Time Zone
Safeguard for Privileged Passwords sets a default time zone based on the location of the person performing the set up. The time zone is expressed as UTC + or – hours:minutes and is used for timed access (for example, access from 9 a.m. to 5 p.m.). It is recommended that the Bootstrap Administrator set the desired time zone on set-up. An Authorizer Administrator can also change the time zone.
To configure the time zone
- Navigate to User Management > Settings > Time Zone.
- The User Administrator can search for and select the desired time zone.
- The User Administrator can change Allow users to modify their own time zone.
- Enable the setting to let users change their time zone (the default).
- Disable the setting to prohibit a user from changing their time zone, possibly to ensure the user conforms with policy.
Reports
Reports allows users to view and export reports that show which assets, accounts, users, tags, and partitions a selected user manages. Reports can be exported in .csv or .json format.
In the web client, the Reports section contains the following sub-pages:
-
Activity Center: The Activity Center is the place to go to view the details of specific events or user activity. The appliance records all activities performed within Safeguard for Privileged Passwords. Any administrator has access to the audit log information; however, your administrator permission set determines what audit data you can access.
-
Entitlements: Safeguard for Privileged Passwords provides the following types of entitlement reports (for more information, see Entitlement reports):
NOTE: The number indicated in the tab title shows the number of unique users, assets, or accounts. When you enter search criteria for the report, the number displayed on the tab will adjust accordingly.
- User: Lists information about the accounts a selected user is authorized to request.
- Asset: Lists information about the accounts associated with a selected asset and the users who have authorization to request those accounts.
- Account: Lists detailed information about the users who have authorization to request a selected account including: Entitlement, Policy, Access Type, Password Included, Password Change, Time Restrictions, Expiration Date, Group, From Linked Account, and Last Accessed.
-
Ownership: Safeguard for Privileged Passwords provides these ownership reports (for more information, see Ownership reports):
NOTE: The number indicated in the tab title shows the number of unique users, partitions, assets, accounts, or tags. When you enter search criteria for the report, the number displayed on the tab will adjust accordingly.
-
User: Lists information about ownership based on each owner.
-
Partition: Lists information about ownership for a partition.
-
Asset: Lists information about ownership for an asset.
-
Account: Lists information about ownership for an account.
-
Tag: Lists information about owners of assets and accounts assigned to a tag.
Activity Center
The Activity Center is the place to go to view the details of specific events or user activity. The appliance records all activities performed within Safeguard for Privileged Passwords. Any administrator has access to the audit log information; however, your administrator permission set determines what audit data you can access. For more information, see Administrator permissions.
Applying search criteria
Use the query builder in the Activity Center to add and remove data from your activity audit log report to get the information you need.
By default, an activity audit log report includes all activity occurring within the last 24 hours. However, using the query options provided you can specify search criteria to retrieve specific information from the activity audit log. The available search criteria may include:
- Activity Category: Use this drop-down to narrow parameters and event details.
- Date Range: Use this drop-down to narrow results by hours, days, or a custom time frame you set.
- User Name: Clicking this field opens a dialog where you can select a user for the activity report.
- Asset Name: Clicking this field opens a dialog where you can select the asset for the activity report.
- Account Name: Clicking this field opens a dialog where you can select the account for the activity report.
To apply search criteria to the audit log
Activity Category and Time frame are required to generate a report. Other search criteria is optional and allows you to narrow the report to the exact parameters provided.
- Navigate to the Activity Center (Reports > Activity Center).
-
Activity Category defaults to All Activity (Summary Only). Click the drop-down to limit the report to select the activity category to be included in the report.
-
Date Range defaults to Last 24 Hours. To specify a different time frame, click the drop-down and select the time frame to be included in the report. If using the Custom option, specify the custom date and time range.
- Clicking the User Name field opens a dialog where you can select a user for the activity report.
- When available, clicking the Asset Name field opens a dialog where you can select the asset for the activity report.
- When available, clicking the Account Name field opens a dialog where you can select the account for the activity report.
-
To remove your selections, use Clear Search Criteria to reset the search back to the default.