netwrix group policy change reporter - pnltools ltd · netwrix group policy change reporter quick...

27
NetWrix Group Policy Change Reporter Version 7 Enterprise Edition Quick Start Guide

Upload: vanthuy

Post on 01-Sep-2018

272 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter

Version 7

Enterprise Edition

Quick Start Guide

Page 2: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

Contents

1. INTRODUCTION ............................................................................................................................................................ 3

1.1 KEY FEATURES .................................................................................................................................................................... 4 1.2 LICENSING ......................................................................................................................................................................... 5 1.3 HOW IT WORKS ................................................................................................................................................................. 6

2. GETTING STARTED........................................................................................................................................................ 8

2.1 SYSTEM REQUIREMENTS ...................................................................................................................................................... 8 2.2 UPGRADING FROM PREVIOUS VERSIONS ............................................................................................................................... 10 2.3 INSTALLATION .................................................................................................................................................................. 10 2.4 AUDIT CONFIGURATION WIZARD ......................................................................................................................................... 11

3. WORKING WITH THE ENTERPRISE EDITION ................................................................................................................ 13

3.1 CREATING A MANAGED OBJECT ........................................................................................................................................... 14 Step 1: Specify Object Type ....................................................................................................................................... 14 Step 2: Supply Default Data Processing Account ...................................................................................................... 15 Step 3: Specify SMTP Settings ................................................................................................................................... 16 Step 4: Specify Domain Name ................................................................................................................................... 17 Step 5: Enable Features ............................................................................................................................................. 18 Step 6: Configure Database ...................................................................................................................................... 19 Step 7: Configure Group Policy Change Reports Recipients List ................................................................................ 20

3.2 MODIFYING GROUP POLICY CHANGE REPORTER SETTINGS ....................................................................................................... 21 3.3 DATA COLLECTION AND REPORTING ..................................................................................................................................... 22

3.3.1 Running a Data Collection Task ..................................................................................................................... 22 3.3.2 Viewing Task Session Results ......................................................................................................................... 23 3.3.3 Viewing Scheduled Reports ............................................................................................................................ 24

4. ABOUT NETWRIX PRODUCTS ..................................................................................................................................... 25

5. ADDITIONAL SOFTWARE LINKS .................................................................................................................................. 26

6. CONTACTING NETWRIX .............................................................................................................................................. 27

7. DISCLAIMER ............................................................................................................................................................... 27

Page 3: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

3

1. Introduction Group Policy auditing is a must have procedure for all organizations relying on Group Policy infrastructure. Relatively small changes to security policies, desktop configurations, software deployment and other settings can severely impact enterprise security, compliance, and performance. Built-in Group Policy management tools don't have any auditing and change reporting capabilities and you just can't track the Who, What, When and Where data for critical modifications. The uncontrolled and unaudited change process imposes major security and compliance risks for an IT infrastructure run by multiple IT professionals.

Powered by AuditAssurance™ technology, NetWrix Group Policy Change Reporter makes Group Policy change auditing task very easy and straightforward. This product sends daily reports detailing every single change made to Group Policy configuration. The reports list newly created and deleted GPOs, GPO link changes, changes made to audit policy, password policy, software deployment, user desktops, and all other settings. The data includes Who, What, When and Where information for all changes with previous and current values for all modified settings.

Features and Benefits:

Audit and report on all day-to-day Group Policy management tasks; Streamline creation of compliance reports for your SOX, GLBA and HIPAA auditors - Download report sample; Provide bird's eye view of all Group Policy management processes to IT managers; Easy targeted change report delivery via the Subscriptions feature; Automatically backup and recover Group Policy objects (download instructions); Integration with System Center Operations Manager via SCOM Management Pack for Group Policy Change

Reporter that feeds the audit data to SCOM for customized processing (rules, etc.).

The product records all Group Policy modifications and archives them to enable historical reporting. You can build summary of changes made to Group Policy during any period, to analyze any policy violations that took place in the past. For example, you can see who turned off invalid logon auditing in your domain security policy, who added new software to deploy on client computers, who changed desktop firewall and lockdown settings, and many other examples.

This product is a part of NetWrix Active Directory Change Reporter pack which consists of:

Active Directory Change Reporter;

Group Policy Change Reporter;

Exchange Change Reporter;

Active Directory Object Restore Wizard.

