# SailPoint Data Access Security > SailPoint Data Access Security Help # SailPoint Data Access Security # Data Access Security SailPoint Data Access Security empowers organizations to discover, govern, and secure sensitive data and protect it from critical security risks. Designed as an integrated SaaS solution with SailPoint Human Fabric, it delivers enhanced intelligence on critical data to help organizations improve data security posture, reduce risk, and streamline compliance efforts from day one. Accelerating the work of security teams, it proactively uncovers and remediates hidden data risks with automated data discovery and classification, built-in workflows, and out-of-the-box governance policies. # DAS Product Documentation Data Access Security (DAS) governs identities' access to an organizations data – powering productivity and security while incorporating data access insights into the core governance processes of SailPoint Human Fabric (ISC). # Access Certification Overview Access Certification allows users to certify permissions and identities. First, determine what permissions or identities need to be certified. Next, determine the review process. Lastly, create the certification campaign. ## Access Certification Flow Run a certification campaign by completing the following steps: - [Campaign creation](https://documentation.sailpoint.com/das/help/access_cert/campaign_creation.html) - Campaign has all the necessary details and is ready to be run. - Campaign in progress - Campaign is actively running. # Creating an Access Certification Campaign To create a new campaign to certify access, go to **Compliance > Access Certification** and select **Create New**. When creating a new campaign, you need to provide details about the desired campaign. ## General Details On the first step of the campaign creation, provide the following information: - Campaign Name - Name of the campaign. - Campaign Description - Details about the campaign. - Campaign Type - Choose either Identities or Permissions. - Instructions for Reviewers - Provide any explicit instructions for the reviewers. - Due Date - Choose an exact date or a time frame for the campaign. Select **Next**. ## Filter Selection On the filter selection step, define a scope for the campaign. This can be done by selecting an already saved or shared filter from the dropdown. Or, select the Forensics link to be taken to the Forensics page to create a new filter. Note If creating a new Permissions or Identities filter from the Forensics page, select **Refresh** on the Filters page of the campaign creation and the newly created filter will display as an option in the Filter List dropdown. Once a filter is selected from the dropdown, the filter and its parameters display. Select **Next**. ## Review Process On the review process step, set the appropriate reviewers for the certification campaign. Certification campaigns have the ability to have multiple review levels. You can choose up to three review levels for a campaign. Each record in the campaign must be in a committed status before the campaign will move to the next level. In the Reviewer Type dropdown, select either **Data Owner**, **By Selected Reviewer(s)**, or **By Manager/Entitlement Owner**. The review type options will depend on what type of campaign this is. Note The By Data Owner review type is only available with permission type campaigns. If By Data Owner is selected, the user also needs to select a default reviewer. The default reviewer will review the records in case the review cannot be assigned to the owner. If **By Manager/Entitlement Owner** is selected and the review record contains an identity, the review process is assigned to the identity's manager. If the manager is not available, the system checks to see if there is an entitlement owner. If there is no entitlement owner, the review is assigned to the selected default reviewer. If a campaign requires more review levels, select **+ Add Level**. Note Data Owners and Managers can only be set once for a review level. Other reviewers can be set for all three levels. Select **Next**. ## Permission Revocation The permission revocation features allows users to remove [directly granted permissions](https://documentation.sailpoint.com/das/help/resources/permissions.html#what-permission-can-be-revoked) to resources on the created campaign. The Automatic Revocation toggle is enabled by default. To not run a task that revokes qualified permissions, toggle this option off. If enabled, select an option on what type of campaign to run the revocation task on. ## Summary On the summary page, review all the certification settings you have chosen. You also have the ability to select what columns (information) should be visible when viewing the campaign details. Here you can use the Invitation toggle to activate sending invitations which is on by default. Note Customizing campaign [email templates](https://documentation.sailpoint.com/saas/help/common/emails/available_templates.html) is available. You can also send out a reminder about the campaign. The reminder option is on by default but can be turned off. They are sent out weekly on Mondays at 5:00 UTC. Select either **Save** or **Save and Run**. If Save is chosen, the campaign will not be started. The campaign will be available in the Campaign Management screen and at desired time, **Run Now** can be selected in the Actions column which will kick-off the campaign. If **Save and Run** is selected, the campaign is created and initialized. This makes the campaign display as In Progress. # Campaign Management To view an existing campaign or create a new one, go to **Compliance > Access Certification > Campaign Management**. Note This page is only available to a user with the Data Access Security Administrator user level or the Data Access Security Compliance Manager user level which is set within SailPoint Human Fabric. This page allows you to create, edit, manage, and delete various certification campaigns. All of the created campaigns are listed along with their descriptions, the type of campaign it is, the owner of the campaign, its due date, its review level, and the current status of the campaign. The campaign statuses are: - Completed - The campaign is complete. - Created - A campaign has been created. - Creation Failed - The creation of this campaign failed. The campaign size limitation is 100k records. Please contact your administrator for more information. - Deletion Failed - The campaign could not be deleted. Please contact your administrator for more information. - Review In Progress - This campaign is in progress. - Pending Creation - This campaign is in the process of being created. - Pending Completion - This campaign is in the process of being completed. - Pending Deletion - This campaign is in the process of being deleted. - Pending Reinitialization - This campaign is in the process of being reinitialized. - Pending Review in Progress - This campaign is being reviewed. - Revocation in Progress - The campaign is configured with automatic revocation enabled. All reviews have been completed and directly granted permissions are now in the process of being revoked for rejected records. - Revocation Failed - The revocation task failed. You can see the result of each failed record in the **Campaign Details > Automatic Revocation > Revocation Results** column. This status will occur if one or more records failed to be revoked. All records must be successfully revoked or ignored to move into the completed status. ## Filtering Campaigns There are two ways to search for a particular campaign. You can use the predefined filter options (View All, My Campaigns, Active, or Overdue) or you can use the filter icon to search for a campaign based on the campaign details. - View All - All campaigns display with no filters. - My Campaigns - Campaigns that you have created. - Active - Campaigns that are in the process of running. - Overdue - Campaigns that are past their due date. If you select the filter icon to search using the campaign details, a filter overlay appears with the following filters: - Campaign Name - If some or all of the campaign name is known, you can enter it in the field to search for a campaign. - Campaign Type - Choose between identities and permissions. - Owner - Search by the creator of the campaign. - Status - Search by the campaign status. - Due Date - Enter dates to search by the due date of the campaign. ## Campaign Management Actions Each campaign listed has a set of actions the user can perform. - Run Now - Only available for campaigns with the Created status. - Edit - Edits the details of the campaign. - Delete - Deletes the campaign. - Refresh - Refreshes the users view of the campaign status. - Save as Template - The content of the campaign will be saved as a template. - Generate Report - Select this option, then go to **Reports > My Reports** to view the newly [created report](https://documentation.sailpoint.com/das/help/reports/report_main_page.html). - Reinitialize - This action creates a task to reinitialize the campaign. Reinitializing a campaign means all decisions are cleared. Tip If you select multiple campaigns using the checkboxes, you can bulk delete them. ## Viewing Campaign Details To view more details on a particular campaign, select the campaign you want to view. At this point, the campaigns details for that campaign displays. Below the name of the campaign, various details are presented. Here you can quickly view the campaign owner, when it started, its due date, the type of campaign it is, and its current and overall status. To end the entirety of the campaign, select **End Campaign**. To view more information other than what is provided, select **Campaign Summary**. You can see the progress of the records completed in the campaign by the Overall Campaign Status percentage bar. On the Campaign Details page, there are two tabs a user can select to view depending on the information they are wanting to see. ### Pending Records per Reviewers This tab only lists reviewers on the campaign that still have reviews pending. You can see the reviewers listed and the number of records that are still pending review. If a campaign is still in progress, you have the opportunity to reassign the reviewer to someone else. Note If records are rejected, they will not be forwarded to the next review level and the numbers displayed will be adjusted. Important This view only displays for reviewers on the current review level of the campaign. Reviewers for level 3 will not be displayed if the current review level is on level 1. Within this tab, you can filter among the listed reviewers. Provide the name of the reviewer you are searching for within Filters and select **Apply**. Select **Save** to apply the filter. ### All Records This tab provides more details about the individual records within the campaign. All of the columns are customizable depending on the information that you want to view. The default columns that display are predetermined when the user [creates the campaign](https://documentation.sailpoint.com/das/help/access_cert/campaign_creation.html). In the Action column, you can look into the review process of the campaign by selecting **Show Review Process**. Here, you can see the response of each review level along with the review details. You can also choose to perform one of the following actions on a record from the Action column: - Reassign Record – This action is only available if the status of a record is Pending. Reassign Record allows you to select another reviewer on that record. If multiple reviewers were selected for the campaign, the user is asked which current reviewer they want to reassign the record to. Reassigning a record will delete any past comment made on the record. - Show Review Process – This action allows you to view who made review decisions. You will be able to view all levels and statuses of each level of the record. Rejected records do not transition to the next level. **Revert Review Process** can also be selected by checking the checkboxes to the left of the records. This allows you to reset the whole review without resetting the whole campaign. This action is also available as a bulk option. Reverting a record will delete any past comment made on the record. Only records with the Approved or Rejected status can be reverted. This tab comes with two predefined filters. You can select Pending Review to view all records that are still waiting on a decision or select View All to see all records, no matter their status. For more in depth filtering options, select **Filters**. From the dropdown field, select what you want to filter by. Select **Save** and then **Apply** to apply the filter. ### Automatic Revocation This tab provides a view into the progress of revocation tasks and is only available if revocation was enabled for your campaign and you have records which [qualify for revocation](https://documentation.sailpoint.com/das/help/resources/permissions.html#revocation-special-use-cases). You can view details regarding the user, the rejected permission and its resource path, and the result of the revocation. If the revocation task failed on a particular resource, you have two options to rerun the revocation task. - After correcting the issue, select **Rerun Revocation Task** and the failures should be removed after the task is complete. - Ignore the failures by selecting **Ignore Failures** which will move the campaign status to Completed. If this option is chosen, a warning appears verifying you want to ignore the failures. Ignoring the failures cannot be undone. # Access Certification Campaign Templates Access Certifications campaign templates allow Compliance Managers and Administrators to more easily organize and schedule reoccurring campaigns to help meet organizational goals as well as any compliance needs. When a campaign template is scheduled, it will initialize a campaign at the scheduled times which can be located in the Campaign Management screen. This allows for the automation of campaign creation and initialization based on the reoccurring schedule. The following are common uses for campaign templates: - Regularly occurring access certifications of data assets - Semi-annual or annual audit requirements - Initialize an ad hoc campaign from a pre-configured template Ad hoc campaigns can also be created directly within the [Campaign Management](https://documentation.sailpoint.com/das/help/access_cert/campaign_creation.html) screen using the **Create New** button. ## Managing Campaign Templates Campaign templates can be viewed, edited, duplicated, deleted, or scheduled by going to **Compliance > Campaign Templates**. All campaign templates are listed along with details about each one. These details include who owns the campaign, the type of campaign it is, and information about its schedule if one has been established. There are multiple ways to search for a particular template. You can use the predefined filter option (All, Permissions, Identities) which filters between the campaign type, search for templates by using the search bar, or use the filter icon to search for a template based on the owner or the schedule frequency. You can also sort templates alphabetically or by the next run time. Note When using the search bar to locate a template, **Enter** has to be selected to perform the search. Depending on your user level (Administrator or Compliance Manager), each template has the following options: - **Edit** – Opens an editing page where edits to the template can be made. - **Duplicate** – Duplicates the template and allows parameters to be edited with information prepopulated from the duplicate template. - **Delete** – Deletes the template. The deleted template is no longer displayed. Any campaigns generated from campaign templates will not be deleted or negatively impacted when deleting the campaign template. - **Use this Template** – A new tab opens in the Create Campaign screen with predefined data from the template. Here you can review, save, and/or run a new campaign. - **Schedule** – Schedules a template to run as often or as little as needed. A campaign will be created and initiated automatically at scheduled times. You can find the scheduled campaign in the [Campaign Management](https://documentation.sailpoint.com/das/help/access_cert/campaign_creation.html) screen. The new campaign will be named the same as the template with a timestamp added to the title of when the campaign was intialized. This can be edited after creation. ## Creating an Access Certification Template To create a new access certification template, go to **Compliance > Access Certification > Campaign Templates** and select **Create Template**. When creating a new template, you need to provide details about the desired template. ### General Details 1. On the first step of the campaign creation, provide the following information: - **Template Name** - Required. Name of the template. - **Template Description** - Details about the template. - **Campaign Type** - Choose either Permissions or Identities. Note The type of campaign that is chosen will determine what filters are displayed in the filter dropdown list. Only filters meeting the selected campaign type will be displayed. - **Instructions for Reviewers** - Review the pre-populated text and adjust as needed. - **Duration** - Required. Choose how long the campaign should run for when initiated from the template. 1. Select **Next**. ### Filter Selection The filter selection is the main component of a campaign. It defines what populates in the campaign to be certified. 1. On the filter selection step, define a scope for the campaign. This can be done by selecting an already saved or shared filter from the dropdown. Or, select the Forensics link to be taken to the Forensics page to create a new filter. Note If creating a new Permissions or Identities filter from the Forensics page, select **Refresh** on the Filters page and the newly created filter will display as an option. If choosing an already created filter from the dropdown, the filter and its parameters display. Tip If a resource or application is ever deleted using the selected filter, a new filter will need to be created since the selected one will be invalid. 1. Select **Next**. ### Review Process On the review process step, set the appropriate reviewers for the certification template. Certification campaigns have the ability to have multiple review levels. You can choose up to three review levels for a campaign. Each record in the campaign must be in a committed status before the campaign will move to the next level. In the Reviewer Process dropdown, select either [Data Owner](https://documentation.sailpoint.com/das/help/resources/owners.html), **By Selected Reviewer(s)**, or **By Manager/Entitlement Owner**. The review type options will depend on what type of campaign this is. Note The By Data Owner review type is only available with permission type campaigns. If By Data Owner is selected, the user also needs to select a default reviewer. The default reviewer will review the records in case the review cannot be assigned to the owner. If **By Manager/Entitlement Owner** is selected and the review record contains an identity, the review process is assigned to the identity's manager. If the manager is not available, the system checks to see if there is an entitlement owner. If there is no entitlement owner, the review is assigned to the selected default reviewer. A campaign is created for each manager or data owner associated with all items from the campaign. Select **Next**. ### Schedule Running a certification template on a schedule is enabled by default and initiates a campaign at the scheduled intervals. To disable, toggle **Enable Schedule**. 1. Select a scheduling frequency from the dropdown list. 1. Select the interval frequency of the schedule. For example, if you previously selected "monthly" and then select an interval of "2" the schedule will run every other month. 1. Using the hour and minute options, select the time of day the corresponding campaign is initialized. Specify AM or PM by selecting the button. 1. Specify a start date using the calendar icon. The schedule frequency starts after the selected start date. 1. If the schedule should have an end date, toggle the **Never** to display the end date calendar option. 1. Select **Next**. ### Summary On the Summary page the Invitation toggle is on by default. This will activate sending invitations when the campaigns created from the template are initialized. Invitations cannot be edited. You can also send out a reminder about the campaign. The reminder option is on by default but can be turned off. Reminders cannot be edited. They are sent out weekly on Mondays at 5:00 UTC for the duration of the campaign once initialized. Lastly, review all the certification settings you have chosen. ## Creating a Template from the Campaign Management Screen If a campaign exists that you want to use as a template, go to **Compliance > Access Certification > Campaign Management**. Locate the desired campaign within the Actions column and select **Save as Template**. After selecting Save as Template, the template wizard displays with campaign details prepopulated starting at the [General Details](#general-details) page. All steps outlined above are the same for this process. # Access Certification Tasks If you have been assigned to review a campaign and that campaign has been initiated, the Access Certification page within My Tasks allows you to view the details of that campaign and make decisions on it. Go to **My Tasks > Access Certification**. Only active campaigns are shown. To filter campaigns based on their status, select one of the following: - View All - This filter shows all campaigns that are still in progress. - Overdue Reviews - To view all campaigns that are past their set due dates, select this filter. To further filter between campaigns, select the Filter icon and choose from the following options: - Campaign Name - If the campaign name or some of the name is known, enter it in this field to locate the campaign. - Campaign Type - Choose between identities or permissions. - Due Date - The due date filter comes with a few options. From the dropdown, choose between an exact date, a time frame, or all campaigns that are overdue. ## Reviewing and Performing Campaign Tasks From the campaign management screen, select a campaign to review. From there, the review page for that campaign displays. All records are displayed. When decisions are completed, select **Commit**. This applies to both the table and graph view. ### Table View Note The default view of the review page is the table view. Toggle to **Graph** to view the resources in a graph view. To view the details of this campaign, select **Campaign Summary**. Here, the reviewer can see details about the due date, the description of the campaign, and the instructions for the reviewer. It also provides the reviewer's review progress for the campaign. The following are predefined filters that are available for easy viewing: - **Pending Commit** - All records that have a decision but have not been committed. - **Pending Review** - All records that still need decisions. Default view. Within the **Actions** column, approve or reject each individual record. Leaving a comment is optional. Note Making a comment is mandatory on bulk rejections or approvals. ### Graph View The graph view allows a user to take quick action on large amounts of information. When the graph view loads, multiple bar graphs display with the status of each record within the resource grouped together. The statuses are: - Pending - Pending Approve - Pending Reject - Approved - Rejected Selecting **Group By** allows the reviewer to group the records in the campaign by different attributes. Select the desired bar in the graph. A popup appears which provides the reviewer a full view of that resource. Here, the reviewer can easily see the amount of records in each status and perform the necessary action. The **Action** dropdown provides the ability to go back to the table view. Select **View in Table** from the dropdown to be taken back to the table view. The Pending Decision status has **Approve** and **Reject** actions. Selecting one of those actions will move those records from Pending Review to either Pending Approve or Pending Reject when utilized. Note Approving or rejecting is a bulk action at this screen. A comment is required. The Pending Approve and Pending Reject status has a **Clear Decision** action. This allows the reviewer to revert records back to a Pending Review status and clear their current decisions. Tip If at any point you toggle from graph view back to table view, the selected filters will be maintained. Once final decisions are made, select **Commit**. This is applicable for both table and graph view. # Account and Entitlement Aggregation In order to securely communicate with your organization's systems, SailPoint uses Virtual Appliances (VAs) to connect your SailPoint Human Fabric cloud platform and on-premise applications. A VA is a Linux-based virtual machine that connects to your sources and apps using SailPoint APIs, connectors, and integrations. Note Cloud applications are considered "on-premise" because they are deployed from private clouds reserved for use only by your organization. The following steps should be accomplished: 1. Create a VA cluster. This is done in order to associate our VA with your organization. At least one VA should exist within a VA Cluster. 1. Create a source in SailPoint Human Fabric to aggregate Accounts and Entitlements from either Active Directory or Azure Active Directory. 1. Create an Identity Collector in Data Access Security and connect it to the relevant source. 1. Manually run aggregation for Accounts and Entitlements. # Aggregating Accounts and Entitlements There are two possible ways to collect accounts and entitlements. This can be done by either running an aggregation manually in SailPoint Human Fabric or by using the Data Access Security website. ## Run Aggregation Manually in SailPoint Human Fabric 1. Navigate to **Admin > Connections > Sources**. 1. Find the source you want to aggregate from and select **View** on that particular source. 1. In the top left corner, select **Import Data**. 1. Verify that **Account Aggregation** is selected. Near Manual Aggregation, select **Start**. 1. To see all of the aggregated accounts, select the **Accounts** tab. 1. Once the account aggregation process is complete and the amount of accounts matches the number of rows in the Data Access Security database, navigate to the **Import Data** tab. 1. On the Import Data tab, select the **Entitlements Aggregation** view and then select **Start**. 1. To see the aggregated entitlements, navigate to the **Entitlements** tab. ## Run Aggregation from Data Access Security Website Note After the first aggregation from Data Access Security, events will then be pushed to SailPoint Human Fabric. Once events are in SailPoint Human Fabric, then aggregation can be done from there. 1. Navigate to **Admin > Identity Collectors**. 