Skip to main content

Users reports

Users reports provide information about user profiles, accounts, and related attributes.

Demo

Click below to view a demonstration of running an enrollment report:

Accounts

Purpose: Accounts with their associated profile and target system.

In addition to account long IDs, the report displays the target system that each account was listed from, and the user that owns each account.

Executable: account

Table 1. Accounts report search criteria

Criteria

Description

Account

Type a comma-and-space-delimited list of long IDs (not short IDs) that match the accounts you want to include in the report. Alternatively, you can search for one or more accounts.

Target system ID

Type a comma-and-space-delimited list of target system IDs to only include accounts from those systems. Alternatively, you can search for one or more target systems.

Target system group

Select one or more target groups to include in the report. The list only includes target groups that are in use with the instance being configured.

Account status

Select one or more values to only include accounts with a matching account status. The possible values are:

  • Auto associated: accounts that were automatically associated with a profile ID.

  • Manually claimed: accounts that were manually associated with a profile ID.

  • Unclaimed: accounts that are not associated with a profile ID.

  • Deleted: accounts that can no longer be listed from a target system.

  • Filtered: accounts that have been filtered out by ID filters.

By default, all account statuses are selected. This field applies to detail or summary report types only.

Deleted by

Choose a method on which an account has been removed from the drop-down list. All method is selected by default.

  • All: lists all deleted accounts.

  • Bravura Security Fabric: lists all accounts that were deleted by Bravura Security Fabric. The "track account changes" option must be enabled on the account's target system for it to be listed here.

  • Out-of-band: lists all accounts that were not deleted by Bravura Security Fabric. The "track account changes" option must be enabled on the account's target system for it to be listed here.

  • Other: lists all deleted accounts that belonged to target systems where "track account changes" was not enabled.

Report type

Choose a report type from the drop-down list. The Account details setting is selected by default.

  • Account details: lists accounts by status, User ID, target system, and target group.

  • Account summary: lists the number of accounts of each status.

  • Account as source of profile IDs: lists the number of accounts on target systems that are a source of profile IDs; includes the attribute used to automatically attach accounts to profile IDs, and account status.

  • Account not as source of profile IDs: lists the number of accounts on target systems that are not a source of profile IDs; includes the attribute used to automatically attach accounts to profile IDs, and account status.

Graph type

Specify the type of graph for a visual representation of the data. The available graph types are vertical bar chart, pie chart, and horizontal bar chart. This field is only visible when the account summary report type is selected.



If you do not specify any search criteria, all valid accounts are included in the report.

Table 2. Account details

Column

Condition

Description

Account status

Always

The status of the account. Possible values: Auto associated, Manually claimed, Unclaimed, Filtered, Deleted by Bravura Security Fabric, Deleted out of band, Deleted other.

Account ID

Always

The account login name (long ID).

Removed on

Deleted status is selected

The date and time the account was deleted.

Full name

Auto associated or Manually claimed is selected

The full name of the associated user.

User name

Auto associated or Manually claimed is selected

The profile ID of the associated user.

Target system ID

Always

The target system short ID.

Target system description

Always

The target system display name.

Target system group

Bravura Passis licensed

The target system group ID.



Table 3. Account summary

Column

Description

Statistic

The account status category. Possible values depend on selected filters: Auto associated, Manually claimed, Unclaimed, Deleted by Bravura Security Fabric, Deleted out of band, Deleted other, Filtered.

Value

The number of accounts with that status.



Table 4. Source / non-source accounts on targets

Column

Condition

Description

Target system group

Bravura Pass is licensed

The target system group ID.

Target system ID

Always

The target system short ID.

Target system description

Always

The target system display name.

Associate attribute

Always

The account attribute used to associate accounts with profile IDs. Defaults to SHORTID if not configured.

Filtered

Always

The number of filtered accounts on this target system.

Associated

Always

The number of auto-associated accounts on this target system.

Manually claimed

Always

The number of manually claimed accounts on this target system.

Unclaimed

Always

The number of unclaimed accounts on this target system.