The whole pack provides a convenient change management solution for your network environment.

Page 4: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

4

1.1 Key Features

NetWrix Group Policy Change Reporter helps you to carry out the following auditing and reporting tasks:

Detect and report on changes made to Group Policy objects. Reports include information about what changes were made, who made the changes, where and when they were made.

Report on previous and current values for every change.

Generate on-demand Web-based reports.

Create custom reports (can also be ordered from NetWrix).

Store collected audit data and enable historical reporting for any period of time.

Create e-mail subscriptions for certain report types. The feature is based on Advanced Reporting functionality and enables automatic delivery of certain Advanced Report types to a customizable list of recipient e-mail addresses.

Integration with SCOM. The product stores collected changes in an event log. This option allows cooperating with SCOM.

Page 5: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

5

1.2 Licensing The Group policy Change Reporter comes in two Editions: Freeware and Enterprise. The table below outlines the differences between them.

Feature Freeware Enterprise Edition

Who, When and Where fields for every change No Yes

Advanced Reports based on SQL Reporting Services, with filtering, grouping and sorting

No Detailed

Custom reports No Yes. Create manually or order from NetWrix

Subscriptions (based on Advanced Reports) No Yes

SCOM integration No Yes

Enterprise-class scalability No Full

Long-term archiving and reporting No Any period of time

Technical support Support forum Phone, e-mail, Support forum

Licensing Free of charge Per user; please request a quote

A single installation handles numerous managed objects(domains, multiple domains)

No Yes

Integrated interface for all NetWrix products which provides centralized configuration and settings management

No Yes

Integrated advanced reporting with lots of predefined out-of-the-box reports for all the major platforms

No Yes

The Free Edition can be used by companies and individuals for an unlimited time, at no charge. The Enterprise Edition can be evaluated free of charge for 20 days.

Please note that different parts of the Active Directory Change Reporter: Active Directory Change Reporter, Group Policy Change Reporter and Exchange Change Reporter have to be bought separately.

Page 6: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

6

1.3 How It Works

Figure 1: Product Architecture and data flow

Page 7: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

7

The NetWrix Group Policy Change Reporter data collection and reporting workflow is usually as follows:

1. A user launches the configuration utility and sets the parameters for the automated data collection and reporting, choosing whether to report on the following Group Policy changes:

Group Policy Objects changes;

Group Policy Objects creation;

Group Policy Objects removal.

2. A dedicated scheduled task which is launched periodically (every 10 minutes by default; it can also be launched manually from the Enterprise Management Console when needed) collects Group Policy audit data, and emails reports to the specified recipients once per 24 hours at 3 AM by default. The task name is NetWrix Management Console – Active Directory Change Reporter - <your domain name> where <your domain name> is the actual name of your managed domain.

3. If the Advanced Reporting is enabled and configured, the task will also store information about the Group Policy changes to the specified SQL server database (you can use the Database Importer to import data on demand, for more details please refer to NetWrix Group Policy Change Reporter Administrator’s Guide). The Enterprise Management Console or a web browser can be used to view the compliance reports.

4. If the integration with System Center (SCOM) is enabled, the product will record all changes to the event log in a simple format. Active Directory SCOM Management Pack provides easily managed procedure of the product integration with SCOM. The integration allows you to review alerts, SRS reports via SCOM

5. Change reports and subscriptions are sent by email; to generate and view the on-demand reports the Enterprise Management Console can be used.

Page 8: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

8

2. Getting Started This section describes the necessary prerequisites for the Group Policy Change Reporter installation.

2.1 System Requirements

Hardware  

Processor:

Minimum: Intel or AMD 32 bit, 2GHz;

Recommended: Intel or AMD 64 bit, 3GHz. Memory:

Minimum: 512MB RAM;

Recommended: 2GB RAM. Disk:

Minimum: 50MB physical disk space for product installation. More space is required for the Audit Archive and SQL, depending on the number GP objects and changes per day;

Recommended: two physical drives with 50GB of free space total.

Software  

The product can be installed on any computer running Windows XP SP2 or higher. The computer must belong to a managed or trusted domain.

NOTE: in order for the Group Policy Change Reporter to monitor GP Preferences, it has to be installed on Windows Vista or above.

