cancel
Showing results for 
Search instead for 
Did you mean: 

What is the best method to conduct an OnBase Group/User Security Audit?

kliebeng
Champ on-the-rise
Champ on-the-rise

Hi there,

 

I am tasked with conducting an audit of the security/access of OnBase users and groups.   I've ran the User Group / Right Configuration Report and find it to be a little more busy and cumbersome that I would like.  Its fine for ME as a technical person, but I don't think  distributing it to a department or group would be helpful unless I flatten it out. 

 

My intent is to reach out to each a functional owner(s) of each group to have them verify the user memberships and accesses within each group.  

The current solution is holding a meeting(s) where we will look at the Users Groups and Rights menu in Config and get feedback from the content owners on what their setup should be.   This is conceptually pretty easy but I feel that it could be difficult to schedule these meetings or track down a user in every group with the authority to make these decision while on a Zoom meeting.   I would like to find a way to accomplish the same thing a little less real time and give them some liberty to really consider their content permissions and report back asynchronously.

 

I could be making a mountain out of a mole hill and idea of going through the UI together could prove to be the least painless-but I was just wondering if there is another way to accomplish this that I am not privy to.   I do not have database access or anything like that, so I can have a dev generate anything custom like another report or a dashboard to help me.

I would love to hear any thoughts or considerations the community has to offer.  Thanks so much!

1 ACCEPTED ANSWER

Ryan_Wakefield
World-Class Innovator
World-Class Innovator

My first (and biggest) question for you would be, are you using AD-Enhanced with your OnBase installation and setup?

View answer in original post

8 REPLIES 8

Ryan_Wakefield
World-Class Innovator
World-Class Innovator

My first (and biggest) question for you would be, are you using AD-Enhanced with your OnBase installation and setup?

Yes.  We are using AD-Enhanced.  But I believe it is only for access  to Onbase, not to control the permissions on the data.

Ryan_Wakefield
World-Class Innovator
World-Class Innovator

Well, what I can tell you is that depending on how you have your security setup (as in if it is controlled by the security group(s) you are in, then I would highly suggest doing your audit based on the security group(s) that a user is in inside of AD. The reason for this is because a user won't show inside of OnBase unless they have logged into the system. This is due to OnBase not having a true sync with AD.

 

While that might give you who has access to the system (and without being familiar with your configuration) then it will be hard for me to give advice on the rest. However, at least this might help and give you some ideas on how you might be able to go about the rest.

Larissa_Armand
Elite Collaborator
Elite Collaborator

"I do not have database access or anything like that, so I can have a dev generate anything custom like another report or a dashboard to help me."

 

Are you saying you have no ability (from your organization) to query the database or use reporting dashboards with a SQL data provider? 

 

If you are able to at least use reporting dashboards I could share some SQL we've used to report on user group membership and what document types/configuration items groups can access. 

 

Otherwise the built-in reports or doing what you are with reviewing the setup in Config might be the best option.

Getting started

Find what you came for

We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.