1. On any existing Identity Collector row, select the third icon in the Actions column and select **Run Aggregation**. This triggers the Run Accounts Aggregation task in SailPoint Human Fabric. - All accounts existing in the source that are connected to the current Identity Collector will be imported into SailPoint Human Fabric. - Every found account is sent a message to the Kafka Accounts topic. The Data Access Security Accounts Collector Service takes the relevant messages and saves the collected accounts into the Data Access Security database. After the Accounts are imported, the Entitlements aggregation triggers automatically. It works in the exact same way as for Accounts except for these differences: - Entitlements are sent to Kafka Entitlements topic. - The Data Access Security service responsible for collecting and saving Entitlements is the Data Access Security Entitlement Collector Service. - After the Entitlements aggregation process is finished, an automatic process runs connecting all the imported Accounts with the relevant Entitlements. Note This automatic process also runs on an hourly basis regardless of whether or not aggregation was requested. Note All Accounts should be collected before the Entitlements collection process is finished. After both aggregation processes are complete, all existing users and groups in the Source are in the Data Access Security database. # Create a Source Sources for identity information need to be created in SailPoint Human Fabric. The Data Access Security Identity Collection task relies on these sources to properly associate accounts and entitlements to permissions on the Data Access Security applications. To load or aggregate account data into Data Access Security, configure a source using one of the following links. Important When connecting to an Active Directory or Azure Active Directory source, avoid any filters or limitations when defining the connection in the SailPoint Human Fabric wizard. Data Access Security crawling requires full visibility on the accounts and entitlements. Tip If a user is deleted, they will continue to display in Data Access Security unless the [Enable Account Deletion](https://documentation.sailpoint.com/saas/help/accounts/loading_data.html#scheduling-aggregations-for-direct-connect-sources) is enabled in SailPoint Human Fabric. To enable this, go to **Admin > Source** and select the relevant source. Once the source is selected, go to **Account Management > Account Deletion** and enable the feature. ## Active Directory Source Click [here](https://documentation.sailpoint.com/connectors/active_directory/help/integrating_active_directory/connecting_active_directory.html) to connect an Active Directory source. The following are required in the schemas: **Accounts (Identities)** - sAMAccountName - NetBIOSName - objectSi **Groups (Entitlements)** - sAMAccountName - NetBIOSName - objectSid ## AWS Click [here](https://documentation.sailpoint.com/connectors/saas/aws/help/saas_connectivity/aws/amazon.html) to connect to an AWS source. ## Box Source Click [here](https://documentation.sailpoint.com/connectors/saas/box/help/saas_connectivity/box/connecting_sailpoint_and_box.html) to connect to a Box source. ## Dropbox Source Click [here](https://documentation.sailpoint.com/connectors/saas/dropbox/help/saas_connectivity/dropbox/connecting_sailpoint_and_dropbox.html) to connect to a Dropbox source. ## Google Workspace Source Click [here](https://documentation.sailpoint.com/connectors/g_suite/help/integrating_g_suite/introduction.html) to connect to a Google Workspace source. ## Microsoft Entra Warning Ensure [Manage Microsoft 365 Groups](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/manage_groups_and_teams.html) is enabled. This is required for Data Access Security to properly gather all group information. Click [here](https://documentation.sailpoint.com/connectors/saas/msentraid/help/saas_connectivity/microsoft_entra_id/connecting_sailpoint_microsoft_entra_id.html) to connect to a Microsoft Entra SaaS source. Click [here](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/connecting_sailpoint_and_entra_id.html) to connect a Microsoft Entra ID source. ## Snowflake Click [here](https://documentation.sailpoint.com/connectors/saas/snowflake/help/saas_connectivity/snowflake/connecting_sailpoint_snowflake.html) to connect to a Snowflake source. # Aggregation Troubleshooting The following are possible troubleshooting scenarios while trying to aggregate accounts and entitlements. ## Created Source Could Not Connect After defining a new source, there is an option to test the connection of the relevant source (Active Directory or Azure Active Directory). Sometimes while the connection is being tested, it fails with the following error: The solution for this error is to either to restart the virtual appliance and run a Test Connection or to wait and after some time re-run the Test Connection again and it will finish successfully. To see the status of your source: 1. Navigate to **Admin > Connections > Sources**. 1. View the status of the source. 1. Select **Test Connection**. ## Run Aggregation Has Not Run in SailPoint Human Fabric 1. Navigate to **Admin > Connections > Sources**. 1. Select **VIew** within the appropriate source. 1. Navigate to the **Import Data** tab. 1. View the Aggregation Activity Log at the bottom of the page. 1. Verify that the aggregation process that you ran is displayed in the grid and the status is Success. 1. If ran aggregation is not displayed in the grid, there was a problem triggering aggregation from Data Access Security. 1. If the aggregation failed, then SailPoint Human Fabric could not import any Accounts or Entitlements from the source. ## Azure Active Directory - Removal of Four Risk Accounts The following error can occur if you try to aggregate accounts without completing the following steps: 1. Navigate to **Admin > Connections > Sources**. 1. Select **View** by the above-created source. 1. Navigate to the **Import Data** tab > **Account Schema**. 1. Search for "risk" and the following results should be returned: - riskLevel - riskState - riskDetail - riskLastUpdatedDateTime 1. Delete all of them. # Create an Identity Collector In Data Access Security, an Identity Collector is used for collecting accounts (users) and entitlements (groups) from a source. Currently, Data Access Security supports collecting accounts and entitlements from Active Directory and Azure Active Directory sources. To create an identity collector, complete the following steps: 1. Navigate to **Admin > Identity Collectors** and select **Create New**. ## General Details 1. From the Type dropdown, select the type of source. 1. In the Name field, provide a name for the identity collector. Note Identity Collectors cannot have the same name, even if they have different sources. 1. Select **Next**. ## Connection Details 1. From the ISC Source dropdown, select the source the needs to be used for collecting users and groups. Note The source that was selected in the General Details steps will be the only source option that displays. 1. In the Properties to Fetch fields, you can manually add properties for users and groups which will be collected in addition to the default properties. Properties added in the Users Collection will be relevant to the collected users' data and the properties added in the Groups Collection will be relevant to the collected groups' data. When fetching user and group properties, only attributes that are available in the corresponding SailPoint Human Fabric source schema can be fetched. Note Entered properties will be mapped in the following steps. Each source that Data Access Security connects to has a set of account and group attributes: - [Active Directory Attributes](https://documentation.sailpoint.com/connectors/active_directory/help/integrating_active_directory/ldap_names.html) - Azure: - [Account Attributes](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/account_attributes.html) - [Group Attributes](https://documentation.sailpoint.com/connectors/microsoft/entra_id/help/integrating_entra_id/group_attributes.html) - G Suite: - [Account Attributes](https://documentation.sailpoint.com/connectors/g_suite/help/integrating_g_suite/account_attributes_.html) - [Group Attributes](https://documentation.sailpoint.com/connectors/g_suite/help/integrating_g_suite/group_attributes_.html) - Dropbox: - [Account Attributes](https://documentation.sailpoint.com/connectors/dropbox/help/integrating_dropbox/account_attributes.html) - [Group Attributes](https://documentation.sailpoint.com/connectors/dropbox/help/integrating_dropbox/group_attributes.html) - [Box Attributes](https://documentation.sailpoint.com/connectors/box/help/integrating_box/schema_attributes.html) - Microsoft Entra: - [Account Attributes](https://documentation.sailpoint.com/connectors/saas/msentraid/help/saas_connectivity/microsoft_entra_id/account_attributes.html) - [Group Attributes](https://documentation.sailpoint.com/connectors/saas/msentraid/help/saas_connectivity/microsoft_entra_id/group_attributes.html) ## Users - Dynamic Fields Mapping This step is optional. Dynamic Fields Mapping allows renaming the fetched properties (default properties and manually added ones) by mapping them to a dictionary field. Note Only Users Data Dictionary fields can be used for mapping. 1. After mapping the properties, select **Next**. ## Groups - Dynamic Fields Mapping This step is optional. Dynamic Fields Mapping allows renaming the fetched properties (default properties and manually added ones) by mapping them to a dictionary field. Note Only Groups Data Dictionary fields can be used for mapping. 1. After mapping the properties, select **Next**. # Creating Virtual Appliances View [SailPoint Virtual Appliances](https://documentation.sailpoint.com/saas/help/va/index.html) in order to understand the necessary system and network requirements as well as how to deploy, configure, and manage your virtual appliances. # Data Access Security Admin Help The terms "user" and "user permissions" in Data Access Security are used in two different contexts: - **Business Resource Users** - Entities within the organization, their access permissions to various company resources, and the activities they perform on these resources. - **Users** - Entities such as company employees and bots with access to company resources. - **User Permissions** - Permissions or capabilities granted to a user to perform tasks such as reading and writing to a Windows File Server, sending emails, writing to Google Drive, deleting files, etc. - **Data Access Security Users** - Administrators and users of Data Access Security and their access permissions to various parts of the application. What reports they can run, what resources they are allowed to view, etc. ## Capabilities Review the following main capabilities of Data Access Security: - **Crawling** - Crawling is a process that discovers the business resources of a specific application, such as folders, mailboxes, etc. It is the first task performed on an application, since business resources are required for many other capabilities, such as Permissions Collection and Data Classification. - **Identity Collection** - The Identity Collector is a software component responsible for synchronizing identity data (for example, accounts and attributes) from identity stores. - **Permission Collection** - Permissions Collection is a process that discovers and collects permissions on the business resource of an application. These permissions are later used and displayed in Permissions Forensics, Access Certification campaigns, Access Requests, and in other locations. - **Data Classification** - The Data Classification mechanism provides the ability to discover and classify resources and files containing sensitive information, such as credit cards, personal information, and health records. # Permissions This section describes how permissions (i.e. access rights) that are collected during the Permission Collection process and analysis task are represented in Data Access Security. Many of the key Data Access Security Permissions use cases involve gaining visibility to actual active involvement of management in permission reviews. Permissions describe the access that a specific User or Group has on a specific Business Resource. Examples of permissions include: - Mary Jones has Read access to the Finance folder directly. - John Smith has Write access to the Finance folder because he is a member of the Finance AAD Group. - Larry Taylor has Write access to the Finance folder directly because he is a member of the Admins AAD Group. Atypically, a permission may also include an Allow/Deny modifier. ## Permission Modeling Basic rules are used to model permissions from various systems into a single coherent view. Every permission consists of a combination of the following four elements: - User - Group - Permission - Business Resource Not all components are required for all permissions, since some systems provide direct permissions to users, while others only enable permissions through groups. ## User The user is an object that represents an account associated with a permission. Standard user attributes include: - **User entity type** - User, local account, or special account. - **User disabled / enabled** - Whether the user account is enabled or disabled in the managed application or the identity store. - **User domain** - The security domain in the identity store in which the user is defined. For example, when an identity collector is set on an SailPoint Human Fabric source for Azure Active Directory, extended attributes may be Department and Manager. ## Group A group is a container of users in a group, responsibility, or profile. Some endpoint systems only set permissions through groups. Standard group attributes include: - **Group Type** - Often provided in accordance with the group type, depending on the type of endpoint system. - **Group Domain** - The security domain in the identity store in which a group is defined. ## Group Nesting Normally, it is possible to nest Groups such as that one group resides within another group. For example, assume that Group A contains both User A and User B. If Group A is also a member of Group B, then it follows that Group B also contains User A and User B. Data Access Security examines all nested groups when it analyzes which entities are effective group members for a given group. ## Permissions Permissions are functions enabled or denied to a user or group. Permissions are identified for out-of-the-box supported systems. The standard permission attributes (that provide context) include: - **Permission Type** - The function name - **Access Control List (ACL) Allowed** - Allow or Deny - **In Inherited** - Defined locally or inherited Note “Is Inherited” is crucial to Permission queries, since it eliminates permission duplication by showing only unique permissions. ## Owner Permission Most permission mechanisms utilize a special Owner permission type. Typically, the Owner permission cannot be blocked, revoked, or customized, and provides full access rights. Different applications and permission mechanisms may interpret Owner permission differently. The table below describes the permission types that Data Access Security treats as an Owner permission. For each platform, the Owner permission is defined and named (queried by the listed name in the AFM query filter controls). | Permission Scheme | Description | | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Microsoft ACL | Microsoft Access Control Lists contain a special field that indicates the owner user/group of the resource (for example, a file or a folder). There can be only one entity defined as the Owner (but that Owner can be a group). Since an Owner has full control of the ACL, the Owner effectively grants all permissions. The Microsoft ACL Owner applies to:- Windows File Server - Active Directory - Microsoft Exchange Online - NetApp - CIFS - Powerscale | | Unix | When a file(/folder) is created in Unix/Linux, its creator is automatically set as the Owner. Permissions are categorized by:- Owner - User's in the Owners group - Other Users There can only one owner user and one owner group per file/folder. Since only the Owner (or root) can change file permissions, an Owner effectively grants all permissions. The Unix file system Owner applies to:- NetApp – NFS | | SharePoint | A SharePoint server features Site Collection containers, which function as separate entities, and permission scopes. Different Site Collections may have different users, groups, and permission types. One or more users in a Site Collection may be defined as a Site Collection Administrator. The Administrator has full control of the resources in the Site Collection’s inner structure. The SharePoint Site Collection Administrator applies to:- Microsoft SharePoint - Microsoft SharePoint Online - Microsoft OneDrive | | Cloud Storage Providers | Typically, cloud storage providers include a permission type named “Owner” which grants full access rights to the resource (file, folder etc.). The generic “Owner” permission is employed in:- Box.com - Dropbox - Google Drive | ## Business Resource A business resource (BR) is a monitored application object, such as a folder on OneDrive or Sharepoint Online. Business resources can have child BRs and can inherit permissions from a parent resource. Standard business resource attributes include: - **Name** – Name of the resource - **Full Path** – Path with all its hierarchy levels (a unique business resource identifier, for example C:\\Finance\\CTO) - **Inherits Permissions** – A flag identifying whether or not a business resource inherits permissions In cases applications support file level permissions, the business resource tree will include BRs on a file level, where: - The application is configured in the setup to includes file level permissions. - The file has unique permissions, compared to its parent nodes. ## Inheritance While inheritance can make management easier, it also can result in unnecessary duplication. Permission analysis analyzes inheritance by determining whether a business resource inherits permission, and whether a specific permission is inherited. The table below lists the relationships involved in permission analysis. | Business Resource Inherits Permission | Permission is Inherited | Result | | ------------------------------------- | ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- | | True | True | The permission is not unique and derives from the father permission. | | True | False | The permission is unique and even though the business resource inherits permissions, the specific permission is not inherited. This is a common scenario in NTFS. | | False | False | The permission is unique. | | False | True | The permission is unique. | Note The last case in the table is a situation that occurs in a few specific end systems (as it is logically inconceivable). For example, the system enforces SharePoint Policy Rule Permissions from the Web application level. Therefore, even if the business resource does not explicitly inherit any permissions, permissions are still inherited. ## Permission Examples The table below lists examples of the results of combining specific permission elements. | Business Resource | Permission | User | Group | Result | | ----------------- | ---------- | ------ | ------ | ---------------------------------------------------------------- | | Folder X | Read | Asmith | Group1 | User Asmith has read permission on Folder X derived from Group1. | | Folder X | Read | Asmith | | User Asmith has a direct read permission on Folder X. | | Folder X | Read | | Group1 | Group1 has read permissions on Folder X. The group is empty. | ## Permission Collection Process Permissions Collection is a process that discovers and collects permissions on the BRs (business resources, such as folders) of an application. These permissions are later used and displayed in Permissions Forensics. The task itself is a Permissions Collection task. The permission collector uses one permission collection virtual appliance cluster. In applications that support file level permissions, and where activated, the Permission Collector will read all files/objects with unique permissions. This means objects with different permissions than the resource where they reside. These will be considered as business resources in the resource tree, and will support data ownership. ### Configuring and Scheduling the Permissions Collection Permissions can be analyzed to determine the application permissions of an out-of-the-box application, provided you have defined an identity store for Data Access Security to use in its analysis, and you have run a crawl for the application. The permission collector is a software component responsible for analyzing the permissions in an application. ### Scheduling a Task The following are options for scheduling a permission collection task: **Create a Schedule** - Select this option to view the schedule setting parameters. **Schedule Task Name** - The name for this scheduled task. When creating a new schedule, the system generates a default name in the following format: [appName] - [type] Scheduler You can override or keep this name suggestion. **Schedule** - Select a scheduling frequency from the dropdown menu. - Run After - Create dependency of tasks. The task starts running only upon successful completion of the first task. - Daily - The start date and time for the task. - Weekly - The day(s) of the week on which to run the task. - Monthly - The start date defines the day of the month on which to run a task. Max interval number of 12. - Quarterly - A quarterly schedule with a max interval of 4. - Semi-Annually - A schedule with a max interval 2. - Yearly - A yearly schedule with an interval of 1. **Date and time fields** - Fill in the scheduling times. These fields differ depending upon the scheduling frequency selected. **Active Check Box** - Check this to activate the schedule. Note When scheduling a task, be aware that the default time is in UTC. Select **Next**. # Business Resource Owners Business resources in Data Access Security are assigned to users so they can see the resources in the various screens they are permitted to access. The business resources assigned to a user are defined as the user’s scope. A business resources owner, or Data Owner, is defined in the system as a user with user scope assigned to them, who has the Data Owner capability. The Data Owner is the owner all the business resources that are assigned to them. ## Assigning Data Owners You can select business resource owners through any of the following methods: **Manually (using Data Owners page)** - Navigate to **Resources > Owners**. See Assigning a Data Owner Manually for more information. **Bulk Upload (using Import User Scope)** - See [Import User Scope](https://documentation.sailpoint.com/das/help/admin/manage_das_users.md#import-user-scope) for more information. Important This process only updates the user scope. You must add the Data Owner capability in order to make the user a data owner of this scope. Important The bulk assignment of data ownership overrides data ownership previously assigned to an individual business resource. ### Assigning a Data Owner Manually By default, data owners own the entire tree below the business resource they are assigned to, via data owner hierarchy. To assign a data owner to a resource manually, you must first break the hierarchy. Complete the following to add a data owner to a resource: 1. Navigate to Resources > Owners. 1. Select a resource from the resources tree on the panel on the left. 1. If there is a current owner inherited from a higher hierarchy, uncheck **Inherit data owners from [application][business resource]**. There are two options for breaking the hierarchy: - **Yes** - Breaks the inheritance and removes the current owner(s). - **Yes - Copy the current owners** - Breaks the inheritance and adds a new owner in addition to the current owner(s). 1. Select **+ Add New Owner**. 1. Select the requested user by entering part of the name and selecting from the dropdown list. 1. Select **Save**. ## Data Owner Inheritance The owner of a business resource is also the owner of the child business resource, unless you assign a different data owner to a specific child business resource. If the business resource has an owner through data owner inheritance, there is no button to add an owner. Breaking the inheritance allows assigning additional data owners at this level and below. If you break the data owner inheritance but do not assign a new owner, the data owner inheritance switches back on. The new owner assigned to the business resource is the owner of the current and all downstream resources. ### Breaking Data Ownership Inheritance In this example, Data_Admin is the owner of folder C$\\Data. You want to assign the folder C\\Data\\HR to Admin_HR and the folder C\\Data\\System to the users Data_Admin and Example_Ops. 1. Navigate to **Resources > Owners**. 1. Assign a unique owner for HR: 1. Select the folder C$\\Data\\HR on the Resource Tree. 1. On the Current Owners panel uncheck **Inherit data owners from [application]C$**. 1. Select **Yes** to indicate that you want to break the inheritance, and not continue Data_Admin as the local owner from this branch down. 1. Select **+ Add New Owner**. 1. Select the user Admin_HR. You can start entering the name and select from the dropdown list. 1. Select **Save**. 1. Assign additional owner for System: 1. Select the folder C$\\Data\\System. 1. On the Current Owners panel, uncheck **Inherit data owners from [application]C$**. 1. Select **Yes – Copy the current owners** to indicate that you want to break the inheritance, and add a new owner in addition to Data_Admin for this resource. 1. Select **+ Add New Owner**. 1. Select the user Example_Ops. You can starting entering the name and select from the dropdown list. 1. The names Data_Admin and Example_Ops are listed as current owners for this, and all downstream folders. 1. Select **Save**. # Crawling Crawling is the process that discovers the business resource (BR) of a specific application type. It is the first task involving an application, since BRs are required for many other activities involving applications, such as Permissions Collection and Access Certification. For example, a crawler may discover folders (BR) on a connected application. Before beginning the crawling process, you must create a [Resource Collection](https://documentation.sailpoint.com/das/help/getting_started/cluster_creation.html#crawler_virtual_appliance) virtual appliance cluster. The crawling process involves the following: - Discovery of business resources and the population of a business resource tree - Business resource size calculation | File Name | File Type | Size | | ------------------------- | ----------------------- | ---- | | Finance Balance Sheet.xls | Excel (\*.xls) | 2 MB | | Finance Salaries.docx | Word (\*.docx) | 1 MB | | Finance Departments.txt | Text (\*.txt) | 3 MB | | Finance Organization.ppt | PowerPoint (\*.ppt) | 5 MB | | Finance Other Files | (An uncommon file type) | 4 MB | - Summary of business resource size by file type | Category Name | Size | | ------------------- | ----------------------- | | Office Files | (2MB + 1MB + 5MB = 8MB) | | Text Files | 3 MB | | Finance Other Files | 4MB | The Business Resource Trees display the results of crawling in various locations in Data Access Security. ## Interaction of Crawling with Permission Analysis The permissions analysis process collects the following: - The crawling process collects application business resources. - In parallel, the Identities Collector collects users and groups (which may occur before the crawler collects the business resources, since these collections are unrelated). - The Permissions Collector collects the business resources, users, and groups, and associates them with permission types to create permissions. ## Configuring and Scheduling the Crawler To set or edit the Crawler configuration and scheduling, complete the following: 1. Navigate to **Admin > Applications**. 