Skip to main content

Getting Started

Once Access Analyzer is installed, use the following workflow to quickly begin auditing the organization’s IT infrastructure. See the Navigating the Console topic for additional information and data grid functionality.

Initial Configuration During First Launch

The initial Access Analyzer Configuration Wizard walks you through configuring several key global settings:

  • Storage

    • Mandatory configuration during the first launch
    • Requires credential on the SQL® Server database which is used to create and modify the Access Analyzer database
    • Option to either create a new database or point to an existing database
    • If using Windows Authentication, you must also configure the Schedule node
    • See the Storage topic for additional information
  • Schedule

    • Only appears if you configure the Storage Profile to use Windows Authentication
    • If you configure the Storage Profile to use SQL Authentication, you configure the setting later
    • See the Schedule topic for additional information
  • Instant Job

    • Install the pre-configured solutions the organization has a license for
    • See the Instant Job Wizard topic for additional information

Global Settings Configured

The global Settings have an overall impact on the running of Access Analyzer jobs. You manage them through the Settings node at the top of the Navigation pane. The following global Settings require configuration from the start:

  • Connection – Configure the Default Connection Profile and additional Connection Profiles as needed for intended data collection
  • Schedule – Configure the Default Scheduled Service Account for scheduling Access Analyzer job execution, if not configured via the initial configuration wizard
  • Notification – Configure an SMTP server for Access Analyzer to use for sending email notifications

The other global Settings provide additional options for impacting how Access Analyzer functions:

  • Access – Enable and configure Role Based Access for a least privileged application of Access Analyzer and report viewing or the enable the REST API

    note

    If you enable Role Based Access by accident, contact Netwrix Support for assistance in disabling it.

  • Application – Configure additional settings not included in the other nodes

  • Exchange – Configure Microsoft® Exchange Server connections

warning

Don't configure data retention at the global level without ensuring History is supported by ALL solutions to be run.

  • History – Configure data retention and log retention settings
  • Host Discovery – Configure Host Discovery task settings
  • Host Inventory – Configure Host Inventory settings
  • Reporting – Configure reporting options, if necessary
  • Sensitive Data – Flag false positive within discovered potential sensitive data files
  • ServiceNow – Configure the ServiceNow Action Module authentication credentials
  • Storage – Configure additional SQL Server database Storage Profiles

See the Global Settings topic for additional information.

Discover Hosts

Within the terminology of Access Analyzer, hosts are the machines being targeted during data collection. You can discover hosts or manually introduce them to Access Analyzer. Access Analyzer then inventories known hosts to populate dynamic host lists. Perform host discovery at the Host Discovery node. Manually introduce hosts at the Host Management node.

Host management consists of maintaining up-to-date host inventories and host lists that you can assign to job groups or jobs as targeted hosts. See the Host Management topic for additional information.

Job Workflow

After you configure the global Settings and introduce hosts to Access Analyzer, it's time to begin auditing. This requires an understanding of the relationship between solutions, job groups, jobs, queries, analysis, actions, and reports.

The Access Analyzer job is the fundamental unit. Jobs are responsible for all data collection queries, analysis tasks, notification tasks, action tasks, and report generation. When jobs are designed to work together, job groups house them to control the order of job execution. Solutions are pre-configured job groups which have been designed to target specific types of environments to audit for specific data sets, typically the most common types of information desired.

See the Jobs Tree topic for additional information.