Veritas Data Insight User's Guide
- Section I. Introduction
- Section II. Data Insight Workspace
- Navigating the Workspace tab
- Analyzing data using the Workspace views
- Viewing access information for files and folders
- About viewing file or folder summary
- Viewing the overview of a data source
- Managing data custodian for paths
- Viewing the summary of user activity on a file or folder
- Viewing user activity on files or folders
- Viewing file and folder activity
- Viewing CIFS permissions on folders
- Viewing NFS permissions on folders
- Viewing SharePoint permissions for folders
- Viewing Box permissions on folders
- Viewing audit logs for files and folders
- About visualizing collaboration on a share
- Viewing access information for users and user groups
- Viewing the overview of a user
- Viewing the overview of a group
- Managing custodian assignments for users
- Viewing folder activity by users
- Viewing CIFS permissions for users
- Viewing CIFS permissions for user groups
- Viewing NFS permissions for users and user groups
- Viewing SharePoint permissions for users and user groups
- Viewing Box permissions for users and user groups
- Viewing audit logs for users
- Section III. Data Insight reports
- Using Data Insight reports
- About Data Insight reports
- How Data Insight reporting works
- Creating a report
- About Data Insight security reports
- Activity Details report
- Permissions reports
- Inactive Users
- Path Permissions
- Permissions Search report
- About Permissions Query templates
- Creating a Permissions Query Template
- Creating custom rules
- Permissions Query Template actions
- Using Permissions Search report output to remediate permissions
- Entitlement Review
- User/Group Permissions
- Group Change Impact Analysis
- Ownership Reports
- Create/Edit security report options
- Data Insight limitations for Box permissions
- About Data Insight storage reports
- Create/Edit storage report options
- About Data Insight custom reports
- Considerations for importing paths using a CSV file
- Managing reports
- About managing Data Insight reports
- Viewing reports
- Filtering a report
- Editing a report
- About sharing reports
- Copying a report
- Running a report
- Viewing the progress of a report
- Customizing a report output
- Configuring a report to generate a truncated output
- Sending a report by email
- Automatically archiving reports
- Canceling a report run
- Deleting a report
- Considerations for viewing reports
- Organizing reports using labels
- Using Data Insight reports
- Section IV. Remediation
- Configuring remediation workflows
- About remediation workflows
- Prerequisites for configuring remediation workflows
- Configuring Self-Service Portal settings
- About workflow templates
- Managing workflow templates
- Creating a workflow using a template
- Managing workflows
- Auditing workflow paths
- Monitoring the progress of a workflow
- Remediating workflow paths
- Using the Self-Service Portal
- About the Self-Service Portal
- Logging in to the Self-Service Portal
- Using the Self-Service Portal to review user entitlements
- Using the Self-Service Portal to manage Data Loss Prevention (DLP) incidents
- Using the Self-Service Portal to confirm ownership of resources
- Using the Self-Service Portal to classify sensitive data
- Managing data
- About managing data using Enterprise Vault and custom scripts
- Managing data from the Shares list view
- Managing inactive data from the Folder Activity tab
- Managing inactive data by using a report
- Archiving workflow paths using Enterprise Vault
- Using custom scripts to manage data
- Pushing classification tags while archiving files into Enterprise Vault
- About adding tags to files, folders, and shares
- Managing permissions
- Configuring remediation workflows
- Appendix A. Command Line Reference
About recommending permission changes
Data Insight allows you to leverage the activity data provided by the audit logs and information about permissions on a path to make recommendations for permission changes. Data Insight enables you to manage permissions on file servers and SharePoint sites to ensure security and compliance with best practices and company policies.
The permission change recommendations help you evaluate the integrity of the assigned permissions. You can monitor the permissions of inactive users to eliminate access risk and lock down open access, and implement recommendations by modifying security groups.
Note:
The permission remediation action from the tab can only be taken by a user with the Server Administrator role. The options to remove users or groups or to revoke permissions using reports are only visible to users with the Server Administrator role and Report Administrators who are allowed to remediate data and permissions.
You can orchestrate permission changes in the following ways:
Recommend that the permissions of inactive users on shares and folders be revoked.
The permission recommendations are calculated after considering the effective permissions for a user or a path, which include share-level permissions.
See About recommending permissions changes for inactive users.
See Reviewing permission recommendations .
See Analyzing permission recommendations and applying changes.
Use the Permissions Search report to remediate permissions.
For more information about the Permissions Search report, see the Veritas Data Insight User's Guide.
Remove direct member users or groups from a group on the tab of the Workspace.
Revoke permissions of specific trustees directly from the tab of the Workspace.
Remove permissions from the Workflows > Audit page on paths that are part of an Entitlement Review workflow.
See Removing permissions for Entitlement Review workflow paths.
You can configure the settings required to implement the permissions recommendations.
Note:
Data Insight does not fetch permissions for the Microsoft OneDrive, SharePoint Online, and Documentum data sources. Hence, you cannot configure permission recommendations for these data sources.