1. Scroll through the list or use the filter to find the application. 1. Click the edit icon on the line of the application. 1. Select **Next** until you reach the Crawler & Permissions Collection settings page. Note The actual entry fields vary according to the application type. See [Scheduling a Task](https://documentation.sailpoint.com/das/help/resources/permissions.html) to set a schedule. ### Setting the Crawl Scope There are several options on how to set the crawl scope: - Setting an explicit list of resources to include and / or exclude from the scan. - Creating a regex to define resources to exclude. ### Including and Excluding Paths by List To set the paths to include or exclude in the crawl process for an application, complete the following: 1. Navigate to **Admin > Applications**. 1. Scroll through the list or use the filter to find the application. 1. Click the edit icon on the line of the application. 1. Select **Next** until you reach the Crawler & Permissions Collection settings page. Note The actual entry fields vary according to the application type. 1. Scroll down to the Crawl configuration settings. 1. Select **Advanced Crawl Scope Configuration** to open the scope configuration panel. 1. Select **Include / Exclude Resources** to open the input fields. 1. To add a resource to a list, type in the full path to include / exclude in the top field and select **+** to add it to the list. 1. To remove a resource from a list, find the resource from the list and click the **x** icon on the resource row. Note When creating exclusion lists, excludes take precedence over includes. ### Excluding Paths by Regex To set filters of paths to exclude in the crawl process for an application using regex, complete the following: 1. Navigate to **Admin > Applications**. 1. Scroll through the list or use the filter to find the application. 1. Click the edit icon on the line of the application. 1. Select **Next** until you reach the Crawler & Permissions Collection settings page. Note The actual entry fields vary according to the application type. 1. Select **Exclude Paths by Regex** to open the configuration panel. 1. Type in the paths to exclude by Regex; see regex examples in the section below. Since the system does not collect business resources that match this Regex, it also does not analyze them for permissions. Note To write a backslash or a Dollar sign, add a backslash before it as an escape character. Note To add a condition in a single command, use a pipe character “|”. ### Excluding Top Level Resources Use the top level exclusion screen to select top level roots to exclude from the crawl. This setting is done per application. Note If utilizing Exclude Top Level Resources, what is available to exclude is based on the type of connector. See the various [connector guides](https://documentation.sailpoint.com/das-connectors/help/index.html) for more details. To exclude top level resources from the crawl process, complete the following: 1. Open the application screen by navigating to **Admin > Applications**. 1. Find the application to configure and click the dropdown menu on the application line. Select **Exclude Top Level Resources** to open the configuration panel. The Top Level Resource Exclusion overlay displays. If the **Run Task** button is selected, a task will run a short detection scan to detect the current top level resources. This is the first time the task will run, a note at the top of the overlay will read "Run task to detect the top level resources. If the top level resource list has changed in the application while on this screen, select the **Run Task** button to retrieve the updated structure. Once triggered, you can see the task status in **Settings > Task Management > Tasks**. Note This will only work if the user has access to the task page. When the task has completed, select **Refresh** to update the page with the list of top level resources. 1. Select the top level resource dropdown list and select top level resources to exclude. 1. Select **Save** to save the change. 1. To refresh the list of top level resources, run the task again. Running the task will not clear the list of top level resources to exclude. ## Business Resource Structure The table below lists additional information on the Business Resource Structure. | Application Type | Business Resource Type | Business Resource Full Path Structure | Example | | --------------------- | --------------------------- | ------------------------------------------------------------------------------------ | --------------------------------------------------------------------------- | | Active Directory | Every LDAP Object | Distinguished Name | CN=Howard,CN=Users,DC=Example,DC=com | | OneDrive for Business | Folder | Personal// | Perosnal/watson@company. Example.com/Diagnostics/Recent | | SharePoint Online | Site Collection/List/Folder | https://.sharepoint.com///Lists// | https://sailpoint.sharepoint.com/Wayback Site/Lists/Songs/New York/New York | # Data Dictionary Data Dictionary fields define the attributes of Data Access Security main entity data types such as Users, Groups, and Permissions. Each entity has a separate list of attribute fields. This list of attributes can be modified and added to, in order to extend the identities and permissions entity attributes. You can also provide additional context and adjust them to the specific needs of your organization. These extended attributes can then be viewed in the Data Access Security [Identities](https://documentation.sailpoint.com/das/help/forensics/identity_forensics.html) and [Permissions](https://documentation.sailpoint.com/das/help/forensics/perm_forensics.html) Forensics screens, be queried and filtered, and be used to define certification campaigns and enhance reports. To create a new data dictionary field, edit, or delete an existing one, go to **Admin > Permissions Management > Data Dictionary Fields**. Note If a data dictionary entry needs to be edited, only the field name can be changed. To create a new data dictionary entry, select **New Data Dictionary Field**. Enter a name for the new data dictionary and select the type. Both of these fields are required. ## Search Data Dictionary Fields To search for specific dictionary entries, use the filter function. You can either search for the name of the data dictionary or you can do a general filter by the type of data dictionary it is. Once your filter parameters are set, select **Apply**. # Configuring Data Access Security This section describes the Settings tab in Data Access Security. The Settings tab includes the following sub tabs (displayed from left to right): **Task Management** - Tasks - Scheduled Tasks - Task Auto Retry **Account Exclusions** - Sensitive Account Exclusions **General** - Overexposed Resources - Import User Scope ## Task Management View Data Access Security is a task-oriented system with both interactive tasks (such as querying events) and background tasks (such as producing reports). Scheduling tasks with parameters allows them to comply with various requirements. Data Access Security has long-running processes, including crawling, permissions collection, and reports. The system executes and tracks these processes using tasks and runs them in batches. Reports throughout the system have a button or menu item to create a scheduled task or to run it now. Select Run Now to create ad-hoc tasks in the administrative client to run the report. You can track the tasks in the Data Access Security web application, under **Settings > Task Management > Tasks**. Each Data Access Security service uses a message queue topic to subscribe to a specific type of task for which it is responsible. For example, the Reporting Service listens and handles Report Tasks. User-created tasks and scheduled tasks display in the Tasks screen. Note The permission “Show Tasks from All Users” is required to view all system tasks. This permission is granted by default to the administrator role. Without this permission, the system only displays user-created tasks. Navigate to **Settings > Task Management**. ### Navigation and Menus The Task Management table has the following options: - The checkbox on the left of a task selects a task - The checkbox on top of the table selects all of the tasks on the page - The filter icon at the top right corner opens the filter window - Move through pages by using the arrows at the bottom right corner or insert a page number to go to that page. - Select all x items on the top menu – select all tasks on all pages according to the filter. - Unselect all items – unselect all items on other pages except for the current one. ### Tasks This screen shows a table with the tasks selected according to the user’s permissions and the filter. The data is updated in real time. On this screen you can cancel, rerun, or delete task instances. The filter allows selecting tasks by various parameters, including status, type, and date. Selecting a task opens the Task Details panel which provides a detailed description of the task details and status of submitted tasks. #### Task Fields - **Name, Type** - The task name and/or type - **Status** - This field shows the current status of the task, including a progress bar - **Start Date, End Data** - The start day and time of the task and the end date and time of the task - **Created By** - Provides the name of who created the task - **Task Description** - A brief reason for the task | Status | Icon | | ----------------------- | ---- | | Completed | | | Completed with warnings | | | Failed | | | Canceled | | | In Progress | | | Pending | | Additional columns include Start and End Data, Created By, and Parameters. #### Task Filter The Task screen includes a filter to narrow down the selection of tasks. Select the filter button on the top right corner of the Task screen to open the filter. Note The filter icon and feature is not visible if there are tasks selected. Filter fields include Name, Type, Service, Status, Task that Ended Before (date field), Created by me only. The service filter dropdown lists services that have tasks. 1. Click **Apply** to set the filter. #### Task Actions Select one or more tasks using the checkbox to the left of each task. Selecting a task will open the top option menu: - **Rerun** - Rerun the task(s) selected. Selected tasks that cannot be run will not run. Selected tasks that depend on other tasks to complete before running will run after the prerequisite task runs. - **Cancel** - Cancel the running tasks. - **Delete** - Delete the task(s). #### Task Details Screen Clicking on a task opens the Task Details screen, with a description of the task stages. To close the detail screen, click outside the details screen, or click the X in the upper corner. ### Scheduled Tasks A Scheduled Task tells Data Access Security when, and how often, to execute a specific task repeatedly. For example, a weekly scheduled task can run a weekly Activities Report. The wizards in Data Access Security help create Scheduled Tasks. Every wizard with a scheduling screen has a checkbox for creating a scheduled task in the background. While deselecting a checkbox deletes a scheduled task, an attempt to delete a Scheduled Task via the Scheduled Tasks screen results in the display of a warning popup, indicating that another object or process is dependent on this Scheduled Task. The Schedule Task Handler service creates and processes Scheduled Tasks for the relevant services to handle. Except for a few types of scheduled tasks, it is only possible to edit task scheduling (not parameters) from within the Scheduled Tasks screen. #### Scheduled Tasks Filter The Scheduled tasks screen includes a filter to narrow down the selection of scheduled tasks. Select the filter button on the top right corner of the Task screen to open the filter. Note The filter icon is not visible if there are tasks selected. The filter fields include Name, Type, and Status (either all, active, or inactive). Click **Apply** to set the filter. #### Scheduled Tasks Fields - Name - Task Name - Type - The type of a Scheduled Task indicates the task actions The table below lists and describes the task types: | Type | Description and Task Source | | ------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Application Deletion | One-time task created when deleting an Application. You cannot schedule this task type. | | Built-in Application Permissions Only Collection | Created from the Permissions Collector or the Edit Application wizard. | | Built-in Business Resource Permissions Only Collection | Created by right clicking a business resource in the Permissions/Permissions and Identities Forensics screen and starting a specific business resource permissions’ collection. You cannot schedule this task type. | | Business Resource Deletion | One-time task created when deleting a Business Resource. You cannot schedule this task type. | | Crawler | Controlled through the Edit Application Wizard. | | Data Classification | Different Data Classification tasks. | | Report | Created during report creation or in the Edit report wizard. | | Revert Review Process | A one-time task, created when a review process is reverted in Access Certification or Access Request. You cannot schedule this task type. | **Status** - This field shows the current status of the task, including a progress bar. A scheduled task can be either active or inactive. **Schedule Type** - The schedule type describes the frequency of running the tasks. The following are the schedule intervals: - **Run After** - Create dependency of tasks. The task starts running only upon successful completion of the first task. - **Daily** - Set the start date and time. - **Weekly** - Set the day(s) of the week on which to run. - **Monthly** - The start date defines the day of the month on which to run a task. - **Quarterly** - A monthly schedule with an interval of 3 months. - **Semi-Annually** - A monthly schedule with an interval of 6 months. - **Yearly** - A monthly schedule with an interval of 12 months. **Last Run** - The last time the task ran and whether or not it was successful. **Next Run** - For scheduled tasks that have future runs scheduled. **Parameters** - The run parameters of the scheduled task. Note If a user set a schedule to run yearly, the interval cannot be higher than 1. If a user is setting an hourly, weekly or monthly schedule, an interval higher than 1 will start to work at 00.00. For example, if a schedule is set with a 2 hour interval, it will run every second hour and not every 2 hours from its creation. #### Edit Schedule To edit the schedule of one or more scheduled tasks, select the scheduled task from the Scheduled Task screen, and select Edit. This will open the Edit Schedule panel. Scroll down the panel to see all the input fields. **Frequency Type** - See schedule intervals above. **Run After** - If selecting Run After, select the task after which this task should run. Note When editing more than one task at the same time, you cannot select Run After. **Start Date** - All tasks, except for Once and Run After, have a Start Date. That date defines the baseline date for all calculations. For example, daily tasks with two-day intervals run first on the start date. The next run will be two days after the start date (not two days after the scheduling date). **End Date (Ends)** - There are two options, either Never or On. Never means tasks never end if there is no end date. On means the task will end on the selected date. If set, the system does not schedule new tasks beyond the End Date. #### Related Tasks Clicking a task will open the Related Tasks panel which lists the instances of the scheduled task that were run, the run dates, task status, and running user. Click outside the panel or click the X on the top right corner of the panel to return to the previous screen. #### Running Tasks To run a task, perform the following steps: 1. In the web client, navigate to **Task Management > Scheduled Tasks**. 1. Select a task or tasks from the list of tasks. This can be done by: - Using the filter to narrow down the list of tasks. - Marking the boxes at the left of each task to select it. - Using the select all checkbox at the top of the list which selects all the tasks on the page. 1. This will open the task menu bar at the top of the Task table. - Edit - Run Now - After running a task or tasks, a popup message opens, with a link to the Tasks screen to view the task progress. - Activate – Turn on the Activate flag for all schedule tasks selected. This will enable the scheduling to run, as it is configured. - Deactivate – Turn off the activation flag for all scheduled tasks selected. If you deactivate a scheduled task, the next run field for these tasks will remain empty. Note The options displayed after right clicking are Run Now, Edit, and Delete. #### Task Auto Retry Data Access Security lets you set auto-retry, so that failed tasks can automatically rerun a preconfigured number of times. The tasks that can be retried are configured by task type. By default, most task types are set to auto retry twice. Navigate to **Settings > Task Management > Task Auto Retry** to view a list of all task types that are available for retry. To enable auto retry for tasks, perform the following: 1. Navigate to **Settings > Task Management > Task Auto Retry**. 1. Toggle **Enable Auto Retries for Failed Tasks** on. 1. From the dropdown, select the number of retry attempts. This is the number of additional tries the system will run. To set the task type that will be retried, perform the following: 1. Select the task type from the dropdown menu. 1. Select **Add** to add the task type to the list. Note The dropdown list includes all available task types that are not already selected for auto retry. If all the task types are enabled, the Add Task Type field is disabled. To delete a task type from the list of task types, perform the following: 1. Locate the task type you wish to delete from the list. 1. Select the trash icon on the same row of the task. 1. Select **Save** to save the changes or **Discard** to undo them. ## Account Exclusions Administrators use the Account Exclusions setting to exclude specific accounts from appearing in various reports or activities. This might include bots that access resources often, but should not be considered for data ownership, or sensitive accounts, that we might not want appearing on activity reports. To open the exclusion screen, navigate to **Settings > Account Exclusions**. ### Add a Single Account 1. Select **+Add Account**. 1. Search for a user from the combo box. 1. Select **Add**. ### Remove Accounts Filter the list of accounts using the filter field. **For a single account:** Select **Delete** from the Actions menu on the row of the account to delete. **For a multiple accounts:** Select the required accounts by clicking the checkbox on the account row. Select the **Delete** icon. ### Critical Account Exclusions The permissions and activities of the excluded accounts will be visible to Administrators only. Select User / Group accounts, or use a prefix. All the direct members of an excluded group will be excluded. Once an account is on the exclusion list, data owners will not be able to see those accounts in the following screens: - Resources > Permissions > Simple View - Resources > Permissions > Excess View - Resources > Permissions > Tree - Resources > Owners - Forensics ## General Menu General settings affect the entire system. To get to the general menu, navigate to **Settings > General**. ### Overexposed Resources Overexposed resources are resources accessed by groups with “too many” members. The system determines large groups based on basic parameters, and administrators can change those parameters. Everyone and Authenticated Users groups are included by default, but it is possible to further filter (define) overexposed resources by group. To define overexposed resources, perform the following steps: 1. Navigate to **Settings > General > Overexposed Resources**. 1. Check the **Groups containing at least \_\_\_% of user accounts** checkbox to define groups by the percentage of user accounts. (This checkbox is checked by default.) 1. Check the **Groups containing at least \_\_\_ user accounts** checkbox to define groups by the number of user accounts. (This checkbox is checked by default.) 1. Check the **Include Share permissions (on CIFS-based applications)** checkbox to include those share permissions. (This checkbox is checked by default.) 1. To exclude group accounts from the overexposed group, type the account name, or the first few characters of the account name, in the Exclude Group Account search box. 1. Select **Save** to save the selection, or **Discard** to discard it. 1. To remove a group from the list, select the **x** next to the group name. ## Scope The scope determines what applications and resources a Data Access Security user can access and run reports on within the application. ### Assigning Scope to Users User scope can be assigned to users. Data scope can be defined in terms of folders within an application that the user can access. ### Assigning User Scope to Users There are several ways of assigning scope to users in Data Access Security. - Administrators are assigned the Full Scope resource allocation (see below) automatically when they are assigned the Administrator capability. - Bulk assignment of user scope, using Import User Scope (see below). ### Full Scope Resource Allocation The Full Scope resource allocation is an administrator-level allocation which allows a broad view and general system-wide statistics of the business resources. Full Scope is added automatically to Administrator users. It can also be added through the user scope import by navigating to **Settings > General > Import User Scope**. You cannot remove the Full Scope capability from users who are Administrators, even by using Import User Scope. To create an administrator that has less access than Full Scope, clone the Administrator capability and upload the required coverage using User Scope Import. The Full Scope Resource allows access to all resources in the dashboard and reports. It does not allow the following: - Users with Full Scope who are assigned with the Data Owner capability are not data owners of the entire scope, but only of any user scope that is allocated to them specifically. This includes approving data owner requests, approving access requests, etc. See [Business Resource Owners](https://documentation.sailpoint.com/das/help/admin/br_owners.html). - Drilling down from statistics in the Data Owner Dashboard allows you to view only the resources to which this user has direct allocation. This means that in some cases, drilling down from a chart on the dashboard will display detailed charts of the partial scope that do not add up to the totals that were on the dashboard charts showing the full scope. If an admin user has no directly allocated resources, the user receives an error message and an empty chart. ### Import User Scope Users can be assigned resources in bulk, using a one time or scheduled import process. Note The Import User Scope functionality supports changes and adjustments to existing scopes. There is an Action field that displays one of four possible values: - Add – adds the resource to the User's Scope. This action can either have a full scope or a resource. If a resource is specified, the full scope is ignored. If a resource is empty, the full scope field must be true. The user should specify both the application and full path to add a scope for a specific resource. - Remove – removes the resource from the User’s Scope. This action can either have a full scope or a resource. If a resource is already specified, the full scope is ignored. If a resource is empty, the full scope field must be true. The user should specify both the application and full path to remove a scope for a specific resource. - Clear – removes all resources from the user’s scope. This command does not need any data specified in the Application or Resource Full Path columns. This operation removes all resources from the users scope. This action can only have Full Scope set to True. - Data Owner – functions in the same way as Add, but also adds the Data Owner capability to the user if they do not have it already. If the user already has the Data Owner capability, the Data Owner action simply functions as Add. This action cannot have a full scope. It must have a resource. Full scope is ignored and if the resource is empty, the line will be ignored as well. **Importing a User Scope** When setting the Full Scope parameter to True, the record cannot contain other parts of resources, such as Application Name and Full Path, since it already contains all paths and applications. The input source should contain the following information: | Input Field | Description | | ---------------- | -------------------------------------------------------------------------- | | Application Name | Name of the application as it appears in Data Access Security | | Full Path | Full path of the resource | | Full Scope | True/False toggle for granting the user full scope access to all resources | | User Name | User name of the user receiving access | | Action | Actions related to resources, including Add, Remove, Clear, and Data Owner | **Setting up the Import Process** 1. Navigate to **Settings > General > Import User Scope** to open the Import User Scope page. Note There is a CSV file within the website that is there to serve as a basis for the data source. There are explanations about the different actions within the template file. Select the provided link within the Import User Scope display for this preferred method. 1. Upload the CSV file by dragging the file to the upload box or by selecting **Choose a file**. 1. Once uploaded, select **Run**. 1. Navigate to **Settings > Task Management > Tasks**. Here, you can view the newly created Import User Scope task and track its progress. 1. Click the name of the task to view the details. # Managing Alert Rules You can configure alerts to continuously scan Data Access Security for behaviors that might indicate potential security threats or policy violations. Alert rules are custom created attributes which trigger notifications when defined criteria is met on monitored activities. This can include creating specific rules when actions on sensitive information has occurred. To create, view, and manage alert rules, go to **Compliance > Alert Rules**. Once on the Alert Rules screen, all created rules are displayed along with a description of each rule, the severity of the rule, and the conditions that make up the rule. You are also able to turn each rule to Active or Inactive under the Enabled column as well as edit, duplicate, or delete the rules. # Configuring Discard Rules Discard rules remove unnecessary or irrelevant activities from monitoring or reporting. These rules help maintain focus and reduce unwanted activity information by ensuring only meaningful and actionable data is retained for analysis and monitoring. To create or view discard rules, go to **Settings > Discard Rules**. Discard rules follow the same configuration steps as [creating an alert rule](https://documentation.sailpoint.com/das/help/alerts/new_alert_rule.html) with the exception of selecting the severity level. Discard rules do not require a severity level. Discarded activities will not be available through Data Access Security. # Creating an Alert Rule Go to **Compliance > Alert Rules** and select **Create New**. Complete the following steps: ## Base Configuration 1. Provide a name for the rule. 1. Provide a description of the rule. 1. In the Severity dropdown list, select the level of rule severity. - **High Severity**: Use for important and urgent alerts for your organization. This could be potential rogue behavior, sensitive data leakage, or noncompliant access to sensitive data. - **Medium Severity**: Apply to alerts that indicate potentially non-compliant or harmful activity that requires investigation but might not require immediate response. - **Low Severity**: Assign to alerts that indicate minor or routine issues that require attention but are unlikely to cause serious harm. These alerts can be monitored with less urgency, for example by scheduling a report and reviewing them as needed. 