Deleted

Always

The number of deleted accounts on this target system.



The source/non-source report includes a summary row with totals for each numeric column.

Resource authorizers

Purpose: Authorizers and the resources to which they are assigned.

Executable: authorizers

Table 5. Resource authorizers report search criteria

Criteria

Description

Authorizer ID

Type a comma-and-space-delimited list of profile IDs that match the authorizers you want to list resources for. Alternatively, you can search for one or more authorizers. This option is only displayed if Authorizer type is set to List explicitly assigned .

Target system ID

Type a comma-and-space-delimited list of target system IDs to only include Accounts and Managed groups from those systems in the report. Alternatively, you can search for one or more target systems.

Roles

Type a comma-and-space-delimited list of roles for which you want to list authorizers. Alternatively, you can search for one or more authorizers.

Managed groups

Type the long ID of one or more managed groups for which you want to list authorizers. Alternatively, you can search for one or more managed groups.

Template accounts

Select one or more template accounts for which you want to list authorizers.

Managed system policy ID

Select one or more managed system policy IDs for which you want to list authorizers.

Segregation of duties rules

Select one or more segregation of duties (SoD) rules for which you want to list authorizers.

This option is only displayed if there are SoD rules configured.

Authorizer type

Set the type of authorizers that you want to list:

  • List explicitly assigned: authorizers explicitly assigned to at least one resource

  • List workflow managers: workflow managers assigned by user access rules

  • List delegation managers: delegation managers assigned by user access rules

  • {reportList authorization user class: user class assigned for authorization



The report output depends on the selected Authorizer type.

Explicitly assigned

When Authorizer type is set to List explicitly assigned, the report displays the following columns:

Table 6. Resource authorizers report output — explicitly assigned

Column

Description

Authorizer ID

The profile ID of the authorizer.

Authorizer name

The full name of the authorizer.

Resource type

The type of resource (target system, role, managed group, template, managed system policy, SoD rule).

Resource ID

The resource identifier.

Resource description

The description of the resource.

Phase

The authorization phase.



Workflow managers / Delegation managers

When Authorizer type is set to List workflow managers or List delegation managers, the report lists only the authorizer identity without resource details:

Table 7. Resource authorizers report output — workflow managers / delegation managers

Column

Description

Authorizer ID

The profile ID of the authorizer.

Authorizer name

The full name of the authorizer.



User class assigned

When Authorizer type is set to List authorization user class, the report displays the following columns:

Table 8. Resource authorizers report output — user class assigned

Column

Description

Resource type

The type of resource.

Resource ID

The resource identifier.

Resource name

The name of the resource.

Authorizer ID

The profile ID of the authorizer (resolved from user class).

Authorizer name

The full name of the authorizer.

Phase

The authorization phase.



Delegation

Purpose: Current and archived delegation requests - details and statistics.

Executable: delegation

Table 9. Delegation report search criteria

Criteria

Description

Primary user ID

Type the profile ID of the primary authorizer for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

Delegate user ID

Type the profile ID of the delegate for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

Participant

Select the type of delegation:

  • (All): to include requests for all types of delegations (default)

  • Authorizer: to only include requests to delegate authorization tasks

  • Implementer: to only include requests to delegate implementation tasks

  • Reviewer: to only include Certification delegate

Earliest escalation date

(Optional) Choose a date range during which the delegation is in effect.

Latest escalation date

(Optional) Choose a date range during which the delegation round ended or will end.

Delegable

Select:

  • (All): to include all delegation requests regardless of whether the responsibilities are delegable.

  • True: to only include delegation requests where the responsibilities are delegable

  • False: to only include delegation requests where the responsibilities are not delegable

The term delegable means that the delegate user is allowed to delegate the inherited responsibilities, along with his or her own responsibilities, to someone else.

Status

Select one or more statuses to include in the report. This is the status of the delegation request.