Supported Group Policy environments (both 32 and 64-bit): Windows 2000; Windows Server 2003, any forest mode (mixed, native, 2K3); Windows Server 2008 (including R2).

Additional software: .Net Framework 2.0 or later; Windows Installer 3.1 or later; Microsoft Management Console 3.0 or higher; Group Policy Management Console (GPMC) installed as a Windows Server 2008 feature, a separate GPMC

download for Windows XP/2003, or as a part of Remote Server Administrative Tools for Windows Vista/7; To use the Advanced Reporting, SQL Server 2005 Express Edition or above with Advanced Services (can be

installed automatically or obtained from Microsoft Download Center);

Additional requirements: Disk space – enough for temporary data storage (the configuration snapshots will be saved there). Required

space depends on the number of users in your Active Directory. At least 10GB is recommended. SSRS Report Builder is required to create custom reports. To launch the Report Builder, .NET Framework 2.0

must be installed on the client computer (used to connect to SSRS). Note that Report Builder is available in SQL Server Enterprise or Standard Edition; the Express Edition does not provide this functionality.

Page 9: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

9

Required rights and permissions: The account under which the Group Policy Change Reporter scheduled task will run requires the following:

1. Local administrator rights; 2. To collect and report on objects' security changes, this account must have Manage auditing and

security log user right enabled (if the task is run under Domain Administrator account, this right will be enabled by default). Adjust the Domain Controller Security Policy accordingly.

3. Content Manager role for the Home folder on SSRS. The account you will use to view the reports in the Advanced Reports Manager should have the Browser

role for the Home folder on SSRS and the db_datareader role assigned to the account to extract data from the NetWrix database.

If you plan to collect data using agents, consider that agent service will run on Domain Controllers under Local System account. Also the account under which you run the Group Policy Change Reporter must be a Domain Administrators group member.

Page 10: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

10

2.2 Upgrading from Previous Versions

If you are upgrading from one of the previous version of the product, to the version 7, consider the following:

Upgrading from the Freeware Edition of older versions to the Enterprise Edition of version 7 is not supported; you must uninstall the old version first.

Upgrading from the Standard or Enterprise Edition of older versions to the Enterprise Edition of version 7 is supported.

2.3 Installation

To install the Group Policy Change Reporter, run the setup program on any computer in the domain in the target forest.

Follow the steps of the wizard. When prompted, accept the license agreement, then specify the installation folder, and click Next to proceed with the installation.

On the last step of the installation wizard, the following dialog appears:

Figure 2: Active Directory Change Reporter / Group Policy Change Reporter Setup configuration utility selection dialog window

Verify that the Start NetWrix Active Directory Change Reporter Enterprise Edition is checked to start NetWrix Enterprise Management Console right after you exit the setup or uncheck it to skip this for now. Click Finish to complete the setup.

Page 11: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

11

2.4 Audit Configuration Wizard

The Audit Configuration Wizard is a tool that allows you to automatically configure all the necessary audit settings on your managed units.

To launch the tool please go to Start | All Programs | NetWrix | Group Policy Change Reporter | Audit Configuration Wizard. Note that you need to run the wizard under the domain admin account in order for it to work properly.

On the first step of the wizard enter the domain name that you want to configure the audit settings for.

Figure 3: Audit Configuration Wizard – Domain choice step

After clicking Next the following window appears, proposing to choose the effective policy that is currently applied to the domain controllers and is a subject for a change.

Figure 4: Audit Configuration Wizard – Effective Domain Controller Policy selection window

Page 12: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

12

After the effective policy is selected the wizard proceeds to the Audit Policy Settings step. Select an account that was specified for data collection (the account will be checked for the correct audit privileges) and click Detect… to determine if it needs tweaking.

Figure 5: Audit Configuration Wizard – Account Policy Settings step

If the wizard detects some unfavorable audit rights values, click Adjust… to automatically modify them. The wizard is pretty self-explanatory and similar operations are performed on every step.

Page 13: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

13

3. Working with the Enterprise Edition NetWrix Enterprise Management Console (implemented as an MMC snap-in) provides flexible configuration and management capabilities.

To start NetWrix Enterprise Management Console please go to NetWrix | NetWrix Group Policy Change Reporter | Group Policy Change Reporter (Enterprise Edition) from the Start menu.