1. Change the rule status to Active to enable this rule upon creation. 1. Select **Next**. ## Rule Criteria Define the scope of the rule. 1. From the Scope Type dropdown list, select All, Application Type, Applications, or Resources. Then select the appropriate value in the next dropdown list. 1. To remove parameters from the rule, set exclusions. From the Scope Type dropdown list, select what type needs to be excluded. Then select the appropriate value in the next dropdown list. 1. You can use and combine filters to specify the criteria that trigger the alerts, and ensure only relevant and actionable activities are flagged. Combine filters (e.g., action type + actor attributes + data classification on the object that alert was performed on) to refine and focus the behavior according to your organizational needs. 1. Select **Next**. ## Response Choose a response for the alert. 1. Enter an identity's name in the search field and select the identities who will receive an email with the alert properties once it’s triggered. The email includes the alert rule and the following properties: - User name - Department - Action Type - Application - Resource Path Note Customizing alert [email templates](https://documentation.sailpoint.com/saas/help/common/emails/available_templates.html) is available. 1. To complete the alert rule creation, select **Done**. # Viewing Alerts in Activity Forensics To view alert rules or alert severity, go to [**Forensics > Activity**](https://documentation.sailpoint.com/das/help/forensics/activity_forensics.html) and select Alert Rules Name or Alert Severity from the filter dropdown list. Once one is selected, continue providing the parameters to the filter. Enable **Show Alerts Only** to view alerts only. ## Generating an Alerts Report You can generate an ad-hoc or scheduled report for an alert rule by selecting **Generate Report** on the Activity Forensics page. This can be used as a log for audits and compliance reporting or used by a security team to review medium and low severity alerts from Data Access Security. # Data Classification Data Access Security's Data Classification engine identifies and categorizes data based on data sensitivity, its impacts, and the importance of the data to the business. The Data Classification engine is a mechanism to classify organizational data and to apply categories to that data based on the content of files and data assets residing on the various applications. Data Classification can leverage preset packaged policies and rules, as well as create custom ones, to identify sensitive information such as personal information, medical records, or payment card information which may by subject to certain regulations such as HIPAA, PCI, and regional data protection and privacy regulations like GDPR, CCPA, LGPD, etc. In addition, policies and rules can be created and leveraged to identify organizational “crown jewels”, such as content that may include intellectual property, classified, or restricted content. Data Access Security delivers a variety of preset classification rules and policies including policies to identify Personal Identifiable Information (PII), Protected Healthcare Information (PHI), and information subject to GDPR regulation, and rules to identify different data elements such as Payment Card Information and various national identifier patterns, among others. In addition, administrators and compliance managers can customize policies, rules, search pattens, and conditions to create their classification criteria to address their unique needs. The Classification policies and rules can be leveraged to classify data assets and apply classification categories on the data assets based on their content analysis. For more information on content-based classifications, see [Classification Types](https://documentation.sailpoint.com/das/help/data_class/class_types.html). ## External Classification In addition to its native classification capabilities, Data Access Security can also interact and leverage classification tags and categorizations done by external or 3rd-party tools. This can be done in several ways: - When the existing classification or data categorization applied metadata tags or attributes to the files or data assets themselves, such as in the case of MIP, Titus and others. Data Access Security will be able to extract and read these classification tags, act on them, and incorporate them into its own classification process. - In addition, Data Access Security can import classification tags and data categorization through its Data Classification Import capabilities. Import capabilities can ingest classification results when these are exported to a file-based format, and integrate them into its own classification catalog. - These methods can be leveraged to incorporate classification results to encrypted or password protected files and data assets without the need for enabling Data Access Security to read the encrypted or protected content. # Application and Policy Scope ## Application Scope Use this screen to view and set the scope of applications and resources on which to apply Data Classification policies. Navigate to **Compliance > Data Classification > Application Scope**. The scope list includes only applications with installed Data Classification. The [Optical Character Recognition (OCR)](https://documentation.sailpoint.com/das/help/data_class/ocr.html) column indicates whether the application has OCR activated on part or all part of its resources. The scope definition directly affects the time required for Data Classification indexing. Activating Optical Character Recognition on resources is a resource intensive process, and should be configured carefully. For example, to reduce Data Classification indexing, an Administrator can: - Exclude an application from Data Classification indexing (if “non-critical” data is saved by default on that application). - Include a specific resource (one with very important data) for Data Classification indexing. You can specify which resources to use (and which to exclude) from a selected application by clicking the Edit button to the right of the application. The Scope definition only takes effect after the next run of the Data Classification task. Only the business resources of an application selected for editing display on the list. ### Editing the Application Scope 1. Select **Edit** to modify the scope (such as folders). 1. Find the desired application from the Application Scope screen. 1. Select **Edit**. To change the scope, complete the following: 1. Select the scope type. - All – Run Data Classification on all the resources in the application - Resource – select from a list of resource to include To exclude resources from the Data Classification process: 1. Toggle the **Exclude from Classification** option on to select the desired resource. 1. Select resources to exclude from the dropdown list. To enable OCR: 1. Toggle the **Optical Character Recognition (OCR)** option on to enable OCR analysis for the application. 1. Select the resources to exclude from the OCR analysis from the dropdown resource tree. Note Changes to the scope or activating the OCR on an application will trigger a re-indexing in the next run of the Data Classification task. Deactivating OCR on an application will not trigger re-indexing. To adjust the data classification sampling ratio: 1. Move the sliding scale to the desired percentage. Rather than scanning all resources which could take a substantial amount of time, the sampling ratio feature allows you to select a percentage per top level resource that is scanned within the set scope. For example, if 25% is selected on the scale, the data classification task will navigate to each top level resource and scan every fourth resource within that folder hierarchy. The default percentage is 10%. 1. Select **Save**. ## Policy Scope Use this page to view and define the Data Classification scope of your existing policies and adjust each one by specific applications or application types. By default, every policy will include all applications and application types in the scope. 1. Navigate to **Compliance > Data Classification > Policy Scope**. 1. Select the **Edit** icon on the desired policy. The Policy Scope overlay displays. From here, the Scope Type and the Application Type or specific Application can be edited. If Application Type is selected, supported applications within Data Access Security will display. If Application is selected, a list of the added applications will display. 1. Select **Save**. After saving the policy scope, a task is created. 1. Rescan all applications associated with the updated policy. # Classification Types ## Content-Based Classification Content-based classification scans, parses and analyzes the files’ textual content and searches for specific patterns, according to predefined sets of rules. These patterns can consist of keywords or keyword lists, dictionaries, complex regular expressions representing patterns such as national identifiers, payment card information, patent numbers, formulas and source code, and other user-defined parameters. # Data Classification Components The Data Classification process assigns categories to business resources according to rules. Rules are composed of one or more rule criteria. Rule criteria consists of finding a match within files to one or more string or pattern. The strings can be defined as free text, regular expressions, or one stored as a policy object. A regular expression in a policy object may be accompanied by a verification algorithm to further narrow down the search. Note There are policy objects and verification algorithms out of the box for standard searches or you can create your own to fit your needs. The classification rule is the main data classification component. Rules also contain subcomponents that complete the rule structure, simplify the rule management task, and provide extended functions. File properties can be used for classification of files that is performed by the customer manually or using a third party application. Data Access Security will read the metadata on the files and can use them for data classification rules. This will include reading metadata from encrypted files. ## Data Categories The data category (the basic component of data classification) is the tag used when a classification rule is satisfied. To define a data category, open the **Manage Categories** panel from any of the Data Classification screen. 1. Navigate to **Compliance > Data Classification > Policies > Actions > Manage Categories** or **Compliance > Data Classification > Rules > Actions > Manage Categories**. 1. In the Manage Categories window, type the category name in the **Add New Category** section. 1. Select **Add**. The system adds a new data category to the Current Categories list. Users can edit and delete existing user-defined categories from the Current Categories list. Users can also search categories either by name or by checking the **Show user defined categories only** checkbox. Categories have a default sensitivity level of Medium. The sensitivity level can be set to Low or High according to the organizations policy for the business resources tagged within the configured category. ## Data Classification Policy The Data Classification Policy is a logical container for data classification rules. For example, all the rules that help identify content which may be subject to HIPAA regulation should be grouped under a HIPAA policy. Data Access Security provides several predefined packaged policies and classification rules. Users can create additional user-defined policies, as well as adjust, extend, and customize existing ones. ## Rules Policies set the rules for detecting critical, sensitive, and regulated data to be protected by organizational procedures, governance processes,and access controls. ## File Properties Data Access Security analyzes standard attributes, including extension, size, and file name and also other metadata attributes and file properties. All file properties are discovered and created during the classification analysis process. 1. In the web client, navigate to **Compliance > Data Classification > Rules > Actions > Manage File Properties** or **Compliance > Data Classification > Policies > Actions > Manage File Properties** to open the Manage File Properties window. 1. Type the file property details. 1. If relevant, check the **Custom Properties** checkbox. 1. Select **Add**. ## Encrypted Files In order to classify encrypted files without Data Access Security reading the file contents, you can tag the files locally according to your classification rules and use these tags for classification rules (See Local Classification). ## Local Classification You can use a local classification for files by tagging files with relevant tags. The metadata of the files are uploaded to the Data Access Security database as file properties in the scanning process. These properties can be used to create classification rules manually. The file properties found will be added automatically to the list of available properties for filtering after the first iteration. In order to have these properties available in the initial run of the Data Classification, add the properties to the property list, as described in [File Properties](#file-properties) above. ## Policy Objects Policy objects are searches which are saved for use in rules. For example, predefined policy objects can search for credit cards. 1. Navigate to **Compliance > Data Classification > Policy Objects**. 1. Select **New Policy Object** to open the New Policy Object page. Data classification policy object fields include: - **Policy Object Name** - Name of the policy object - **Description** - Provide additional information about the policy - **Type** - The type of search that the policy object performs. It can be one of the following search types: - Keyword - A keyword may be one or more words. If multiple words are involved, the entire phrase will be searched. Stop words such as "a" or "and" are stripped from the search keywords. If you want to include stop keywords in the phrase, you can use a regex phrase instead. (For more information on ignoring stop words, see ) - Wildcard - Supports the following special characters. It supports any amount of asterisks (\*) and only one question mark (?). - Regular Expression - Using standard regex for defining policies. - **Values** - You can search for a single value or a list of matching values. - **Mask Values (Regular Expression policy objects only)** - Masking portions of matched values collected as classification evidence on demand. There a maximum limit of 3 unmasked characters on all evidence snippets. The original value of masked characters is discarded, is nor persistent and cannot be inferred from the evidence masked value. - Display the first characters — number of characters from the left displayed in the matched value. - Display the last characters — number of characters from the right displayed in the matched value. - **Verification Algorithm** - A code based algorithm to enable more complex filtering. See [Data Classification Verification Algorithms](https://documentation.sailpoint.com/das/help/data_class/dc_algorithms.md) for further details. Policy objects are a good way to reuse searches containing complex definitions. ### Classification Types **Regular Expressions Within Policy Objects** Regular expressions form the basis for many content pattern searches. Data Access Security uses the .net regular expression engine as its underlying engine for regular expressions searches. All regular-expression definitions and searches must conform to the engine’s restrictions, limitations, and standards. When selecting a policy object of type Regular Expression, Admins and Compliance Managers have the ability to provide additional information and settings to the policy object and search criteria. **Verification Algorithm** - A standard, out of the box example, is the Luhn verification algorithm. This algorithm ensures that all phrases classified as credit cards are, indeed, valid credit card numbers (as far as an algorithm can validate without contacting the bank, of course). When selected, this verification will only be run on strings that conform with the credit card regular expression entered, for example: “^3[47][0-9]{13}$” See [Data Classification Verification Algorithms](#data-classification-verification-algorithms) for a full description on creating verification algorithms. **Mask Values** - By default, the regular-expression matches are saved as part of the results. It is recommended to mask the values of the matches to avoid exposing critical data. **Regex Matching and Case** Please note that regex matching is case sensitive by default. To make a regex ignore case, use the prefix “(?!)” For example: “home” will find “home”, but ignore “Home” The regex “(?!)home” will find “Home”, “HOME” and “HoMe” **Identifying Line Breaks using Regex** For parsed files, line breaks are represented by a single CR (\\r), instead of (\\r\\n) or (\\n), and therefore not identified by the regex line boundaries ^ and $. ## Data Classification Verification Algorithms Verification algorithms add a secondary validation step to Regular Expression policy objects in Data Classification. After the regular expression identifies potential matches, the selected algorithm evaluates each matched string and excludes results that do not meet its validation criteria. Data Access Security comes with a set of verification algorithms for standard verifications, such as Luhn, for credit card numbers or SSN algorithms. ### Verification Algorithm Verification algorithms for common rules: - Luhn (Credit Card Number) - US SSN - Netherlands BSN - Israeli ID - IBAN - South African ID The dropdown list of verification algorithms is located under **Compliance > Data Classification > Policy Objects** in the Create Policy Object overlay when the Regular Expression type is selected. # Data Classification Policies Data classification policies are the top-level “container” of data classification rules which allows administrators to determine what type of data should be classified. Creating a data classification policy involves defining several policy details and setting the containing classification rules and data categories. Existing policies can serve as templates or baselines, allowing you to customize and expand them to create new policies tailored to your specific needs. You can also create your own policies from scratch, using existing building blocks, or creating new ones. See [Policy Rules](https://documentation.sailpoint.com/das/help/data_class/create_rule_types.html) and [Policy Objects](https://documentation.sailpoint.com/das/help/data_class/components.html#policy-objects) for more information. ## Policy Management To view an existing data classification policy, go to **Compliance > Data Classification > Policies**. This page allows you to create, edit, duplicate, and delete various data classification policies. All of the created policies are listed along with their descriptions, the owner who created the policy, the number of classification rules and data categories involved in / contained in / comprising of the policy, and if the policy is active or not. Inactive policies will not be included in the classification scans and won’t be used to classify data. ### Filter Through Existing Policies To search for a specific policy, complete the following: 1. Navigate to **Compliance > Data Classification > Policies**. 1. Select the Filters icon at the right of the screen and provide any of the following information to better your search. - Name – search for policies by full or partial name - Owner – use the dropdown to search for policies created by specific individuals or users - Status – use the dropdown to search for active or inactive policies - Show user define policies only – toggle this to view to filter out any preset policies that are delivered out of the box. This allows you to focus on the ones created by your organization ### Policy Management Actions Each policy has a set of actions the user can perform. - Edit - edits the details and contents of the policy - Delete - deletes the policy. Deleting the policy will not delete the classification rules that are contained within the policy with the exception of [global rules](https://documentation.sailpoint.com/das/help/data_class/global_rules.html). - Duplicate – duplicates the policy. Duplicating the policy does not duplicate the containing rules with the exception of [global rules](https://documentation.sailpoint.com/das/help/data_class/global_rules.html). ## Global Options This dropdown provides additional action options, including performing classification tasks on specific resources, managing classification categories and file properties, and adjusting the policies scope. ### Run Resource Classification For more information on how to run a data classification process on a business resource, see [run a resource classification](https://documentation.sailpoint.com/das/help/data_class/resource_class.html). ### Manage Categories For more information on how to use a data category, see [Data Categories](https://documentation.sailpoint.com/das/help/data_class/components.html). ### Policy Scope For more information on how to define a policy scope, see [Policy Scope](https://documentation.sailpoint.com/das/help/data_class/app_policy_scope.html). ## Policy Creation To create a new data classification policy, navigate to **Compliance > Data Classification > Policies > Create New**. When creating a new data classification policy, you need to provide the details defining the policies and set the classification rules and data categories that will be used by the policy during classification tasks execution. ### Policy Details On the first step of the policy creation, provide the following information: - Policy Name - Name of the data classification policy - Policy Description - Details about the policy - Active toggle - by default a policy will be active once it’s created. Toggle this to inactive if the policy should be inactive at creation. Users can add existing rules or create a new rule for a policy. ### Policy Composition Data Classification policies are made up of rules which are used to evaluate the content of files or metadata and apply categories to those classified files. 1. To add a rule to this policy, either search for an existing one by using the dropdown or by typing in the field. You can also select **Create New** to [create a new rule](https://documentation.sailpoint.com/das/help/data_class/create_rule_types.html). All assigned rules to this policy will be listed under Assigned Rules. 1. If this policy needs to have a global rule, toggle [Global Rule](https://documentation.sailpoint.com/das/help/data_class/global_rules.html) to active. 1. Once all rules have been assigned, select **Done**. The newly created policy appears in the policy list. # Data Classification Rules The following provides information on how to create a content-based and composite type rule. ## Content-Based Rules A content-based classification rule specifies file attributes as well as data patterns within the files that fit a particular type of data. For example, credit card numbers, driver's license numbers, or text files created last month by user `X@domain.com`. Each such rule is associated with a category. In the process of creating a content-based classification rule, Data Access Security performs an AND operation between each expression. However, some operators act as an internal OR (for example, the IN operator). To create a content-based rule, perform the following steps: 1. Navigate to **Compliance > Data Classification > Rules**. 1. Select **+ New Rule > Content-Based Rule**. A new content-based rule window displays. The available Content-Based Rule fields include: - **Rule Name** (mandatory field) - Rule names are unique. It is best to create a naming convention that avoids using the same name twice. - **Categories** - Enter one or more categories for the rule. To add a new category to the Categories list, select **Manage Categories** and add a new item. 1. Navigate to **Compliance > Data Classification > Rules > New Rule**. 1. In the Rule Criteria section, add the general details to the content-based classification rule. Users can search for existing rules using filters. Users can perform the following actions on rules: - Edit (only user-defined rules) - Duplicate - Delete (only user-defined rules) 1. Create an expression and select **Save**. Note Users can edit or delete existing rule criteria. 1. Add additional rule requirements as needed. 1. Select **Save** to save the new content-based rule. The system adds the rules to the Rules list. ## Composite Rules A composite classification rule lets you combine several rules together to form a more complex criterion. This can include content type rules, and is defined by category. - The data classification matches content patterns to rules and assign categories to resources according to these rules. - After running data classification, composite rules use a combination of categories to define complex combinations of simple rules. **Examples:** You can create a rule to list files that have at least two out of one list of categories and must contain another specific category. or Identify all resources that would be defined by rules that belong to category **X**. To define a composite classification rule, select one or more categories and the created rule will be triggered for any existing rules within the selected categories. The value column allows selecting one or more categories from the category repository. ### Triggering Composite Rules Composite rule tasks are triggered after each data classification task and evaluate results from that application only. The Composite rule runs after of all content rules as it is based on their results. This task cannot be scheduled. If you change a composite rule, this change will take effect only when a new classification task is executed and triggers the composite rule. ### Creating Composite Rules 1. Navigate to **Compliance > Data Classification > Rules**. 1. Select **+ New Rule > Composite Classification Rule**. The available Composite Classification Rule fields include: - **Rule Name** (mandatory field) - Rule names are unique. It is best to create a naming convention that avoids using the same name twice. - **Categories** - Enter one or more categories for the rule. To add a new category to the Categories list, select **Manage Categories** and add a new item. 1. In the Rule Criteria section, add the desired combination of categories to trigger the rule. **Operator** - Enter the number of concurrence of categories in the business resource tested for this criterion. For example, if you went the rule to collect Business Resources that fit both criteria C1 and C2, set the Operator to Contain at least 2 of Value: C1, C2. **Value** - Enter one or more categories from the search box. 1. Select **Save**. 