Required to accept

Select:

  • (All): to include all delegation requests regardless of whether the delegate was asked to respond

  • True: to only include delegation requests where the delegate was asked to respond

  • False: to only include delegation requests where the delegate was not asked to respond

Report type

  • Detailed: The default detailed output

  • Summary by user: The summary by user mode. In this mode, the report output contains delegation-request statistics for each primary authorizer, as well as for the entire system. Statistics includes the total number of delegation requests, and the total number of requests in each status.

  • Total for all users: The total summary mode. In this mode, the report output contains delegation-request statistics for all delegation types. Statistics include the total number of delegation requests, and the total number of requests in each status.

Graph type:

Select the graph type:

  • (None): no graph will be generated.

  • Vertical bar chart: a vertical bar chart for different delegation type will be generated.



If you do not specify any search criteria, the report is generated for all delegation requests.

The columns displayed in the report output depend on the selected report type.

Detailed mode
Table 10. Delegation report output — Detailed mode

Column

Condition

Description

Delegator

Always

The primary authorizer who delegated responsibilities.

Delegate

Always

The user who received the delegated responsibilities.

Delegation type

Not in Bravura Privilege-only mode

The type of delegation: Authorizer, Implementer, Reviewer, or All.

Start date

Always

The date the delegation takes effect.

End date

Always

The date the delegation expires.

Delegable

Always

Whether the delegate can further delegate. Values: Yes, No.

Default action

Always

The default action if the delegate does not respond.

Acceptance needed

Always

Whether the delegate must accept the delegation. Values: Yes, No.

Response time

Always

The deadline for the delegate to respond.

Verified

Not in drill-down mode

The verification status of the delegation.

Reason

Always

The reason for the delegation status.



Summary by user mode
Table 11. Delegation report output — Summary by user mode

Column

Condition

Description

Delegator

Always

The primary authorizer.

Delegation type

Not in Bravura Privilege-only mode

The type of delegation.

Accepted

Always

Number of accepted delegation requests.

Not responded

Always

Number of delegation requests with no response.

Rejected

Always

Number of rejected delegation requests.

Escalated

Always

Number of escalated delegation requests.

Canceled

Always

Number of canceled delegation requests.

Total

Always

Total number of delegation requests.



Total for all users mode

The "Total for all users" mode uses the same columns as "Summary by user" but without the Delegator column, showing only totals by delegation type.

Enrollment

Purpose: Detailed and statistical overview of the progress of user enrollment.

Executable: enrollment

Table 12. Enrollment report search criteria

Criteria

Description

User ID

Type the profile ID of the user for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

User name

Type the full name of the user for whom you want to generate the report.

Status match

Select whether to display users with any of the statuses, or all of them.

Status

Select the enrollment statuses that you want to add to the report output.

Enrollment type

Select the types of enrollment that you want to add to the report output:

  • Update security questions

  • Generate voice print enrollment PIN

  • Attach other accounts

  • Password synchronization registration

  • Mobile devices

  • View and update profile

Show detailed report

Select this checkbox to display additional report details.

Graph type

Select the chart type for the graph. This option will only show when Show detailed report option is not selected.



The report output depends on whether the Show detailed report option is selected.

Detailed mode

When Show detailed report is selected, the report displays the following columns:

Table 13. Enrollment report output — Detailed mode

Column

Condition

Description

User ID

Always (non-drill-down)

The profile ID of the user.

User name

Always (non-drill-down)

The full name of the user.

User

Drill-down only

Combined user name and profile link.

Security questions status

Enrollment type selected

The enrollment status for security questions.

Last modified date

Security questions selected

The date the security questions were last modified.

Voice print PIN status

Enrollment type selected

The enrollment status for voice print PIN.

Attach other accounts status

Enrollment type selected

The enrollment status for attaching other accounts.

Password synchronization status

Enrollment type selected

The enrollment status for password synchronization registration.

Mobile devices status

Enrollment type selected

The enrollment status for mobile devices.

View and update profile status

Enrollment type selected

The enrollment status for profile updates.



Note

The columns shown depend on which enrollment types are selected in the search criteria. Each selected enrollment type adds its status column.

