGRES_DATA_DIR` | `--postgres-data-dir` | `/mnt/ssd/postgres` | -| `CLICKHOUSE_DATA_DIR` | `--clickhouse-data-dir` | `/mnt/nvme/clickhouse` | -| `ACCEPT_WARNINGS` | `--accept-warnings` | `true` | -| `LOG_LEVEL` | `--log-level` | `info` (default), `debug`, `warn`, `error` | -| `HTTP_PROXY` / `HTTPS_PROXY` | (no flag) | `http://proxy.example.com:8080` | -| `NO_PROXY` | (no flag) | `localhost,127.0.0.1,.svc,.cluster.local` | -| `SKIP_AV_CHECK` | (no flag) | `true` | -| `DRY_RUN` | `--dry-run` | `true` | - -:::note -`LDAP_BIND_PASSWORD` is the only secret environment variable, and the installer ignores any exported value. The installer always reads the bind password from an interactive prompt or piped stdin. See [Quick Install — Step 4](quickinstall.md#step-4-run-the-installer) for the interactive prompt. -::: - -## Running the Installer - -When you run the curl command, the installer automatically: - -1. Runs preflight checks to verify your system meets requirements -2. Installs Kubernetes (k3s v1.33.4, the version Netwrix validated for this release) -3. Deploys ArgoCD as the GitOps controller -4. Pulls and deploys the Access Analyzer application stack from the Netwrix registry -5. Waits for all components to become healthy - -Installation typically takes 15–30 minutes depending on network speed and hardware. - ---- - ---- - -## Identity Provider Flags - -The following table lists every identity provider (IdP) flag the installer accepts. For end-to-end examples, see one of these walkthroughs: - -- [Quick Install](quickinstall.md) — Active Directory deployment using environment variables (recommended for most customers) -- [Configure Identity Provider](identity-provider.md) — example commands for Active Directory and LDAP, plus recovery with `--configure-idp-only` - -| Flag | Default | Description | -| --- | --- | --- | -| `--idp-type ` | — | Federation type: `ad`, `ldap` | -| `--idp-alias