1. Select **+ Add** to add another criterion. All criteria will be combined with an AND operator. 1. Select **Save** to save the new composite rule. 1. The system adds the rules to the Rules list. # Data Classification Results Data Access Security provides reports of data classification results. You can filter the results by various parameters, including a match count – having a certain critical category at either more than or less than a given threshold. To generate a data classification report, perform the following steps: 1. Navigate to **Reports > Report Templates**. 1. Use the Classified Data filter to locate a specific report. 1. To apply a different filter than one of the existing templates: 1. Create a duplicate template by selecting **Duplicate** from the template dropdown menu. 1. Set the filter parameters and select **Run Now** or **Save** the template for future runs. 1. The report will be available in the My Reports screen. Note Data Access Security can import data classification results using the Import Classification Result capability. This allows for results to be imported from a CSV file. ## Importing Data Classification Results Data Access Security has the ability to import external data classification results. In order to successfully import data classification results, verify an application name was created and that a resource full path exists in the application. A crawl task may need to be run to update the database. The selected CSV must have the following fields: - Application Name - Resource Full Path - Category Name - File Name - Match Count Important The CSV file you are uploading should be structured with these five fields as columns. If there are not five columns with the above fields, the import will not be successful. If the value within Application Name or Resource Full Path is incorrect, the import task will fail or finish with warnings. To import data classification results: 1. Navigate to **Compliance > Data Classification > Import Data Classification Results**. Note The import task imports the match count from the external source, in addition to the fields of the categories. The match count field is imported as a number. 1. Select **Run** to start the import task. 1. To follow the task progress, navigate to **Settings > Task Management > Tasks**. # Classification and Flow Architecture The Data Classification content analysis and data processing is performed by the Data Access Security Data Classification [Deploy-Anywhere collectors](https://documentation.sailpoint.com/das/help/getting_started/cluster_creation.html). These collectors are based on specialized virtual appliances that are deployed in customer environments, data centers, or a private virtual cloud, to ensure data is processed on the customer site. The Data Access Security central Data Classification engine identifies data locations eligible for scanning and sends directions to the specialized data collectors in the customer's environment. The collectors then traverse the data location to be scanned; read, process and analyze the content of the scanned files; classify and categorize content based on the relevant classification policies and rules, and send metadata-only results back to the central classification engine and their Data Access Security tenant. ## Data Classification Content Analysis Process The Data Classification Content Analysis Process is comprised of several steps that can execute concurrently and independently. These include: - Classification Policy Management and Evaluation - Running a Data Classification Content Analysis Task - Querying and Retrieving Results ## Classification Policy Management and Evaluation Data Access Security includes a variety of preset packaged classification policies and content classification rules. Additional rules and policies can be created and existing ones can be adjusted and customized at any point through the Data Access Security web user interface. Once a Data Classification Content Analysis tasks is issued for a specific application, the Data Classification engine leverages the most recent policy definition applicable to the scanned application. The relevant policy definition will persist through the duration of the content analysis and classification task. Any changes made to the policy definition after the content classification task has been started will not be reflected in the current classification process. Note Changes to classification policies will trigger a complete re-scan and analysis of the application data content in the subsequent data classification task. ## Data Classification Content Analysis Flow 1. The Data Access Security classification Engine identifies data assets and locations to be analyzed and classified. A data asset (Business Resource) will be selected for classification when the following conditions are met: 1. This is the first time the data asset is being analyzed and classified 1. The data asset has been updated or modified since the last time it was classified (changes are evaluated based on the Business Resource Last Modified Date attribute) 1. The Business Resource is included in the Classification Scope of the scanned application 1. There is at least one classification policy configured to include the scanned application in its classification policy scope 1. The Business Resource is not excluded from classification due to the de-duplication mechanism (see below) 1. If any changes were made to the classification policies, all Business Resources in scope will be queued for re-scan, analysis, and classification 1. The Central Classification Engine sends the information about data assets and locations to be scanned to the Classification Collectors. 1. The collectors retrieves the list of files to be scanned and analyzed in each business resource. 1. The Data Classification Data Collectors reads the content and metadata of each file. 1. The Data Classification Data Collectors evaluates the content of the files based on the classification policies and rules, classifies and categorizes the data content, and sends the metadata results of the classification to the Central Classification Engine to inform the customer tenant. Note If files are placed into cold storage but are also scoped within the crawl, data classification will rehydrate them. Data Access Security cannot gather sensitive information without directly accessing the file. To exclude these resources from data classification in order to avoid rehydration, go to to **Compliance > Data Classification > Application Scope > [select application] > Edit > Toggle Exclude from Classification > [select resources]**. ## Data Classification Deduplication Scan In various storage solutions and file share applications, it is possible for multiple access paths or share paths to point to the same physical location and data content. To minimize the running time of the Data Classification task, these duplicate access paths are identified and shared data is scanned only once. To maintain ease of use and user readability, when a user reviews the classification results through reports, insights, or the Data Classification Forensics page, classification results will reflect all access paths including duplicate access and share paths. # Global Rules Global Rules are policy-level classifications, designed to enable complex searches for advanced classification scenarios. They allow Compliance Managers and users to define content classifications criteria that span across multiple data points and categorizes or labels files only when they span multiple data dimensions and satisfy multiple rules. Thus, Global Rules allow Compliance Managers to apply more sophisticated policies to classify their data more accurately, get more targeted results, and reduce compliance clutter. By supporting adjustable thresholds for classifications, Global Rules give compliance professionals the flexibility and agility they need to tailor their compliance suites to the needs of their organization, their internal criteria, and regulatory requirements. Note Policies can only contain one Global Rule. Note Users are able to add and adjust Global Rules to all user-created policies. Note Adding or removing Global Rules from SailPoint delivered, out of the box, policies is possible. ## Creating a Global Rule To create a Global rule within a user-defined policy, perform the following steps: 1. Navigate to **Compliance > Data Classification > Policies** to open the rules page. 1. Select **+ New Policy**. The available policy fields are: - **Policy Name** - Policy names are unique. It is best to create a naming convention that avoids using the same name twice. - **Activate/Deactivate Policy** - Users can activate or deactivate a policy using this button. - **Owner** - The logged in user is the creator of the policy. (This field is read-only.) - **Description** - Users can provide descriptions to the policies they create to better explain what the policy is meant for and designed to do. You can use this description to describe the logic of your Global rules, as well for additional readability. Note To add a Global rule to a policy, a user must first add at least one Content rule. This can be done by either adding a new rule or by adding a pre-existing rule using the Search option. We recommend adding Global rules at the end after the Content rules have been added. Note Global rule settings are enabled once Content rules have been added. 1. After adding at least one Content rule, select **New Global Rule**. Provide the following information: - **Rule Name** - Unique name for the Global rule - **Categories** - The resource will be classified by the Categories when the rule is satisfied 1. For the Rule Criteria, add the type of categories in the Value field. The dropdown will provide a list of only the categories that are set by the content rules defined within the policy. Creating rule criteria allows you to set a condition that will be satisfied when a set of categories are applied. 1. Select **Save** within the Rule Criteria block. 1. Either add another set of rule criteria or select **Save** to save the new Global rule. ## Global Rule Options Within the Policy screen, a user can either Edit or Remove a Global Rule from the policy. Select the hamburger menu within the Global rule to see these options. - **Edit** - all options can be edited - **Remove** - the Global rule will be removed from the policy Note Global rules cannot be created or removed from out of the box policies. They can only be edited. Caution If you remove a Global rule from a policy, you cannot add it back. I new Global rule will have to be created and added to the policy. ### Global Rule - Rules Screen By navigating to the Rules screen (**Compliance > Rules**), a user can see all of the various rules including global rules that have been created. These rules will also state what type of rule they are. From the Rules screen, Global Rules can only be deleted (with the exception of OOTB global rules). You cannot edit a Global Rule from this screen. Note If a Global Rule is deleted from the Rules screen, it will automatically be deleted from any corresponding policy. Next to the hamburger menu is a downward arrow. A user can select this arrow to view details, such as categories and criteria, about the Global Rule. ## Filter 1. To view only Global Rules, select the Filter icon. 1. In the Type dropdown, select Global Rules. # Optical Character Recognition Data Access Security can identify text in image files either directly or embedded in other files – such as a scanned documents or a collection of scans stored in a zip file. Note Files less than 1000 pixels across will not be scanned to avoid less reliable results from low resolution images. To enable Optical Character Recognition, following the steps when [editing an application scope](https://documentation.sailpoint.com/das/help/data_class/app_policy_scope.html#editing-the-application-scope). This feature is disabled by default. Note The optical character recognition process is resource intensive and should be configured carefully. # Re-Scan Scenarios Any Data Classification policy change will cause all data assets within the classification task scope to be re-scanned, analyzed, and classified, but the subsequent classification task. In most cases, classification policies will see minimal updates and modification after the initial implementation and testing phases are completed. To minimize the amount of forced re-scans and optimize performance, Data Access Security provides several different capabilities to limit the scope of classification tasks and to expedite scans and enable testing policy changes faster, such as Scoping and [Run a Specific Resource Classification](https://documentation.sailpoint.com/das/help/data_class/resource_class.html) task. # Run a Resource Classification The Data Classification process can be run on a specific business resource, rather than on an entire application. You can test the Data Classification process faster, since you will only be testing a single resource. In addition, you can run Data Classification faster on a single critical resource (for example, one on which many changes were made), than on multiple resources. To run Resource Classification on a rule, perform the following step: Navigate to **Compliance > Data Classification > Policies or Rules > Actions > Run Resource Classification**. To run Resource Classification on a policy, perform the following step: Navigate to **Compliance > Data Classification > Policies or Rules > Global Options > Run Resource Classification**. # Supported Applications and File Types The following provides information about applications and file types that Data Classification supports. ## Supported Applications Data Classification supports numerous applications which can be found [here](https://documentation.sailpoint.com/das-connectors/help/connector_matrix.html). ## Supported File Types Data Access Security Classification analyzes data based on files content, attributes and metadata. It supports file properties (attributes) and custom properties (attributes), as part of its metadata analysis, for all supported file types. Image files can be scanned, analyzed, and classified using an optical character recognition (OCR) capability. Since OCR-based analysis is a resource-intensive operation, which can impact scan performance, it is recommended to enable it only when needed and on a limited scope. Refer to [Optical Character Recognition](https://documentation.sailpoint.com/das/help/data_class/ocr.html) for more information. The Data Classification engine supports the following file types/extensions: | File Extension | Expected File Type | | -------------------------------------------------- | --------------------------------------------------- | | docx, doc, xls, xlsx, ppt, pptx | Microsoft Office Files | | txt, csv | Plain Text (including Comma Separated Values files) | | htm, html, xml | Web files | | cs, js, sql | Code script files | | pdf | Adobe | | zip, gzip, tar, rar, 7zip | Archive files | | bmp, emf, gif, jpeg, jpg, pdf, tif, tiff, png, wmf | Image files analyzed by the OCR module\* | # Data Access Security Text Search Data Access Security Data Classification Collectors leverage Lucene as its primary text-based optimized search and analysis. The Lucene engine provides term-based search capabilities, based on the textual content extracted and analyzed from scanned files. To extract textual content from various file types and formats, the Data Access Security Data Classification Data Collectors uses a proprietary text extraction library, which is able to extract the file content based on its type. Based on the extracted content, the Lucene engine parses and analyzes file content into searchable terms. The full content of the file itself is discarded and is never persisted. All textual evaluations are done in memory on highly efficient textual analytics structures, optimized for term and phrase-based textual searches. When Data Access Security evaluates the scanned and analyzed content based on the classification policies and rules, it parses and translates the various policy rules into term-based search queries. Query results representing files that correspond to the rules’ requirements, consist of file names, extensions, and full path locations, along with other attributes. In certain cases, results may include a masked text snippet to serve as evidence to orient admins and stakeholders reviewing the results. Strict masking requirements apply to all evidence snippets. **Regular-Expressions** Regular-expression-based rules involves matching regular-expression patterns with a file during the process of reading the file content and not comparing the pattern with a term-based index. **Lucene's Analysis Process** While it parses and analyzes the content data, the Lucene analyzer eliminates white spaces, certain punctuation characters, and “stop-words” from the content. Stop-words are a predetermined set of frequently used words with diminished semantic significance, such as pronouns and prepositions. Lucene filters stop-words to keep the analysis manageable, to eliminate “white noise,” and to improve search heuristics. Lucene analyzes and tokenizes file content into searchable terms based on the white spaces and stop-words omitted from the original text. The tokenizing algorithm affects Data Classification policy rules. **Multi-term Phrase-Based Rules** The Data Classification process allows both single-term keyword searches and multi-term phrase searches. Lucene omits any “stop-word” contained in a multi-term search phrase. For example, a rule containing the phrase “It was the best of times, it was the worst of times,” will classify the file containing the entire sentence, as well as any file containing a contiguous phrase, such as “best times worst times.” To avoid possible false-positive classification, it is best to restrict multi-term phrase searches to meaningful, contiguous terms. ## Chinese and Logogrammatic Languages Some scripts, such as Chinese, represent words by symbols (logograms) and a single word may consist of one or more logograms. Furthermore, while most languages use white spaces to separate words, Chinese, as well as other logogrammatic scripts, often do not separate words by spaces. The combination of these two phenomena, along with Lucene’s omission of white spaces, will cause phrase searches in Chinese (with multiple logograms, separated by spaces) to return positive matches for files containing the same sequence of logograms, regardless of the spaces between them. Thus, a rule containing the phrase “莦 莚 虙贄 蹝 轈”, will classify files containing phrases that consist of these logograms, regardless of spaces. Therefore, the phrases “莦莚虙贄蹝轈,” “莦莚虙贄蹝轈”or “莦莚 虙贄 蹝轈”,and “莦 莚 虙贄 蹝 轈,” will all be classified by the rule defined above. However, single term keyword searches of words consisting of multiple logograms, and phrases not separated by spaces, will return correct, exact match results: a rule containing the term “莦莚虙” will only classify files containing that exact term. If more complex phrases are required, a rule containing multiple phrases with the “Contains All” operator will give the desired results. # Data Ownership Election Data Access Security Ownership Election Campaigns introduce an automated election process to identify and assign data owners to business data assets based on data usage patterns. These campaigns help security administrators identify, elect, and assign data owners from business stakeholders, enabling a distributed approach to data governance. This ensures that decision-makers are the ones closest and most familiar with both the data and business needs. Once Administrators define the parameters for Data Ownership Election Campaigns, the Data Access Security Data Ownership Election engine analyzes user activities from the last 180 days on the selected data assets. This identifies the top contributors that would be the most likely candidates to assume ownership of the data. Data Access Security ranks the top active users based on the type of activities they performed on the data, giving higher scores to those who produce and manage content. Automated election campaigns invite the larger user audience to cast their votes in electing the right owners from among the candidates or suggest addition candidates to be considered. Election results can be reviewed by designated reviewers before being automatically or manually assigned to the data assets themselves. Reviewers can approve or reject the elected owners, and / or assign additional owners they see fit according to company policy. Assigned data owners automatically get notified and receive an invitation to assume their ownership duties and log into Data Access Security. ## Data Election Flow Complete a data election ownership campaign by using the following steps: - [Create a campaign](https://documentation.sailpoint.com/das/help/data_ownership/campaign_creation.html) which includes setting the campaign parameters, reviewers, and defining the campaign’s scope. - Data Access Security identifies the ideal candidates for each resource and initiates crowd source campaigns among the most active business users to vote on who should be elected as a data owners. - Voters [cast votes](https://documentation.sailpoint.com/das/help/data_ownership/voting.html) on candidates. - [Review](https://documentation.sailpoint.com/das/help/data_ownership/reviewing.html) the election results. Once the election is done, reviewers are tasked with reviewing and approving the elected owners. - If the campaign was configured to automatically assign data owners upon completion, the elected and approved owners will be assigned as data owners. # Creating a Data Election Ownership Campaign To create a new campaign, go to **Governance > Owner Election > Campaign Management** and select **Create New**. When creating a new campaign, you need to provide details about the desired campaign. ## General Details On the first step of the campaign creation, provide the following information: - **Campaign Name** – Mandatory. Name of the campaign. - **Description** - Details about the campaign. - **Data Owner Assignment** - Select if elected owners will be automatically or manually assigned to business resources at the end of the campaign. - **Assign Election Reviewers** - Toggle this on if you want to assign reviewers to approve or adjust the election results. If reviewers are not set, the top candidates (1st and 2nd place based on the election results) are automatically assigned to the resource as the data owners. Note If Assign Election Reviewers was toggled to enable reviews, a new field appears allowing administrators to search and assign reviewers for the election campaign. Search for identities to assign as reviewers. Selecting identities is mandatory if toggled on. Select **Next**. ## Define Scope The Define Scope page allows administrators creating the campaigns to determine what resources are going to be included in the data ownership election campaign. These are the resources the campaign is going to facilitate electing data owners for. - **Application Type** - Select the type of application the campaign is centered around. - **Application** - Select the specific application. - **Resource Scope** - When setting the scope for the campaign, you have the option to select specific resources from one of three groups: - **All Resources** - Allows you to select specific resources within the chosen applications and assign owners to them. - **Top-level Resources** - Top-level roots of the application hierarchy. These often serve distinct business unit or projects, and often the level you would want to set data owners on. - **Resources with Unique or Modified Permissions** - All resources that have unique or modified permissions compared to the parent folder. These resources represent a fork in the permission inheritance model and often represent a demarcation point that serves a different business purpose where a new data owner might be required. - **Resources** - list of resources based on the previous field selection. Multiple resources can be selected. Select **Next**. ## Summary On the summary page, review all the campaign settings you have chosen. Here, you can use the **Send Invitation** toggle to activate sending invitations, which is on by default. You can also send out a reminder about the campaign. The reminder option is on by default. Reminders cannot be edited. They are sent out weekly on Mondays at 5:00 AM UTC. Select either **Save** or **Save and Run**. If Save is chosen, the campaign will not be started. # Campaign Management To view an existing campaign or create a new one, go to **Governance > Owner Election > Campaign Management**. Note This page is only available to users with the Data Access Security Administrator user level which is set within SailPoint Human Fabric. All of the created campaigns are listed along with their assigned reviewers, the application and application type the campaigns are scoped to run on, the start and end date, the assignment type, and the status and progress of the campaign. Campaigns can be in one of the following statuses: - **Created** - The campaign has been created but has not been started. Candidates and voters have not yet been identified and invites were not sent. - **In Progress** - The campaign has been started but is still in progress. - **Completed** - The campaign has been completed. All elections, reviews, and assignments for all resources are complete. - **Pending Cancel** - The admin issued a cancel command and the the campaign is in the process of being cancelled. All pending work is cleared. - **Cancelled** - The campaign was cancelled. - **Failed** – An unexpected technical issue occurred. ## Filtering Campaigns There are three ways to search for a particular campaign. You can use the predefined filter options (Active or All), search campaigns by name using the search bar, or use the filter icon to search for a campaign based on the campaign details. If viewing the Active filter (selected by default), all campaigns that are in either the Created, In Progress, or Pending Cancel state display. If you select the filter icon, a filter overlay appears with the following filters: - **Status** - Select any of the above mentioned statuses to search for a campaign. - **Reviewer** - Search for campaigns that a specific person (or multiple people) is set to review. - **Assignment** - Search for a campaign that is set to automatically assign the data owners when the campaign ends or if a manual assignment is required. - **Application Type** – Search for a campaign that is scoped for the selected application type. - **Application** – Search for a campaign that is scoped for the selected application. - **Start Date** – Search for campaigns based on their start date. You can search by: - Equals - Searches by an exact date. - Last X Days - Searches for campaigns that started within the last provided number of days. - Between - Searches for campaigns that started between two dates provided by the user. - **Progress** - Search for a campaign whose progress is within a certain range. Select either Lower than or Greater than. A percentage field displays where a percentage needs to be