Summary mode

When Show detailed report is not selected, the report displays the following columns:

Table 14. Enrollment report output — Summary mode

Column

Description

Enrollment type

The type of enrollment.

Status / Count columns

Dynamic columns based on selected statuses, showing the number of users with each status for each enrollment type.



Password status on target systems

Purpose: Last-change date, expiry date and current status for passwords on target systems.

Executable: expiry

Table 15. Password status on target systems report search criteria

Criteria

Description

User ID

Type the profile ID of the user for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

User name

Type the full name of the user for whom you want to generate the report.

Users must have accounts on at least one of these target systems

Type a comma-and-space-delimited list of target system IDs on which users must have accounts. Alternatively, you can search for one or more target systems.

Target system group

Select the target system groups you want to add to the report output.

Password expiration date

(Optional) Choose a date range to define a password expiration date.

Password expiration dates to display

Select the types of password expiration dates you want to add to the report output.

Show all accounts

If users have multiple accounts, select this checkbox to list the password change date, expiry date and status for all accounts.



Table 16. Password status on target systems report output

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Account long ID

The long ID of the account.

Target system ID

The target system short ID.

Target system description

The target system display name.

Target system group

The target system group ID.

Password status

The current status of the password.

Password expiration date

The date the password expires.

Target expiration date

The password expiration date as reported by the target system.

Last changed

The date the password was last changed.



Implementers

Purpose: Resources and associated operations assigned to human implementers (not connectors).

Executable: implementerreport

Table 17. Implementers report search criteria

Criteria

Description

Implementer type

Select the implementer type:

  • Explicitly assigned

  • Assigned by user class

Implementer ID

Type the profile ID of the implementer for whom you want to run the report. Alternatively, you can search for one or more profile IDs.

Target system ID

Type a comma-and-space-delimited list of target system IDs to only include accounts from those systems. Alternatively, you can search for one or more target systems.

Operation

Select the operations that you want to include. All operations are included by default.

This is only shown when implementer type is set to explicitly assigned.



The report output depends on the selected implementer type.

Explicitly assigned

When the implementer type is set to Explicitly assigned, the report displays the following columns:

Table 18. Implementers report output — Explicitly assigned

Column

Description

Implementer ID

The profile ID of the implementer.

Target system ID

The target system short ID.

Resource type

The type of resource.

Inherited from

The source from which the implementation assignment is inherited.

Resource ID

The resource identifier.

Resource description

The description of the resource.

Operation

The operation assigned to the implementer.

Inherited implementer removed

Whether the inherited implementer has been removed.



Assigned by user class

When the implementer type is set to Assigned by user class, the report displays the following columns:

Table 19. Implementers report output — Assigned by user class

Column

Description

Target system ID

The target system short ID.

Resource type

The type of resource.

Resource ID

The resource identifier.

Resource description

The description of the resource.

Implementer ID

The profile ID of the implementer (resolved from user class).



Orphan / Inactive

Purpose: Lists:

  • Unclaimed accounts

  • Users without an associated account

  • Dormant accounts

  • Dormant profiles

    "Dormant accounts" are user objects on target systems where the user has not logged in for at least N days. This number is defined by the Show inactive accounts (days) search criteria. See below for details.

    "Dormant profiles" are user profiles in Bravura Security Fabric , containing one or more accounts, all of which are dormant.

Note

You should generate a full attribute listing before running this report for a target system. To do this, click Generate full list on the Target system information page, then run auto discovery.

Bravura Security Fabric only supports Microsoft Active Directory and Microsoft Windows server target systems for use with the Orphan / inactive report. This report only supports Active Directory target systems running on Microsoft Windows Server 2008 or newer.

Executable: orphan

Table 20. Orphan / Inactive report search criteria

Criteria

Description

Report type

Choose a report type from the drop-down list. The Orphan accounts (not attached to a profile) setting is selected by default.

  • Orphan accounts (not attached to a profile): Lists accounts that are not associated with any user's profile ID.