Figure 6: NetWrix Enterprise Management Console

Page 14: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

14

3.1 Creating a Managed Object If you wish to create a new Managed Object, follow the steps below.

Step 1: Specify Object Type

1. In the Enterprise Management Console main window, navigate to the Managed Objects tree node, right-click it and select New Managed Object.

Figure 7: New Managed Object Wizard – Select Managed Object Type dialog window

Alternatively, you can click Create New Managed Object in the Task pad on the right.

2. The New Managed Object wizard starts. On the Select Managed Object Type step, select Domain to create a new domain object to be configured for data gathering and reporting.

Page 15: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

15

Step 2: Supply Default Data Processing Account

Next, you should select a user account that will be used by the Group Policy Change Reporter as the default one for scheduled data processing and report generation.

Figure 8: New Managed Object Wizard – Data Processing Account setup dialog window

Click Specify Account; when selecting an account, consider that it should be granted the necessary access rights (see 2.4 Audit Configuration Wizard).

NOTE: you will be presented with this step only in case if the Data Processing Account settings were not yet supplied via Settings | Schedule submenu of the Enterprise Management Console.

Page 16: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

16

Step 3: Specify SMTP Settings

Next, specify the settings of a SMTP server that will be used to send the change reports via email. Supply SMTP server name, port, and the sender address. If your SMTP server requires authentication, check Use SMTP authentication and enter the user name and the password. If your SMTP server requires SSL to be enabled, check Use Secure Sockets Layer encrypted connection (SSL). If implicit SSL mode is used, check Use Implicit SSL connection mode.

Figure 9: New Managed Object Wizard – Configure SMTP Server Settings dialog window

NOTE: you will be presented with this step only in case if the SMTP settings were not yet supplied via Settings | E-mail Settings submenu of the Enterprise Management Console.

Page 17: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

17

Step 4: Specify Domain Name

Then you have to enter the name of the domain you are creating:

Figure 10: New Managed Object Wizard – Domain name setup dialog window

Enter the domain name using the Fully Qualified Domain Name (FQDN), e.g. “MyDomain.local”. Also, if you want to use a specific account to process objects from this collection, enter its user name and password at this step. Alternatively, you can leave the Default account here (the one you supplied on Step 2 will be used).

IMPORTANT: make sure the processing account is granted the necessary rights and permissions (see 2.4 Audit Configuration Wizard).

Page 18: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

18

Step 5: Enable Features

Then you should specify what management features will be applied to the collection, that is, what NetWrix products will be involved in processing data from these computers. Select the Group Policy Change Reporter item from the list of installed features:

Figure 11: New Managed Object Wizard – Enable Features dialog window

Page 19: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

19

Step 6: Configure Database

The next step allows configuring the Advanced Reporting SQL settings, enabling the product’s reporting capability.

Figure 12: New Managed Object Wizard – Advanced Reporting SQL Settings dialog window

If you have an SQL Server with SQL Reporting Services already installed, then choose Use an existing SQL Server with SQL Reporting Services and specify the following parameters:

SQL Server – the name of the server and the instance you want to use for the Advanced Reporting.

Windows Authentication – turn the option on if the SQL Server is configured for using Windows Authentication so that the default account, configured during Step 2 is used. Otherwise, leave the box unchecked and fill in the User and Password fields.

Report Server URL, Report Manager URL – Supply the Reports Server and Report Manager URLs, click Verify. The URLs must be in the following format: http://<server_name>/<foldername>, where <server_name> is the name of your SQL server. You can find the correct folder names in the SQL Reporting Services Configuration Manager. To do this, first launch the SQL Reporting Services Configuration Manager (for MS SQL Express 2005 it will be Start | All Programs | Microsoft SQL Server 2005 | Configuration Tools | Reporting Services Configuration) where you can find the folder names under Report Server Virtual Directory and Report Manager Virtual Directory menu categories. The default values for these folder names are “ReportServer$SQLExpress” and “Reports$SQLExpress” respectively.

If you haven’t installed an SQL Server yet, select Automatically install and configure a new instance of SQL Server Express Edition. The Advanced Reporting Configuration Wizard will run in order to install and automatically configure the Express edition. For the detailed instruction on how the wizard works please refer to NetWrix Group Policy Change Reporter Administrator’s Guide.