provided. ## Campaign Management Actions Each campaign listed has a set of actions the administrator can perform. - **View Details** - Provides more details about the campaign. - **Edit Campaign** – Only available for campaigns that have been created. Opens the campaign wizard where edits can be made. - **Run Now** – Only available for created campaigns. Starts the campaign. - **Cancel Campaign** - Cancels the campaign but does not delete it. - **Refresh** – Refreshes the campaign data. - **Restart Campaign** - Starts the campaign from the beginning and changes the status back to In Progress. Restarting a campaign is only available on campaigns with the Failed, In Progress, or Cancelled status. - **Delete Campaign** – Cancels and deletes a campaign. The deleted campaign will not be displayed and this cannot be undone. # Managing Campaigns From the [Campaign Management](https://documentation.sailpoint.com/das/help/data_ownership/campaign_management.html) page, Administrators can select a specific campaign in order to view the progress of every resource in that campaign, see the current state of the voting results, send reminders, end the election, etc. Note If a campaign is in the Created status, the campaign has not yet been started and its management operation is currently disabled. You can only start or edit campaigns in the “Created” status. Once started, the campaign administration options are be enabled. Once a campaign is selected, details appear in a new screen. To the left, the resources within this campaign are listed. You can use the drop-down to narrow down the resources that are shown, or search for a specific resource in the search field. Resources that are listed show a status (In Election, In Review, Completed) of where they are at in the campaign cycle. Select a resource from the **Campaign Resources** window to view the current election results of the resource. Once a resource is selected, three tabs appear above the main grid: - Election Results - Voter Activity - Review and Assignment At the top of the page is the **View Summary** and **Campaign Actions** buttons. Select **View Summary** to view more detailed information about this campaign. Select **Campaign Actions** to do one of the following: - Reassign Reviewers - Send Reminders If reassigning reviewers, a new window appears with a search field. Choose the desired reviewers and select **Save**. The newly selected reviewers replace the previously existing ones. Note If a campaign has been created without reviewers, the Reassign Reviewers option is not available. If sending reminders, a reminder is sent to all voters or reviewers who have pending tasks. The option to end the election is also at the top right of the table. Select **End Election** to complete the election phase of the selected resource. End the election when enough votes have been captured or when you need to move the resource election process to the next phase. Elections automatically end when all voters cast their votes. Once the election phase has ended, the campaign passes onto the next phase. If reviewers were set, the resource moves to the review phase, followed by the assignment phase, before reaching completion. Note Ending an election is only available when a resource is in the In Election phase. ## Election Results Tab The Election Results tab provides a ranking of each identity along with their job title, manager, and department, as well as the reason they are included in the campaign. Candidates are included in the campaign if they were identified by Data Access Security as top active users, if they were nominated by a voter as a potential candidate, or if they were added by a reviewer as an owner as part of the review process. The Total Votes column shows the number of votes and percentage of voters who have voted for that candidate. ## Voter Activity Tab This tab presents the top 20 most active users along with their organizational information. The Action column provides the option to remind a voter that they still need to cast their vote. If a voter has already voted, this button is disabled. All options that are available in the [Election Results](#election-results-tab) tab are also available in the Voter Activity tab. ## Review and Assignment Tab If the selected resource is in the Complete status, the Review and Assignment tab becomes active. A new Approved column appears in the grid and provides a list of users who were approved or rejected by the reviewers to be assigned as Data Owners. # Reviewing a Data Ownership Campaign Campaign reviewers are able to review the results of each resource within the campaign, approve or reject candidates that were voted on, or propose new data owners. Note Detail about the campaign can be viewed by selecting **View Details** at the top right of the page. 1. To make a review of a campaign, go to **My Tasks > Data Ownership > Election Review**. 1. Active campaigns that are assigned to the user are listed with their relevant information. Select the campaign you would like to review. The left pane titled Campaign Resources lists all resources within this election that are either complete or in review. Once a resource is selected, the reviewer can see the results of the campaigns elections, as well as an indication for the first and second top voted candidates. They are the recommended assignments. The reviewer can also see each candidate's information and the reason for their nomination. 1. A reviewer can either approve or reject the election results. Approved results will be assigned as data owners. Alternatively, they can override the decision. To deselect the previously chosen candidate, select the blue **Select** button. 1. To override chosen candidate, select **Override**. Search for a new identity and select **Save**. The new identity is added to the top of the list and is automatically selected as a data owner. As a reviewer, comments can also be left on each identity as a way of explaining why a candidate was approved or rejected. 1. Once your review is complete and all of the desired candidates are selected, select **Commit**. Once a resource has been reviewed and commits have been made, the newly selected data owners are now assigned as data owners to that resource. # Voting for Data Owner Candidates As a voter on a data ownership election campaign, you are able to cast your vote on one or more candidates to become the data owner on the campaigned resource. In addition, a voter can propose a new candidate who will be added to the candidates list or skip voting altogether if the voter doesn't know who should be responsible for the resource. 1. To view all active campaigns and to cast your vote, go to **My Tasks > Data Ownership > Owner Election**. On this screen you see all data ownership campaigns that the user is assigned and that are still in progress, as well as their relevant information like the date the campaign started, the application the resources belong to, and the progress of each campaign. You can search for a specific campaign by using the search field at the top of the table or by selecting the filters icon. If searching for a campaign using filters, you can refine your search by the following parameters: - Application Type - Application - Start Date 1. When a parameter has been set, select **Apply**. 1. To cast a vote on a campaign, select the campaign that needs to be voted on. The left pane titled Campaign Resources lists all resources within this election. The main table provides details about each candidate so that an informed decision can be made. Note Candidates are ranked and ordered by Data Access Security based on their access activity on the particular resource. Ranking is based on both the number of actions they perform, as well as the types of operations they perform, where content producing activities are scored higher than content consuming activities. The candidates are ordered based on this computed rank, where the first candidate is the highest ranking one, making them the most likely ownership candidate. 1. To cast a vote for a candidate that is listed, select the **Select** button on the appropriate row. Note More than one candidate can be selected. 1. If you would like to nominate another candidate that is not listed, select the **Nominate Another Candidate** button at the top of the table. 1. From the **Select an Identity** field, search for the identity you want to nominate. Once the identity is selected, select **Save**. The newly nominated candidate is added to the bottom of the candidate list and is also automatically selected. If a voter deselects a candidate they nominated, that candidate is not included in the campaign and other voters are not able to vote for the nominee. 1. Once all desired candidates have been selected, select **Commit Vote**. Note Once Commit Vote is selected, the next resource in this campaign displays so that decisions can be made on it. If the voter does not want to cast a vote on a particular resource, they can select **Skip and Commit**. If a user wants to start the voting process over, select **Clear Selection**. # Forensics Forensics allow the administrators to view Data Access Security service data analyses. The tables can be filtered to fit specific needs and filters can be saved and shared with other users as well. The following are the types of forensics: - Permissions forensics - Identities forensics - Data Classification forensics Forensic queries can be used to answer questions such as: - Who has access to files classified as credit cards? - Who can access folders classified as SSN? - Are there users without a password in the system or users who haven’t logged in for the past six months? # Activity Forensics The purpose of the activity forensics page is to control and monitor access to sensitive data at the user level, across multiple applications. Administrators and Data Owners can monitor and control identities and external users accessing sensitive resources. This ensures visibility, transparency, and accountability in data governance practices. Administrators and Data Owners can [filter activities](#searching-for-an-activity) based on multiple attributes to enhance investigations, set a specific investigation period, and obtain more details on the event card for a specific activity. Administrators and Data Owners can also generate ad hoc or scheduled [reports](#global-options) with flexible filtering for any type of activity to be automatically saved according to a set schedule. ## Activity Monitoring Capabilities Data Access Security Activity Monitoring enables Administrators and Data Owners to gain the following visibility into data access activities: - Capabilities to capture, track, and analyze activities taking place on data assets and allow detection on unusual identity activity. - Captures and analyzes activities on data assets six months from the moment activity took place, getting a real time or historical snapshot. - Enriches information about the actors and their activities with Identity Attributes, providing more context about “who” acted. - Enriches resource information that are objects to the activity with Data Classification Engine categories, rules, and policies. - Provides visibility on activities that are not known to SailPoint Human Fabric users. - Enables activity log on demand for a customized retention period (up to 7 years) with automatic deletion afterward. ## Using Activity Forensics To view activities, go to **Forensics > Activity**. The user is presented with a list of various activities. By selecting one of the time stamps, you can view details about each activity like the date and time of the action and who performed it, the type of action they performed on the object, the name of the resource, the location of the resource, and more. Note Activities are available for up to 12 months. At the 12 month threshold, activity events are moved to offline storage. The data retention configuration defines the length of time the activity data is stored offline. This data can be made accessible by a support ticket. By default, the data displayed includes the following columns for each activity: - Action Time - User Name - Object Name - Action Type - Resource Path - Data Classification Policies - Identity Department ## Searching for an Activity There are a couple of ways to find certain activities. You can use the Filter function to locate an activity. Using the dropdowns, provide the desired parameters of the filter to perform the search. From that filter, you can save it for future use by selecting **Save** on the filters row and also the save button next to the Filters button. When a filter is saved, it then becomes a query. When a query is created, an overlay appears with fields that need information. Provide a name for the query and if you want to share it with anyone, search for that specific identity. When the information is provided, select **Save**. To view any saved queries, select **Saved Queries** at the top right of the screen. From here you can view three types of saved queries: - Recent - queries that have been recently used but are not saved. - Saved - queries that have been saved. - Shared - queries that have been shared with others. Another way to find activities is to select the Time Frame dropdown to look for activities within a certain time frame. If selecting Advanced Options, you are able to fine tune your search by being able to select date and time ranges. ## Viewing Activity Details To view more details about an activity from the activities list, select the desired activity timestamp and an Activity Details overlay displays. Viewing more details on a particular activity gives the user insight into what type of event took place (read, write, etc.) and who performed that event. In Activity Details, there are three tabs the user can choose from to find information. - Actor tab – data about the identity who performed the action. This data is enriched from SailPoint Human Fabric. - Object Details tab - all details about the object itself. - Advanced Properties tab - displays information that is dependent on the action type that was performed. This set of information shows the old and new information, if it is applicable. For example, if a resource was moved, this tab shows the old and new resource path. Select **Close** to go back to the main Activity Forensics page. ## Global Options There are two global options that can be performed on the Activity Forensics page. - Generate Report – This generates a report based off of a query. This report is available in **Reports > My Reports**. - Schedule Report Template – This creates a report template with a schedule to generate the report. The report template can be seen in **Reports > Report Templates**. Refer to Data Access Security [Reports](https://documentation.sailpoint.com/das/help/reports/index.html) for more information. # Data Classification Forensics The Data Classification Forensics screen can be found by navigating to **Forensics > Data Classification**. It displays data classification results based on your active policies. Use filters to focus on specific data. You can sort the results by Match Count. The returned records are limited to 10,000 results. Note The Data Classification Results table shows results of the data classification process running in Data Access Security, as well as any data classification results imported from an external source, using the Import Data Classification Results feature. This might lead to duplicate entries from the two sources. ## Reports Data Classification reports can be found in the report templates by using the Classified Data tag to locate relevant reports. ## Using the Data Classification Forensics Table Change one or more of the default columns by clicking **Display Columns** and selecting one or more from the dropdown menu. Currently, all columns display, including the following: **Application** - Displays all the system applications. **Application Type** - Displays all the system application types. **Last Updated** - Timestamp of the last classification process in which the file was classified into the specified category. **Result Type** - Source of the classification result (Content or Imported Classification). Select a result type from the Result Type dropdown menu. Note The default column headings from left to right, are: Resource Full Path, File Name, Policy Name, Rule Name, Categories, and Match Count. You can clear any selections made in the Policy, Rule, and Category search fields by clicking **Clear Selection** on the top right of each field. **All** - All possible result types. **Composite Classification** - Results from composite rules (combining the results of several classifications). **Content** - Only results from content rules. **Imported** - Results from a Data Loss Prevention (DLP) product that has already scanned the results to control what data end users can transfer, so there is no need to rescan those results. 1. Type a number in both the Match Count (greater than) and the Match Count (less than) fields to restrict the number of Regular Expression (Regex, the general standard for textual search) results. Note Users can see the resources according to the user scope they have. A result record represents the classification of a certain file by either file, rule and policy. A single file can be classified into multiple rules/policies, resulting in a separate record in the result for each file-to-rule-to-policy relation. The result record consists of default columns which can be changed, based on the users’ requirements: **Resource Full Path** - The full path of the resource in which the file resides. **File Name** - The name of the classified file. **Policy Name** - The name of the policy by which the file is classified. **Rule Name** - The name of the rule by which the file is classified. **Category** - The classification category name used by the rule. Note If the rule result is part of a policy with an active global rule, the global category will also be displayed along with the rule category, as long as it matches the global rule threshold. **Match Count** - This is the maximum number of matches under any rules requirements contained in the file. This is not an aggregative figure and does not sum up the number of matches in each of the rule requirements for the file. Instead, it represents the highest match count yielded by any of the rule requirements and should be viewed as a sensitivity score attributed to the file, in accordance with the applicable policy rules. For example, if a policy rule contains two rule requirements – one matching credit card number with ten occurrences of credit card numbers within the same file, and another matching telephone number with eight occurrences of telephone numbers within the same file, the Match Count value of the file for that category (assigned by the rule) would be 10 (rather than 18, or 8), since it represents the maximum number of occurrences matching any of the rule requirements within that policy rule. When the result displays a regular expression search, this field is clickable and displays the masked matches of the regular expression. Note The query retrieves the first 10,000 results. Narrow the search to obtain a better fit. ## Viewing Critical Data Impact Score is integrated into SailPoint Human Fabric and is calculated by combining the perceived criticality of the data it grants access to with the number of instances of that data type. The Impact Score for an entitlement can be found on the Certifications page within the SailPoint Human Fabric Entitlement tab. The Impact Score can be High, Medium, or Low. View more information on [Impact Score](https://documentation.sailpoint.com/saas/user-help/certs/reviewing/index.html#viewing-critical-data) in the SailPoint Human Fabric documentation. ## Filter Complete the following steps to filter data classification forensics: 1. Select the **Filters** button at the top right of the screen. 1. The filter screen displays. The forensics results can be filtered by the following: - Policy Name - Category - Rule - Result Type (All, Content, Behavior, Imported) - Match Count (bigger than/smaller than) - Filter by Scope - Select a scope type (Application type, Application, or Resource) from the Scope Type dropdown menu. - Select a corresponding resource from the Resources dropdown menu. You can clear a selection from this dropdown menu by selecting **Clear Selection** on the top right of the menu. - Select **Reset** at the bottom left of the filtering screen to apply all the selected filters. # Filters - Creating and Editing Forensics Query A query is a collection of one or more filters that let you select from a list of parameters to select user types, permissions, user scenarios or permission scenarios to analyze. Note When searching for queries using the search bar, the results that are returned will only match words that start with the search term. Example: When typing "ser", that will match results like "server". It will not display results like "users". 1. Select **Clear All** to clear the current filters and to clear the grid. 1. Select **+** to add a filter to the query. 1. Select a field to filter by from the **Select Field** dropdown menu and the filter criteria, according to the filed type and parameters. 1. Select **Save** to add the filter line to the query or **Cancel** to start over. 1. Add more filter lines by repeating these steps as required. For example: "Last login date older than 100 days and Password not required equals True” 1. Select **Apply** to run the query. Note For Permission Forensics, the data retrieved depends on the user scope of the user running the query. The data returned will only be within the applications and resources within each application the user has access to. Note A query can be deleted only by the user who created it. ## Search for Resources Using a Resource Tree Add resources for the filter by navigating down the resource tree and selecting the requested branch. 1. Open a new filter line. 1. Select **Resource** from the **Select Field** dropdown list. 1. Open the **Select Resource** dropdown menu to view the resource tree. ## Save a Query 1. Select **Save**. That will open a popup screen to enter the query name. 1. Select **Save** or **Cancel** to continue. ## Retrieve a Saved Query Note If you select a saved query, the contents of your current query will be overwritten. 1. Select **Saved Queries**. 1. Select a query from one of the saved query lists: 1. Recent – a list of your recently used queries. These queries are named and ordered by the timestamp. 1. Saved – a list of queries saved by the user. 1. Shared – a list of queries shared with the user. Clicking on a query loads the filters and displayed columns for the query. A query object cannot be edited and changes made after loading a query do not impact the loaded query object. However, these changes can be saved in a new query. ## Share a Query Sharing a query makes it available in the query list for other users. 1. Create a query as described above. 1. Select **Save**. 1. Type a name for the query. 1. Type the name or part of a name of the user you want to share the query with. 1. Select the user from the dropdown list. 1. Select **Save** to save the query to your list and the assigned user’s query list. 1. The query will be stored in the other user’s list under Shared. # Generating Forensics Reports ## Generate a Report from the Last Run Query 1. Run a query as described above or by selecting a saved query from the query list. 1. Select **Global Options > Generate Report**. The report will be available in My Reports. ## Schedule and Save a Report Template 1. Run a query as described above or by selecting a saved query from the query list. 1. Select **Global Options > Generate Report**. 1. Name the schedule and fill in the scheduling parameters. # Identity Forensics To locate the Identity Forensics page, navigate to **Forensics > Identities**. The Identities Forensics screen displays users, groups, and their relationship recorded by the system. Use filters to focus on specific data. The page supports reports and campaigns. The displayed output is limited to the first 100,000 results. ## Tabs Note Each tab has a separate filter and stored query list. Select one of the following tabs to display different data about users, groups, and their relationships. **Users' Membership in Groups** - View of users and their group memberships. **Users** - Displays users and their attributes which are defined in the identity store. **Groups** - Displays groups and their attributes which are defined in the identity store. Identity queries involve identity stores connected to Data Access Security, regardless of the permissions attached to these identities. # Permission Forensics Permission Forensics allows the administrator to monitor and analyze the user and group permissions. On this screen you can create queries to analyze the permissions of specific groups of users, save and share queries for selecting users and groups, generate reports, run permission scans, and revoke explicit permissions of users. This page supports reports and campaigns. This component answers questions, such as: - Which users have access to what resources? - Which users have not used permissions granted to them? - Which permissions were granted to each group? - Which groups are not being used? The table displays the permissions according to the level of granularity selected in the filter. When creating a filter, you can define the granularity of the report using the **View by** field, and can mark stale permissions on the table according to the unused time selected. Note The query retrieves the first 100,000 results. Narrow the search to obtain a better fit. **Reports** - See [Generating Forensics Reports](https://documentation.sailpoint.com/das/help/forensics/forensics_reports.html). **Filters** - See [Filters: Creating and Editing a Forensics Query](https://documentation.sailpoint.com/das/help/forensics/forensics_filters.html) ## Viewing Permission Forensics The Permission Forensics table displays the permissions retrieved by the query run. By default, the data displayed includes the following columns for each permission: **Resource** - Business resource full path - Application **User** - User name - User display name - Group name - User domain - Group domain - User entity type - Group entity type **Permission** - Permission type - Classification category - Is inherited - Inherits permissions - ACL type allowed? To change the order of the columns, drag the column titles. **Additional columns available:** - Application group, Application type, Business Resource Logical Path, Business Resource Name, Business Resource Type, Creates Loop, Creation Timestamp, Cumulative Last Used, Department, Distinguished Name, Group Path, Is Effective, Is Owner Permission, Is Riskiest, Is, SID History, Last Login Date, Last Used Date, Loop Path, Password Never Expires, Password Not Required, Permission Type Description, User Disabled, User Email, User Locked To select columns to display: 1. Select the column chooser icon on the table header bar. 1. Select the columns to display from the dropdown list. - Click **Show All / Show Less** to display a full list of columns / only the default columns in the column chooser. This does not change the selection of columns to display in the table. - Use the search field to narrow down the list of columns in the column chooser. - Click **Reset Columns** to reset to the default selection and order of the columns in the table. ### View By The default view is the Users and Groups view. You can change the granularity of the output by selecting the **View By** type. These options determine whether to check a user’s direct permissions or permissions granted by groups the user belongs to, as described below: - **Groups & Users Direct Permissions** – Focuses on permissions that are directly assigned to a user or directly assigned to a group. This view is best for displaying the immediate targets of permission assignments (either a specific user or a specific group) and the direct permission assignments. If a permission is assigned to a group, it shows the group. It does not expand groups to show the individual users who are members of those groups. - **Users direct & Group Membership Permissions** – Aggregates permissions directly assigned to a user as well as permissions a user inherits through any group membership, including nested groups and Everyone or Authenticated Users built-in groups. Note This view will not expand the “Everyone or Authenticated Users” groups to list individual user names. This view is best to understand all permissions a user has, whether direct or inherited, except for the individual breakdown of users within Everyone or Authenticated Users groups. - **Everyone Groups expanded, Users Direct & Group Membership Permissions** – Provides the most granular breakdown. It includes everything from the "Users Direct & Group Membership Permissions" view, and has Everyone or Authenticated Users groups expanded (i.e. will explicitly list each individual user who is a member of the Everyone or Authenticated Users group for that specific permission). The view is best to see every single permission a user has and the individual users listed even when permissions are inherited through Everyone or Authenticated Users groups. Note In the Permission Forensic screen, the View By field can be changed after setting or restoring the filter. ## Scope and Hierarchical Search By default, when you select a Business Resource to scope its permissions, only the direct Business Resource permissions (not the child BR permissions) display. ## Special Groups - Group Entity Type When creating a filter, you can select the group entity type from Field. In Windows-based environments, the user groups are Everyone, Authenticated Users, and Domain Users. **Everyone** - Includes all users. **Authenticated Users** - Includes all internal users. **Domain Users** - Includes a group with all users in the domain. By default, any user created is a member of this group, though it is possible to remove that user. ## Owner Permission Field Data Access Security permission forensics allows identification and tracking of Owner permissions in the following ways: - A proprietary column titles “Is Owner Permission” indicates whether a given permission is an Owner permission. - A proprietary query attribute is dedicated for filtering Owner permissions allowing queries and/or reports listing the owners of resources. ## Permission Scan for Business Resource The permission scan collects the security information from the scanned Business Resources and stores it in the Data Access Security database. This includes which users or groups have access to the Business Resource and whether the access is inherited. The permission scan stores access types such as read, write, full control, etc., depending on the application type. When requesting a permission scan, you can set the resources to scan and the number of levels below the requested Business Resource. ### Performing a Permission Scan 1. Navigate to **Forensics > Permissions**. 