Netwrix Active Directory Change Reporter Version 6 Freeware and Standard Editions Quick Start Guide
Total Page:16
File Type:pdf, Size:1020Kb
NetWrix Active Directory Change Reporter Version 6 Freeware and Standard Editions Quick Start Guide _______________________ NetWrix Active Directory Change Reporter User Guide Contents 1. INTRODUCTION ........................................................................................................................................................ 3 1.1 KEY FEATURES .................................................................................................................................................................... 3 1.2 LICENSING .......................................................................................................................................................................... 4 1.3 HOW IT WORKS .................................................................................................................................................................. 5 2. GETTING STARTED .................................................................................................................................................... 7 2.1 SYSTEM REQUIREMENTS ....................................................................................................................................................... 7 2.2 CONFIGURING ACTIVE DIRECTORY CHANGES AUDITING USING AUDIT CONFIGURATION WIZARD ........................................................ 9 2.3 INSTALLATION ................................................................................................................................................................... 10 3. WORKING WITH STANDARD OR FREEWARE EDITIONS ............................................................................................ 11 3.1 CONFIGURATION ............................................................................................................................................................... 11 3.2 DATA COLLECTION AND REPORTING ...................................................................................................................................... 14 3.3 MANUALLY CONFIGURE THE AUDITING SETTINGS .................................................................................................................... 15 3.3.1 Audit Object Security Settings ........................................................................................................................ 15 3.3.2 Audit "Who/When" Information for AD Object Modifications ....................................................................... 15 3.3.3 Audit Active Directory Access ......................................................................................................................... 15 3.3.4 Audit Changes to Configuration and Schema Containers ............................................................................... 16 4. FUTURE STEPS ........................................................................................................................................................ 19 5. ABOUT NETWRIX PRODUCTS .................................................................................................................................. 20 6. ADDITIONAL SOFTWARE LINKS ............................................................................................................................... 21 7. CONTACTING NETWRIX .......................................................................................................................................... 22 8. DISCLAIMER ........................................................................................................................................................... 22 _______________________________________ ___ NetWrix Active Directory Change Reporter Administrator’s Guide 1. Introduction Active Directory change auditing is an important procedure for limiting unauthorized changes and errors to Active Directory configuration. One single change can put your organization at risk, introducing security breaches and compliance issues. Built-in Active Directory auditing lacks many important features (for example, it does not provide you the before and after values for changed properties) and does not have reporting capabilities. Careful analysis of multi-megabyte Security logs can take enormous resources and still never paint the whole picture. NetWrix Active Directory Change Reporter is a tool that reports the changes made to Active Directory and delivers reports, containing summary and detailed information on a daily basis. These reports include the 4 W — Who, What, When, and Where for all changes, plus before and after values for each of the settings, and also changes made to Active Directory configuration, schema, and other Active Directory objects. You can use these reports to: • Monitor day-to-day administrative activities. • Prepare compliance reports for your SOX, GLBA and HIPAA auditors. NetWrix Active Directory Change Reporter records all modifications, including both user and administrative activity, and e-mails daily reports to Active Directory administrators detailing every Active Directory change. Collected audit data is archived and can be stored for years, so you can build a summary of changes made to Active Directory during any period and drill down to detailed information as necessary. This archiving function allows organizations to analyze any policy violations, adhere to security best practices and maintain established internal policies. (*) The Standard and Enterprise Editions are available. The Enterprise Edition includes advanced features, such as ‘Who’ and ‘When’ fields, long term change archiving, schema change detection, and comes with technical support and NetWrix Enterprise Management Console. 1.1 Key Features NetWrix Active Directory Change Reporter helps you to carry out the following auditing and reporting tasks: • Detect and report on changes made to Active Directory objects, Group Policies, Exchange Servers. Reports include information about what changes were made, who (*) made the changes and when (*) were they made. • Report on previous and current values for every change. • Generate on-demand Web-based reports. (*) • Create custom reports (can also be ordered from NetWrix). (*) • Store collected audit data and enable historical reporting for any period of time. (*) * - Only available in the Standard and Enterprise Editions of the product. 3 _______________________________________ ___ NetWrix Active Directory Change Reporter Administrator’s Guide 1.2 Licensing Active Directory Change Reporter comes in three Editions: Freeware, Standard and Enterprise. The table below outlines the differences between them. Feature Freeware Standard Enterprise Edition Who and When fields for every change No Yes Yes Advanced reports based on SQL Reporting Services, with filtering, No Detailed Detailed grouping and sorting Yes. Create manually or order Yes. Create manually or order from Custom reports No from NetWrix NetWrix Enterprise-class scalability No No Full Long-term archiving and reporting No Any period of time Any period of time Technical support Support forum Phone, e-mail, Support forum Phone, e-mail, Support forum Licensing Free of charge Per user Per user; please request a quote a single installation handles numerous managed No No Yes objects(domains, multiple domains) integrated interface for all NetWrix products which provides No No Yes centralized configuration and settings management integrated advanced reporting with lots of predefined out-of-the- No Yes Yes box reports for all the major platforms The Free Edition can be used by companies and individuals for an unlimited time, at no charge. The Standard and Enterprise Editions can be evaluated free of charge for 20 days. Please note that different parts of the Active Directory Change Reporter: Active Directory Change Reporter, Group Policy Change Reporter and Exchange Change Reporter have to be bought separately. 4 _______________________________________ ___ NetWrix Active Directory Change Reporter Administrator’s Guide 1.3 How It Works Figure 1: Product Architecture and data flow 5 _______________________________________ ___ NetWrix Active Directory Change Reporter Administrator’s Guide The NetWrix Active Directory Change Reporter data collection and reporting workflow is usually as follows: 1. A user launches the configuration utility and sets the parameters for the automated data collection and reporting, choosing whether to report on: • Active Directory changes - Users configuration changes - Changes to Active Directory groups - Active Directory Configuration and Schema changes - Domain structure changes - Changes to OUs - Additions to OUs - Additions to domains - Domains object properties changes • Group Policy changes - Group Policy Objects changes - Group Policy Objects creation - Group Policy Objects removal • Exchange Servers changes - Security policy violations - Exchange objects and permissions changes - Unauthorized and unplanned changes 2. A dedicated scheduled task which is launched periodically (every night, at 3 AM by default; it can also be launched manually when needed) collects Active Directory and/or Group Policy and/or Exchange snapshots and/or audit data, and e-mails the change reports to the specified recipients. The task name is NetWrix Management Console – Active Directory Change Reporter - <your domain name> where <your domain name> is the actual name of your managed domain. 3. If SSRS-based reporting is enabled and configured, the task will also store information about the Active