Page 20: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

20

Step 7: Configure Group Policy Change Reports Recipients List

The next setting to be configured is the Group Policy change reports delivery e-mail addresses:

Figure 13: New Managed Object Wizard – Configure Group Policy Change Reporter settings dialog window

Enter the email addresses of reports recipients. If the audit settings have not been properly configured you may receive the warning as shown below.

Figure 14: New Managed Object Wizard – audit settings warning

The settings can be configured after the wizard finishes. Please refer to 2.4 Audit Configuration Wizard to review the information regarding the audit settings configuration.

Click Next.

Review the settings you have configured for the new managed object, and Finish the Wizard. The new managed object (a domain) is displayed in the Enterprise Management Console tree under the Managed Objects node.

Page 21: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

21

3.2 Modifying Group Policy Change Reporter Settings This section describes how to change the configuration settings of an existing managed object (domain).

To view or edit the Group Policy Change Reporter settings for a certain domain, select the required Managed Object (domain) from the tree on the left, and expand the subjugated Group Policy Change Reporter tree node.

Figure 15: NetWrix Enterprise Management Console – Group Policy Change Reporter settings

Then you can enable or disable the Group Policy change reporting for this object and configure the delivery e-mail addresses list.

In order to know how to change additional settings such as the data collection time, network traffic compression and amount of collections per period, right click on the managed object, select Add/Remove Features and add the Active Directory Change Reporter feature (please refer to NetWrix Active Directory Change Reporter Administrator Guide for the detailed instructions on how to configure Active Directory Change Reporter). You can find the settings listed above on the Active Directory Change Reporter node.

It is also possible to launch the Audit Configuration Wizard to automatically set up the auditing (see 2.4 Audit Configuration Wizard).

Page 22: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

22

3.3 Data Collection and Reporting

This section tells you how to perform data collection and reporting using the Enterprise Management Console.

3.3.1 Running a Data Collection Task

To run data collection, select a managed object (from which you want to collect and report the changes) from the tree in the Enterprise Management Console, and then click Run in the right pane, on the General tab:

Figure 16: NetWrix Enterprise Management Console – Running Data Collection Task window

The Status and Description table columns reflect the current condition of each of the features listed in the Features column.

After clicking Run, the task status changes to “Running” for the whole period of time that it takes the task to run. Any errors, if encountered, are printed in the Description field of the feature.

During the task run the audit data is collected, the change reports are emailed to the selected recipients. Task session information can be examined using the Enterprise Management Console, as described below.

Page 23: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

23

3.3.2 Viewing Task Session Results

All task operation information is shown in the Enterprise Management Console. Expand the Group Policy Change Reporter node, and select Sessions. Then select the data collection session you need to examine, and review the information shown in the right pane:

Figure 17: NetWrix Enterprise Management Console – Task Session Results window

For each selected session, you can review the following information:

Domain – the name of the managed object (domain) processed during the session;

Status – session status that can be one of the following: Success, Warning, Error, or Fatal Error (meaning that data collection failed to start due to incorrect account, remote computer powered off, or other reason specified in the Error Text field below);

Type – the reporter that processed data during the selected session;

Error Text – information on occurred errors if any.

To generate a report on data collected during the selected session, use the controls in the lower pane on the right: click Run to launch the report generation process and automatically show the result.

To see the report generated earlier (i.e., history), click View report (if the report has no history, it will be first generated and then displayed).

Page 24: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

24

3.3.3 Viewing Scheduled Reports

At the first completion of the full data gathering, run automatically right after the managed object creation and at 3.00 AM every day by default, or manually from the Enterprise Management Console, the message notifies you of the initial analysis being completed. Next, you can make some changes to your Group Policy to see the way they get reported. After that, you can launch the full data gathering again by going to the managed domain node and clicking Run. Then wait for the process to finish and check the mailbox for a new report. The changes should be reported like shown in the figure below; if so, consider the product installation and configuration is completed.

Figure 18: Scheduled Reports email example

If the Advanced Reporting was configured (as described in New Managed Object Wizard Step 6), you can click the More reports link from this email report to view HTML reports in your web browser.

Page 25: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

25

4. About NetWrix Products

Solutions developed by NetWrix Corporation help organizations to meet compliance standards, simplify identity management, and reduce IT infrastructure costs. The product line includes solutions for change management, identity management, virtualization, and Group Policy troubleshooting.