1. From the Global Options dropdown menu, select **Start Permission Scan**. This opens the Permission Scan panel. 1. Select the scan level: - This Business Resource only - This Business Resource and levels 'Level 1-4' and 'All Levels' 1. Click **Scan** to start the scan or **Cancel** to return to the Permission Forensics screen. ### DFS Support For DFS resources, the Permission Forensics table will show the physical and the logical path of resources. You can create a filter for DFS resources by logical path only. To select a logical path, select **Resource** on the Select Field drop down menu. Next, navigate to the required path on the resource tree by using the Select Resource dropdown menu. (See [Searching for Resources Using a Resource Tree](https://documentation.sailpoint.com/das/help/forensics/forensics_filters.html)). # Getting Started in Data Access Security Welcome to Data Access Security! To get the most out of SailPoint's Data Access Security, review the following information about setting up all mandatory features. ## Loading Data - [Create Virtual Appliance](https://documentation.sailpoint.com/saas/help/va/index.html) If you want to directly connect to any of your sources to load account data, you'll need a virtual appliance (VA). Virtual appliances allow you to connect your sources to SailPoint Human Fabric without compromising your firewall. This configuration is done in SailPoint Human Fabric. - [Connect to SailPoint Human Fabric](https://documentation.sailpoint.com/das/help/getting_started/connect_to_isc.html) Data Access Security users will need to connect to SailPoint Human Fabric in order to set permissions, add new identities, and assign these identities to Data Access Security roles. ## Creating Sources - [Create Initial Sources](https://documentation.sailpoint.com/das/help/acct_entitlement_aggregation/ad_creation.html) Many organizations have a few sources that, together, have records for every user in the organization. They should be created first so that their data is considered the highest priority. You can create other sources later. - [Create Identity Collector](https://documentation.sailpoint.com/das/help/acct_entitlement_aggregation/create_idc.html) From the source that was previously created, now you must create an identity collector which allows you to collect all accounts and entitlements from that source. - [Add an Application](https://documentation.sailpoint.com/das/help/getting_started/add_app.html) Data Access Security can connect to various applications. For more information about each application, see their guides [here](https://documentation.sailpoint.com/das-connectors/help/index.html). Once data has been aggregated and Data Access Security is running, you can view tasks, approvals, and more on your dashboard. ## Supported Languages Data Access Security supports more than 10 languages, with American English being the default. Note Data Access Security does not recognize territory language distinctions in locales. For example, if you specify the locale as 'en-US' or 'en-GB', Data Access Security will behave as if the locale is 'en'. **The only exception is Chinese. Simplified Chinese will always default to 'zh-CN', and traditional Chinese will always default to 'zh-TW'**. Data Access Security supports the following languages: | Language | Locale | | --------------------- | ------- | | Chinese (Simplified) | 'zh-CN' | | Chinese (Traditional) | 'zh-TW' | | Dutch | 'nl' | | English | 'en' | | French (France) | 'fr' | | German | 'de' | | Italian | 'it' | | Japanese | 'ja' | | Portuguese (Brazil) | 'pt' | | Spanish | 'es' | | Swedish | 'sv' | # Application Main Screen The Applications page enables a user to view, add, modify, or delete applications. The Applications main page is located at **Admin > Applications**. The Applications grid provides the following columns: - Name – Name of application - Description – Additional information about the application - Type – Common search or grouping criteria - Tags – Allows users to group applications together - Actions - Provides multiple options for the user, including editing or deleting the application The amount of rows displaying applications can be changed with the **Rows per page** drop down at the bottom left of the page. The user can also click through pages with the left and right arrows at the bottom right of the page. Within the Applications main page, a user can perform any of the following actions: - Add New - This options allows the user to add a new application. - Filters - Allows the user to have a more defined search. Searchable items are Name, Type, and Tags. - Edit - Allows various details about the application to be edited. - Delete - Allows the user to delete the chosen application. The deleted application will not be available on the grid and a task will be created to clean the application references and data. This deletion task can be monitored on the Tasks screen. - Exclude Top Level Resources - Function allowing the user to exclude top level resources from being retrieved by a crawler action. This feature is only available after the crawl. ## Adding Applications to Data Access Security An application is a component that represents the monitored system, such as, Microsoft Outlook, Active Directory, MS Windows file servers. All active applications can be seen in **Admin > Applications**. You can add tags to applications in order to better group them. In order to integrate with a component, an application entry needs to be created first. This entry includes the identification, connection details, and other parameters necessary to create the link. To add a standard application, use the New Application Wizard. Important The actual configuration pages and fields vary according to the application type you are adding. For a detailed description, see the relevant connector installation guide on the [Data Access Security connector website](https://documentation.sailpoint.com/das-connectors/help/index.html). Note When onboarding a new application, do not use a backslash in the name of the application. # Data Access Security Virtual Appliance Cluster Creation Data Access Security requires the use of virtual appliances to establish connectivity to applications and sources on customer premises within your data centers or your virtual private cloud environment. In addition, it is required to use specialized virtual appliances to perform [Data Classification](https://documentation.sailpoint.com/das/help/data_class/index.html) operations for all types of applications. The following matrix can be used to determine if a virtual appliance is needed and for which component. | Application Infrastructure | Crawl | Permission Collection | Data Classification | Activity Monitoring | | ----------------------------------------- | ----------------------------------------- | ------------------------------------------- | ---------------------------------------------------- | --------------------------------------- | | Cloud (O365, AWS S3, etc.) | N/A | N/A | Data Access Security - Data Classification Collector | N/A | | On Premise (Windows Server, Netapp, etc.) | Data Access Security - Resource Collector | Data Access Security - Permission Collector | Data Access Security - Data Classification Collector | Data Access Security – Activity Monitor | Note [Sources](https://documentation.sailpoint.com/das/help/acct_entitlement_aggregation/ad_creation.html) for identity information need to be created in SailPoint Human Fabric and may or may not require a virtual appliance based on the source. The Data Access Security Identity Collection task relies on these sources to properly associate accounts and entitlements to permissions on the Data Access Security applications. Important Based on the type of functionality you plan to incorporate for the connector in Data Access Security (reference table above), select the corresponding virtual appliance cluster component type in SailPoint Human Fabric. ## Crawler Virtual Appliance In order to take advantage of Data Access Security Resource Discovery within their environments, admins must create a dedicated VA cluster and VAs using the Data Access Security - Resource Collector cluster component. You can create a dedicated cluster in one of two ways: - In SailPoint Human Fabric, follow the steps in [Deploying Virtual Appliances](https://documentation.sailpoint.com/saas/help/va/deploy_va.html) and select the Data Access Security - Resource Collector cluster component. - Use the [Data Access Security Application Configuration](#data-classification-cluster-creation-with-application-configuration) wizard. Note Only on-premise applications require a Resource Collection Virtual Appliance to perform the resource discovery tasks. 1. In the Crawler configuration step in the Application Configuration Wizard, use the **Resource Collection Cluster** dropdown to select an existing one to be used by the applications. 1. If there are no available clusters in the dropdown or if the clusters are being used to capacity and you would like to associate the configured applications to a new cluster, select the plus (+) icon next to the cluster dropdown to add another cluster. Note This creates an empty virtual appliance cluster. Make sure to go back to SailPoint Human Fabric to properly configure the virtual appliance to the cluster. See [Virtual Appliance Important Details](#virtual-appliance-important-details) for more information. 1. A confirmation message is displayed asking you to confirm the operation. Upon approval, a new cluster is created with a default name of “DAS crawler collector cluster.” Subsequent clusters will have a number added to their name to differentiate the ones previously created. ## Permission Collector Virtual Appliance In order to take advantage of Data Access Security Permission analysis within your environment, admins must create a dedicated virtual appliance cluster and virtual appliances using the Data Access Security - Permission Collector cluster component. You can create a dedicated cluster in one of two ways: - In SailPoint Human Fabric, follow the steps in [Deploying Virtual Appliances](https://documentation.sailpoint.com/saas/help/va/deploy_va.html) and select the Data Access Security - Permission Collector cluster component. - Use the [Data Access Security Application Configuration](#data-classification-cluster-creation-with-application-configuration) wizard. To get started: 1. In the crawler configuration step in the Application Configuration Wizard, use the **Permission Collection Cluster** dropdown to select an existing one to be used by the applications. 1. If there are no available clusters in the dropdown or if the clusters are being used to capacity and you would like to associate the configured applications to a new cluster, select the plus (+) icon next to the cluster dropdown to add another cluster. Note This creates an empty virtual appliance cluster. Make sure to go back to SailPoint Human Fabric to properly configure the virtual appliance to the cluster. See [Virtual Appliance Important Details](#virtual-appliance-important-details) for more information. 1. A confirmation message is displayed asking you to confirm the operation. Upon approval, a new cluster is created with a default name of “DAS crawler collector cluster.” Subsequent clusters will have a number added to their name to differentiate the ones previously created. ## Data Classification Virtual Appliances Data Access Security's Data Classification engine identifies and categorizes data based on data sensitivity, its impacts, and the importance of the data to the business. Data Classification enables organizations to identify business-critical information and “crown jewels”, such as intellectual property, as well as sensitive and regulated data, that need to be tightly governed to comply with regulations. In order to take advantage of Data Classification within their environments, Admins must create and deploy a dedicated VA cluster and VAs using the Data Access Security - Data Classification Collector cluster component. You can create a dedicated cluster in one of two ways: - In SailPoint Human Fabric, follow the steps in [Deploying Virtual Appliances](https://documentation.sailpoint.com/saas/help/va/deploy_va.html) and select the Data Access Security - Data Classification Collector cluster component. - Use the [Data Access Security Application Configuration](#data-classification-cluster-creation-with-application-configuration) wizard. To get started: 1. In the Data Classification configuration step in the Application Configuration Wizard, use the **Data Collection Cluster** dropdown to select an existing one to be used by the applications. 1. If there are no available clusters in the dropdown or if the clusters are being used to capacity and you would like to associate the configured applications to a new cluster, select the plus (+) icon next to the cluster dropdown to add another cluster. 1. A confirmation message is displayed asking you to confirm the operation. Upon approval, a new cluster is created with a default name of “DAS data classification collector cluster”. Subsequent clusters will have a number added to their name to differentiate the ones previously created. ## Activity Monitoring Virtual Appliance In order to take advantage of Data Access Security event collection within your environment, Admins must create a dedicated virtual appliance cluster and virtual appliances using the Data Access Security - Activity Monitoring cluster component. You can create a dedicated cluster in one of two ways: - In SailPoint Human Fabric, follow the steps in [Deploying Virtual Appliances](https://documentation.sailpoint.com/saas/help/va/deploy_va.html) and select the Data Access Security - Resource Collector cluster component. - Use the [Data Access Security Application Configuration](#data-classification-cluster-creation-with-application-configuration) wizard. Note Only on-premise applications require Activity Monitoring Virtual Appliance to perform the resource discovery tasks. 1. In the Crawler configuration step in the Application Configuration Wizard, use the **Activity Monitoring Cluster** dropdown to select an existing one to be used by the applications. 1. If there are no available clusters in the dropdown or if the clusters are being used to capacity and you would like to associate the configured applications to a new cluster, select the plus (+) icon next to the cluster dropdown to add another cluster. Note This creates an empty virtual appliance cluster. Make sure to go back to SailPoint Human Fabric to properly configure the virtual appliance to the cluster. See [Virtual Appliance Important Details](#virtual-appliance-important-details) for more information. 1. A confirmation message is displayed asking you to confirm the operation. Upon approval, a new cluster is created with a default name of “DAS crawler collector cluster.” Subsequent clusters will have a number added to their name to differentiate the ones previously created. Note Some activity monitoring connectors require the virtual appliance to accept incoming network traffic. See the relevant connector documentation for details. ## Virtual Appliance Important Details Note Create new VAs to associate them with the Data Access Security VA clusters. Do not associate existing SailPoint Human Fabric VAs with Data Access Security clusters. VAs cannot migrate across cluster components. A VA Cluster can contain one or more VAs. We recommend adding multiple VAs to support redundancy and high-availability, as well as scale per performance. A VA Cluster can service multiple applications and can be associated with one or more applications. There is no need to create a separate cluster for each application, as there is no coupling between applications and clusters. # Connect to SailPoint Human Fabric User levels are sets of permissions within SailPoint Human Fabric that administrators can grant to users. Users cannot grant themselves user level permissions, only SailPoint Human Fabric Admins can grant or remove user levels. Users can be granted multiple user levels and will have the combined access of all levels assigned to them. To view the user levels and associated privileges, refer to the [User Level Matrix](https://documentation.sailpoint.com/das/help/getting_started/user_matrix.html). 1. Sign into your organization. 1. Navigate to **Admin > Identities > Identity List**. 1. For any existing identity select the vertical menu button. 1. Select the **Set User Levels** option. 1. Scroll down and select the relevant Data Access Security role(s). 1. Select **Save**. # Data Access Security Dashboard This section describes the Data Access Security dashboard and its main capabilities and navigation paths. A security dashboard is tailored for security administrators, compliance managers, and auditors. It serves as a centralized command center, providing crucial insights into access to critical resources. This dashboard allows administrators to have clear visibility into their accounts. It also streamlines decision-making which allows for proactive security measures. With widgets on this dashboard, administrators can confidently safeguard critical assets, fortifying an organization's defenses and ensuring a resilient, secure environment. This dashboard makes it easier for IT and security personnel to enlist the cooperation of users to indicate which resources are at risk. ## Data Access Security Widgets Below is a small description of each widget that is available within Data Access Security. ### Accounts Overview This widget displays different cards that could provide information on risky accounts. **External Accounts** - accounts that are external to the organization or to the SailPoint Human Fabric source. Their access to critical data should be restricted, minimized, and periodically certified. Doing so reduces potential data leakage and helps safeguard the integrity and confidentiality of the internal critical information and comply with privacy and security standards. **Accounts with Passwords that Never Expire** - these accounts could weaken the password security policy and increase credential theft risks. It is recommended to replace this configuration with a periodic password reset policy or add a control that requires accounts with the attribute Passwords Never Expire to have a very strong password and their access regularly assessed. **Accounts that Require No Passwords** - these accounts could log on without a password, overriding login security policy. This can cause a security gap. It is recommended to change this attribute value to false. **Disabled Accounts** - these accounts are often used for temporary timeouts of employees. It is recommended to delete disabled accounts that are not expected to re-enable in the future, like a past terminated employee's account, to reduce blast radius for the attacker **Empty Groups** - these are entitlements with no members. Empty groups reduce performance, diminish transparency, and increase the chances of an attacker finding a path to exploit. It is recommended to delete empty security groups. **Cyclic Nested Groups** - these are groups with an infinite loop, where the same group is a parent and a child of another. It is recommended to remove the circular nesting due to operational overhead and potential unintended privilege escalation hidden in circular group references. ### Accounts with Excessive Access to Critical Data This widget displays the top 10 accounts that have a wide array of access to multiple applications either directly or indirectly. Having this information allows a user to monitor and investigate the reasons for the amount of access. **Account Name** - name of the identity who poses a risk. **Critical Resources** - number of critical resources the identity can access. **Applications** - number of applications the identity has access to. This does not mean type of applications, rather the number of applications. **Data Categories** - number of categories on the account. ### Access Exposure by Application This widget shows applications that have too much exposed access. This can include too many permissions or links being shared that have critical data. On this widget, there are three different columns that identify the level of exposure. - Publicly Shared - this is information that is shared to anyone outside of the organization with a link to critical data. - Specifically Shared - this information is shared to a specific person or group inside or outside of the organization with a link to critical data. - Direct Access - this information is given directly to a single user, not a group. ### Active Policies This widget provides insight into the active policies within your system. Each policy listed is accompanied by the number of data categories that is within that policy as well as the number of critical resources that is within that policy. The values on this widget are clickable and will take you to Forensics page with further details about the data. ### Overexposed Resource Score This widget displays a total number of overexposed resources across all applications. There is also a score that represents the risk of overexposed resources. ### Overexposed Critical Resources Score This widget displays a total number of critical resources that are overexposed across applications. There is also a score that represents the risk of critical data that may be overexposed. ### Critical Resources by Policy This widget displays a bar graph with an overview of all critical data across all applications grouped by policies. The values on this widget are clickable and will take you to Forensics page with further details about the data. ### Critical Resources by Application This widget provides a more in-depth bar graph of critical resources. The values on this widget are clickable and will take you to Forensics page with further details about the data. ### Critical Resources without Data Owners Score This widget displays the number of critical resources which are not assigned owners across all applications. ### Critical Resource without Data Owner This widget lists applications that have critical resources without owners. The chart displays the number of folders within each application as well as the number of folders without an owner. The values on this widget are clickable and will take you to Forensics page with further details about the data. # User Level Descriptions The following capabilities are default capabilities with Data Access Security. You can create custom capabilities to fit your needs. Warning The system capabilities described below should not be removed or modified. ## Auditor The auditor capability is designed for users who perform internal audits and assist in external audits of user access information within the organization. The auditor rights include: - Seeing and managing all reports. - Seeing and running the [forensic](https://documentation.sailpoint.com/das/help/forensics/index.html) screens. - Deleting [report templates](https://documentation.sailpoint.com/das/help/reports/using_report_temp.html). An auditor capability is assigned Full Scope by default. This allows users with this capability to see and run reports on all resources. However, it does not allow auditor users to take actions on resources that have not been assigned to them. See Scope within the [Configuring Data Access Security](https://documentation.sailpoint.com/das/help/admin/website_config.html) section of the Administrator help. ## Data Owner This is a capability automatically associated with anyone assigned as an owner of any business resource. Users who are assigned this role are the data owners of all resources in their scope. The data owner rights include: - Seeing and managing user access information for business resources in their scope. ### Data Scope Data Access Security Data Scope should only be enabled in conjunction with another Data Access Security role. Data Scope provides zero capabilities. It *only* provides