Enterprise Management Suite: NetWrix Enterprise Management Suite is a rich collection of all NetWrix products combined together into one integrated solution. The suite is well-maintained and regularly updated with new versions and completely new products that all customers are entitled to as long as their maintenance is up to date.

Change Reporter Suite: The Change Reporter Suite is an integrated solution for automated tracking and reporting of all critical changes in the entire IT infrastructure, including Group Policy, file servers, Microsoft Exchange, filer appliances such as NetApp or EMC, virtual and physical infrastructure, SQL Server databases. Everything is centrally audited, consolidated, and presented in easy to understand reports with before and after values of all “who, what, when and where” modifications.

Identity Management Suite: The NetWrix Identity Management Suite brings convenience, enhanced security, and brings sensible benefits to everyone within an organization. The solution resolves account lockouts, forgotten passwords and password expiration problems, while also providing user account de-provisioning and privileged password management.

USB Blocker: USB Blocker enforces centralized access control to prevent unauthorized use of removable media that connects to computer USB ports—memory sticks, removable hard disks, iPods, and more.

File Server Change Reporter: File server and filer appliance auditing solution. Supports Windows servers, NetApp Filers, EMC appliances.

SQL Server Change Reporter: Auditing and reporting solution to monitor changes to SQL servers, instances, database schema, logins and roles, etc.

Privileged Account Manager: Shared access to privileged accounts with automatic password maintenance.

Non-owner Mailbox Access Reporter: Track users who access other user’s mailboxes and report unauthorized access to mailboxes of C and VP-level accounts.

Password Manager: product gives end users the ability to securely manage their passwords and resolve account lockout incidents in a self-service fashion without involvement of help desk personnel.

Account Lockout Examiner: detects, diagnoses, and resolves account lockouts in real time to reduce administrative costs associated with manual resolution of account lockouts.

Full list of products: http://www.netwrix.com/products.html For more information, please visit www.netwrix.com or call our toll-free number: +1-888-638-9749.

Page 26: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

26

5. Additional Software Links .Net Framework 2.0 is available at http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=0856eacb-4362-4b0d-8edd-aab15c5e04f5 or for 64-bit systems at http://www.microsoft.com/downloads/details.aspx?FamilyID=B44A0000-ACF8-4FA1-AFFB-40E78D788B00&displaylang=en

Windows Installer 3.1 is available at http://www.microsoft.com/downloads/details.aspx?familyid=889482FC-5F56-4A38-B838-DE776FD4138C&displaylang=en

Microsoft Management Console 3.0 for Windows XP (KB907265) at http://www.microsoft.com/downloads/details.aspx?FamilyID=61fc1c66-06f2-463c-82a2-cf20902ffae0&displaylang=en

Group Policy Management Console at http://www.microsoft.com/downloads/en/details.aspx?FamilyId=0A6D4C24-8CBD-4B35-9272-DD3CBFC81887&displaylang=en

ADSI Edit utility is available at http://www.microsoft.com/downloads/details.aspx?FamilyId=6EC50B78-8BE1-4E81-

B3BE-4E7AC4F0912D&displaylang=en

Page 27: NetWrix Group Policy Change Reporter - PNLTools Ltd · NetWrix Group Policy Change Reporter Quick Start Guide 3 1. Introduction Group Policy auditing is a must have procedure for

NetWrix Group Policy Change Reporter Quick Start Guide

27

6. Contacting NetWrix If you encounter any issues during your testing or use of the product, please first check the knowledge base:

http://netwrix.com/knowledge_base.html

If you can’t find a solution for your issue in the Knowledge Base, then contact NetWrix technical support:

www.netwrix.com/support

201-490-8840 x1 for technical support

7. Disclaimer The information in this publication is furnished for information use only, does not constitute a commitment from NetWrix Corporation of any features or functions discussed and is subject to change without notice. NetWrix Corporation assumes no responsibility or liability for any errors or inaccuracies that may appear in this publication.

NetWrix is a registered trademark of NetWrix Corporation. The NetWrix logo and all other NetWrix product or service names and slogans are registered trademarks or trademarks of NetWrix Corporation. Group Policy is a trademark of Microsoft Corporation. All other trademarks and registered trademarks are property of their respective owners.

© 2011 NetWrix Corporation. All rights reserved. www.netwrix.com