visibility to data. When enabled it will give *full* visibility to all resources. ## Compliance Manager The compliance manager rights include: - Configuring [data classification policies](https://documentation.sailpoint.com/das/help/data_class/create_dc_policy.html), rules, and policy objects. - Viewing [data classification forensics](https://documentation.sailpoint.com/das/help/forensics/dataclass_forensics.html). - Seeing and running most reports. This role does not have the Report Template Administrator right. The compliance manager capability is assigned Full Scope by default. This allows users in this capability to see and run reports on all resources. However, it does not allow the compliance manager users actions that require specific resources to be assigned to them. See Scope within the [Configuring Data Access Security](https://documentation.sailpoint.com/das/help/admin/website_config.html) section of the Administrator help. ## Administrator The administrator has all rights in Data Access Security enabled, except for Reviewer. The administrator rights include: - View the administrator [dashboard](https://documentation.sailpoint.com/das/help/getting_started/das_dashboard.html) and statistics. - See and manage user access information for all business resources. - Configure settings for Data Access Security. - Access rights granted to anyone with Administrator capability. - The Report Templates Administrator right. The administrator capability is assigned Full Scope by default. This allows users in this capability to see and run reports on all resources. However, it does not allow the administrator users actions that require specific resources to be assigned to them. See Scope within the [Configuring Data Access Security](https://documentation.sailpoint.com/das/help/admin/website_config.html) section of the Administrator help. For a full description of the rights set per capability, see the `web_permission` table in the Data Access Security database. The capabilities in your system can be modified and new capabilities added by the administrators and implementation teams. # User Level Access Matrix The following table shows the Data Access Security pages and components that are accessible from each user level. | Screen Name | Administrator | Compliance Manager | Data Owner | Auditor | User | | ---------------------------------- | ------------- | ------------------ | ---------- | ------- | ---- | | **Dashboard** | ✓ | x | x | x | x | | **Resources** | ✓ | x | ✓ | x | x | | Permissions | ✓ | x | ✓ | x | x | | Data | ✓ | x | ✓ | x | x | | Owners | ✓ | x | ✓ | x | x | | **My Tasks** | ✓ | ✓ | ✓ | ✓ | ✓ | | Access Certifications | ✓ | ✓ | ✓ | ✓ | ✓ | | Owner Election | ✓ | ✓ | ✓ | ✓ | ✓ | | Election Review | ✓ | ✓ | ✓ | ✓ | ✓ | | **Reports** | ✓ | ✓ | ✓ | ✓ | ✓ | | My reports | ✓ | ✓ | ✓ | ✓ | ✓ | | Reports templates | ✓ | ✓ | ✓ | ✓ | x | | **Compliance** | ✓ | ✓ | x | x | x | | Data classification | ✓ | ✓ | x | x | x | | Import Data Classification Results | ✓ | x | x | x | x | | Policies | ✓ | ✓ | x | x | x | | Rules | ✓ | ✓ | x | x | x | | Policy objects | ✓ | ✓ | x | x | x | | Application scope | ✓ | ✓ | x | x | x | | Policy scope | ✓ | ✓ | x | x | x | | Manage categories | ✓ | ✓ | x | x | x | | Manage file properties | ✓ | ✓ | x | x | x | | Campaign Management | ✓ | ✓ | x | x | x | | Campaign Templates | ✓ | ✓ | x | x | x | | Alert Rules | ✓ | x | x | x | x | | **Governance** | ✓ | x | x | x | x | | Campaign Management | ✓ | x | x | x | x | | **Forensics** | ✓ | ✓ | ✓ | ✓ | x | | Permissions | ✓ | ✓ | ✓ | ✓ | x | | Identities | ✓ | ✓ | x | ✓ | x | | Data classification | ✓ | ✓ | ✓ | ✓ | x | | Activities | ✓ | ✓ | ✓ | ✓ | x | | **Settings** | ✓ | x | x | x | x | | Task management | ✓ | x | x | x | x | | Tasks | ✓ | x | x | x | x | | Scheduled tasks | ✓ | x | x | x | x | | Tasks auto retry | ✓ | x | x | x | x | | Account exclusions | ✓ | x | x | x | x | | Sensitive account exclusions | ✓ | x | x | x | x | | General | ✓ | x | x | x | x | | Overexposed resources | ✓ | x | x | x | x | | Import user scope | ✓ | x | x | x | x | | Discard Rules | ✓ | x | x | x | x | | **Admin** | ✓ | x | x | x | x | | Applications | ✓ | x | x | x | x | | Permissions management | ✓ | x | x | x | x | | Data dictionary fields | ✓ | x | x | x | x | | Identity collectors | ✓ | x | x | x | x | # Reports Overview Data Access Security provides advanced reporting capabilities. Reports make processed data available to the appropriate data owners. Reports can be generated by using predefined report templates and also by the Generate action that can be found on the [Permissions](https://documentation.sailpoint.com/das/help/forensics/perm_forensics.html) and [Identities](https://documentation.sailpoint.com/das/help/forensics/identity_forensics.html) screen within the Forensics tab. # Viewing My Reports The main Reports screen allows the user to view all recently run reports and perform basic actions on these completed reports. The user can easily identity information about each report from the report grid. The grid provides the following information: - Creation Date - date and time when the report was run. - Report Name - title of the report. - Report Type - type of report that was run. - Owner Name - name of person who created the report. - Actions - sharing, deleting, or downloading the report. Note The options within the Action column can only be performed on a single report. For bulk action options, see Bulk Options for Reports below. Note The default display for the reports grid is to show the reports that have not been downloaded yet and that were run within the last 30 days. This is the default filter. **Sharing a report** - Selecting the Share icon displays the following actions: - Share report with - from the dropdown, select the user(s) you wish to share the report with. - Subject - provide a subject line for the sent report. - Message - provide a message to the recipient of the report. - Send me a copy - select this option if you wish to also be sent a copy of the report. Select **Send**. Note Customizing report [email templates](https://documentation.sailpoint.com/saas/help/common/emails/available_templates.html) is available. **Deleting a report** - Select the delete icon on the report you wish to delete. Select **Yes** to confirm the deletion. **Downloading a report** - Select the download icon to download the desired report. Downloading a report only takes a few moments. ## Bulk Options for Reports You can perform bulk options on multiple reports. To perform bulk options, select the various reports by checking the selectable box to the left of each report. Once multiple reports are selected, two new options will appear in the top right corner of the grid. - **Bulk Share** - a new window will display. The options within the window are the same as mentioned above within Sharing a Report. - **Bulk Delete** - a window will display asking to confirm the deletion. Select **Yes** to bulk delete. ## Reports Filter You can search for particular reports by using the filter feature. The filter option can be found at the top right of the grid. Note The filter feature is removed if using bulk options. If using a filter to search for a report, a new overlay will display. - **Name** - if you know the name of the specific report you are looking for, type some or all of the name here. - **Type** - narrow down your search by selecting the type of report you are searching for. - **Owner** - if you know who created the report, use the Owner dropdown to select that identity. - **Date** - you can search for a report based on when it was created. With the date option, you can also give a range of dates when the report was thought to be created. - **New Reports Only** - this option is on by default. It will display reports that have not been downloaded yet. # Using Report Templates Users who have a Data Access Security role (Administrator, Compliance Manager, Data Owner, Auditor) are able to access the Report Template screen and will see all System Report Templates. You will also have the ability to create your own report. Navigate to **Reports > Report Templates** to use Data Access Security's built-in report templates for standard and customized reports. ## Report Actions Navigate to Report Templates to view already existing report templates. Each report has a set of possible actions. Important The available actions are dependent on the user type. ### Run Now Run the report and send it to all recipients. The report template generates a report with the default parameters. ### Scheduling Reports Schedule an ad-hoc execution or set the report to run on a regular cadence. 1. Toggle **Enable Schedule** to schedule a report. 1. Select the day(s) and time the report should run. 1. Select the start date. 1. If you want the schedule to end on a certain date, toggle the **Ends** option and select the future end date. 1. From the **Recipient(s)** dropdown, search and select who should receive this report. 1. Select **Save**. ### Editing Reports Customize the report template and refine its criteria to fit specific business needs. Editable fields will vary depending on the report type. Important System report templates cannot be edited. You can create editable copies by duplicating the system report templates and adjusting them for your needs. Duplicated templates can be edited, shared, scheduled, deleted, or duplicated in themselves. To edit a report template, navigate to **Reports > Report Templates** and perform the following: 1. Select **Edit** on the report template that needs to be edited. 1. Under the **General** tab of the edit window, the only options that can be edited is the Template Name and the Description. 1. Under the **Tagging** tab, add or remove tags on the report. 1. Under the **Sharing** tab, select who the report should be shared with. 1. Select either **Save** to save the changes or select **Run Now** to save the changes and run the report. ### Duplicating Reports Create a replica copy of an existing template. Duplicating system report templates allows you to edit them. Note Any report template can be duplicated, including system and custom user-created templates. Templates can be duplicated multiple times. ### Deleting Reports To remove a template, select **Delete**. ### Sharing Reports Depending on your role, a user can have various sharing rights. Data Access Security can send reports to: - All Administrators - All Authorized Users - Do not share with anyone ### Favorite Reports Mark reports templates as Favorites to save it to your favorite report template list. This is for those reports you use frequently. ## Working with Tags You can assign one or more tags per report to help find them later. ### Attribute Tags Attributes Tags are built-in pre-defined tags that are used to catalog report templates and simplify template management. Attributes tags can be used to easily filter report templates and help locate popular templates quicker. - **My Favorites** - Select this to view all templates that have been favorited by you. - **Scheduled** - Select this to view all templates that are currently on an active schedule. - **Created by me** - Select this to filter between templates you have created. ### Custom Tags Tags can be assigned to report templates in order to categorize them, assist in organizing and managing templates at scale, as well as used in filters to expedite search and help locate specific templates quickly. In addition to [Attribute Tags](#attribute-tags), Administrators can create additional custom tags to address their specific cataloging and search requirements. Note This option is available by default to the Administrator capability only. Note System tags cannot be deleted. The Delete option is disabled for system tags. 1. Select **Manage Tags** to change or delete report tags. The available options are: - Hide system-defined tags - Check this filter out all system made tags. - Search for tags - Use the search bar to locate an exact tag - Edit tags - Use the edit icon to edit the name of the tag. Tag names must be unique. Select the green checkmark to save the edit. - Delete tags - Use this icon to delete the tag. - Add a custom tag ## Run or Create a Scheduled Report The following are two possibilities for running or creating a scheduled report: - Report templates that are system reports or reports that are created and shared by a user. - Report templates that are created by the currently logged in user. To run or create a scheduled report, complete the following: 1. To adjust or customize the template's default settings and parameters prior to creating a report, select **Duplicate** from the template menu. 1. Set the desired report parameters, scheduling times, and other settings. Note When scheduling a report, be aware that time is only reflected in UTC, not local time. 1. Select **Run Now** to run the report. 1. Select **Save** to save the template for future use of this template. 1. If running a report with no customized settings, select **Run Now** on the desired report within the Report Templates screen. # Resource Overview The resource tab allows you to view different governance dimensions on managed resources within applications governed by Data Access Security. All onboarded applications display within the resource tree on the left panel. Each application has its own nested resource tree. A resource within an application can be a file share, folder SharePoint site, database, storage object, etc. Individual files are not represented as "resources" managed by Data Access Security, unless they have unique permissions assigned to them. In this case they will be represented as individual managed resources. The Resource tab includes the following tabs: - [Permissions](https://documentation.sailpoint.com/das/help/resources/permissions.html) - [Data](https://documentation.sailpoint.com/das/help/resources/data.html) - [Owners](https://documentation.sailpoint.com/das/help/resources/owners.html) # Data Tab This tab helps identify the data distribution and staleness levels from within a certain resource. Each color-coded block represents a nested resource. Usage information is aggregated and presented based on the most recent data. Resources are color-coded in a heatmap based on the last time they were accessed, which represents their staleness. Above the heatmap, a legend depicts the time frames that determine the mapping. Stale data is calculated by the following flow: - Most recent activity collected on the resource (must have Activity Monitoring enabled for the application). - Most recently modified date or accessed date of the business resource from metadata collected during the crawl. Note Data Access Security cannot collect last modified and/or last accessed for all business resources. It is highly recommended that [Activity Monitoring](https://documentation.sailpoint.com/das/help/forensics/activity_forensics.html#activity_monitoring_capabilities) is enabled for best results. - The first time the business resource was seen by Data Access Security. Note The size of the block indicates the size of the resource. If a resource has a zero for size, it will not display. Clicking a block provides the user with a snapsnot of information regarding that resource like the type of content within the resource, if there is sensitive information in the resource, and who owns the resource. For more information on that selected resource, select **View Details**. After selecting View Details, you can select between two tabs on the View Details window. Note The info presented in the View Details window reflects the main resource, not the sub-resources. - General tab - provides the same type of info that was presented when the resource block was selected from the heatmap. - Data Analysis tab - gives a visual of the sensitive data and content types that are stale within the selected resource. ## Filtering Filter the resource blocks by either the last time the resource was used or by the size of the resource. # Business Data Owners Tab The Owners tab provides visibility into the ownership status of the data within a resource. This view shows the top 10 identities who are accessing the particular resource in a customized time period. It also shows all business data owners of a particular resource. The user also has the capability to alter those data owners here. With the usage percentages displayed, Data Access Security provides activity information, customized by activity types, to help the user make a more informed decision about who owns certain folders within a resource. You can adjust the usage statistics presented by specific action types, the time frame, or the actions performed within the folder. ## Adding Owners to Resources Within the table displays a list of the most active users on a resource. If a user is not selected as an owner, click the **+Add Owner** button to add them. The following are the two options to add new owners: - Based on existing identities - Based on the usage statistics If a user is not listed within the table and needs to be added as an owner to the resource, click **Add New Owner** within the Current Owners window and search for them. # Viewing Permissions The Permission tab provides four different views on a resource: - **Simple** - High level view that shows who has direct access to what. You can filter the results by the permissions type (menu on the left panel). If a permission is directly granted, you can revoke a user's permission from this view. Select the **more options** button within the Actions column on the user you want to revoke and select **Revoke**. A dialog appears confirming if you want to continue with the revocation. Another option within the Actions column is **View Paths**. This path shows how the user was given the permission and also has the revoke function available. Once viewing a permission path, permissions can be revoked here by hovering over the permission and selecting the blue revoke button. This button is not displayed for all permissions, only revocable ones. Due to limitations from the Microsoft Graph API, the `Records Center Web Service Submitters` permissions cannot be captured with the exception of sites and sub-sites where Rest API is still utilized to collect permissions for these resource types. - **Tree** - Gives the view from a resource perspective on the entire resource. If a permission is directly granted, you can revoke a user's permission from this view. If you hover over a permission and a blue revoke button displays, that permission can be revoked. Select **Yes** to start the revocation task. Note Revoking permission is only supported for OneDrive and SharePoint Online. ## What Permission can be Revoked? A user permission directly granted which are not inherited qualifies to be revoked. | Where is Permission Granted From? | Can it be Revoked? | Notes | | --------------------------------- | ------------------ | -------------------------------------------------------------------------------------------------------------------------- | | User direct access on resource | Yes | The primary creator/owner or high-level admin of the resource cannot be revoked even if directly granted. See table below. | | Permission inherited from parent | No | | | Permission inherited from group | No | | Note When a user is granted Full Control to a resource in OneDrive or SharePoint Online, the OneDrive or SharePoint Online modern view will recognize that as Owner. When an Owner permission is assigned in this manner, it can be revoked by permission revocation in Data Access Security. In the case that a single user is granted both Owner via the Site Collection Administrators setting and directly on a resource, Data Access Security will treat these as a single permission prioritizing the permission inherited from the Site Collection Administrators. Therefore, in the Permissions view, only one instance of Owner permission will appear for this user. Since the permission is inherited, the **Revoke** option will not be available. Note Within OneDrive and SharePoint Online, a user can have the same access by having direct access and a corresponding shared link. If permission is revoked, only the targeted permission (either direct access or from the shared link) will be removed, the other will be unaffected. ### Revocation Audit Events Revocation tasks create various events which can be audited using SailPoint Human Fabric [Search](https://documentation.sailpoint.com/saas/help/search/index.html#event-types). These events can be viewed in Search using the following queries: - type:PERMISSION_REVOKED - operation:REVOKE_PERMISSION ### Revocation Special Use Cases | | | | | | | ------------------------------------- | --------------------------------------- | -------------------------------------- | ------------------ | ------------------------------------------------------------------------------------------------------ | | Microsoft Modern View Permission Name | Microsoft Advanced View Permission Name | Where is Permission Granted From? | Can it be Revoked? | Notes | | Owner | Full Control | User Direct Access | Yes | OneDrive and SharePoint Online UI labels these as **Owner**, but they are standard direct permissions. | | | Permission Inherited from Parent | No | | | | | Permission Inherited from Group | No | | | | Owner | | Site Collection Administrators Setting | No | The primary creator or owner of the resource cannot be revoked. | | | Site collection administrator | User Direct Access | No | High-level admin rights cannot be revoked. | - [**Overexposed**](#overexposed-view) - Accessible by everyone or a larger part of the organization. The definition for overexposed can be configured through the Overexposed Resources section within the General tab under Settings. There are three different scope or view types: - Unique Permissions or Critical Data - Unique Permission only - Critical Data only - [**Excess**](#excess-view) — View users who overlap and have redundant access paths granting similar or excessive permissions to the same resource. ## Overexposed View This screen allows the user to view overexposed resources which are resources that have numerous members. You can view the following information on this screen: - The resource path of the selected resource - The group responsible for the overexposure - The type of overexposed access - The data classification categories within the resource All connected applications display within the left-hand window under the All Application tab. If there are a lot of applications, there are multiple ways to find the desired one. If you know the application name or application path, use the search bar to locate it. Use the filter icon in the search bar to select the **Search contains resource name** option. This option allows the user to fine-tune the search if they know a specific name or phrase in the name of the application. Under the My Resources tab, a user can see all of the resources they own. Note Administrators can view both the All Application and My Resources tabs. Data owners can only view the My Resources tab. ## Excess View This screen provides information on users who have excessive permissions within the organization, such as stale or redundant permissions. The heatmap visually displays these excess access paths for the selected resource. The size of each block represents the amount of redundant access paths that have been granted or the amount of excessive permissions that the resource has. The heatmap blocks have distinct colors according to the time period they have been unused by the user. The color legend which depicts the level of staleness is at the top of the heatmap. Additionally, the Excess View screen allows data to be filtered based on permission staleness. Selecting a block provides the user with a snapsnot of information regarding that resource including user information, the permission count, and the types of permissions granted. For more information on that selected resource, select **View Access Paths**. After selecting View Access Paths, you can select between two tabs on the View Details window. - Permission List – provides the same type of info that was presented when the resource block was selected from the heatmap. - Access Paths – provides a tree view of the user with all of the access they have. Each colored branch depicts the timeframe that resource was last used. # Test Connection After the configuration of one of the following applications is complete, verify it was properly configured by running the Test Connection task. After running the test connection, you will be able to view the connection status on the Applications main page. # Test Connection Detailed View To see more detailed information about the status of a specific application, select the more options button within the Actions column. 1. Select **Test Connection**. A new overlay will display providing further information as to the configuration status of the application. - All tasks associated with the application that were run displays in the Check Name column - The status of the connection status displays in the Status column: - Passed – the configuration of the application was successful. - Failed – the configuration of the application was not successful. A dialog displays providing a reason and/or a suggestion on how to fix the issue. - Warning – a pop up will display with an explanation of the error and a recommendation for solving the issue. If any task fails or has warnings, an information icon displays to the right of the Status column. Click the information icon to see the reason for the failure and a recommendation on how to fix it. Note If any task fails within the application configuration, the whole test connection will fail, which displays on the main Application page. There are three buttons at the bottom of the overlay that the user can select: - Run – runs the test connection task - Refresh – refreshes the grid and displays the latest results - View Task Status – takes the user to the task screen and displays the relevant task If a test connection task has not been run on a specific application, the overlay will be empty. # Run a Test Connection To view or run an application's connection status, navigate to **Admin > Applications** to view the Applications page. ## For Multiple Applications 1. Using the selection boxes to the left of the applications, select the applications that need validation. Note A single application or multiple applications can be selected. 1. Select **Test Connection**. A confirmation message displays and includes the selected applications that will be tested. To view the result, go to [Test Connection Detailed View](https://documentation.sailpoint.com/das/help/test_connection/detailed_view.html). ## For a Single Application 1. Select the more options button within the Actions column. 1. Select **Test Connection**. 1. Select **Run**. A user can also select **Refresh** which refreshes the grid and displays the latest results or **View Task Status** which takes a user to the Task screen in order to view a relevant task. ## Filter Using the filter ability, a user can view all applications which support the Test Connection feature based on their test connection statuses. 1. Select the Filter icon. There are several filters available: - Name - type the name of the application - Type - select Test Connection - Tags - a string that was set during the application configuration - Test Connection Status - select the statuses you want to search for (either Passed, Warning, or Failed). - Supported for test connection only 1. Select **Apply**.