  • Orphan profiles (have no accounts): lists profile IDs that do not have an associated account.

  • Inactive accounts (N days with no login): lists dormant accounts.

  • Inactive profiles (N days with no login): lists dormant user profiles.

Target system ID

To list unclaimed or inactive accounts for one or more target systems, type a comma-and-space-delimited list of target system IDs. Alternatively, you can search for one or more target systems. The search engine only returns results for manually added target systems, not for discovered systems.

This option is only displayed if Report type is set to Orphan accounts (not attached to a profile) or Inactive accounts (N days with no login) .

Account

Type a comma-and-space-delimited list of long IDs (not short IDs) that match the accounts you want to include in the report. Alternatively, you can search for one or more accounts.

This option is only displayed if Report type is set to Orphan accounts (not attached to a profile) , Inactive accounts (N days with no login) or Inactive profiles (N days with no login) .

User ID

Type the profile ID of the user for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

This option is only displayed if Report type is set to Orphan profiles (have no accounts), Inactive accounts (N days with no login) or Inactive profiles (N days with no login) .

User name

Type the full name of the user for whom you want to generate the report.

This option is only displayed if Report type is set to Orphan profiles (have no accounts), Inactive accounts (N days with no login) or Inactive profiles (N days with no login) .

Number of days with no login

Type a numeric value to only show accounts/profiles that have been dormant for the specified number of days.

This option is only displayed if Report type is set to Inactive accounts (N days with no login) or Inactive profiles (N days with no login) .

Discovered in the last N days

Type a numeric value to filter results based on how recently the account was discovered during auto-discovery. A value of zero will return all results.

This option is only displayed if Report type is set to Orphan accounts (not attached to a profile) .



The columns displayed in the report output depend on the selected report type.

Orphan accounts (unclaimed)
Table 21. Orphan / Inactive report output — Orphan accounts (unclaimed)

Column

Description

Target system ID

The target system short ID.

Target system description

The target system display name.

Account long ID

The long ID of the unclaimed account.

Discovered on

The date the account was discovered.



Orphan profiles (no accounts)
Table 22. Orphan / Inactive report output — Orphan profiles (no accounts)

Column

Description

User name

The full name of the user.

User long ID

The profile long ID.



Inactive accounts
Table 23. Orphan / Inactive report output — Inactive accounts

Column

Description

User ID

The profile ID of the account owner.

User name

The full name of the user.

Account ID

The account login name.

Target system ID

The target system short ID.

Target system description

The target system display name.

Last login

The date of the last login on the target system.

Account creation date

The date the account was created.



Inactive profiles

The Inactive profiles mode uses the same columns as Inactive accounts.

Access to product features

Purpose: Security privileges held by product administrators.

Lists product administrators, privileges, and finds product administrators with selected administrative privileges.

Executable: prodadmin

Table 24. Access to product features report search criteria

Criteria

Description

Product administrator

Type a comma-and-space-delimited list of product administrators to include in the report. Alternatively, you can search for one or more product administrators. The default is all product administrators.

Administrative privileges

Select one or more privileges to search on. All privileges are selected by default.

Administrator group ID

Select one or more groups to search on. All groups are selected by default.

This field is not displayed if there is no data available.

Source of privileges

You can specify whether to report on privileges granted to individual administrators, or granted by group membership.



The report displays the following columns:

Table 25. Access to product features report output

Column

Description

Product administrator

The profile ID of the product administrator.

Administrative privilege

The name of the administrative privilege.

Administrator group

The administrator group through which the privilege is granted.

CIDR

The CIDR network restriction for the privilege.



Profile and request attributes

Purpose: Provides information about users, and profile attributes.

Executable: userattr

Table 26. Profile and request attributes report search criteria

Criteria

Description

User ID

Type a comma-and-space-delimited list of profile IDs to only include profile attributes for certain users. Alternatively, you can search for one or more profile IDs.

Profile attribute

Select a profile attribute on which to filter users. You can select up to eight attributes. You can also select the same attribute multiple times; for example, you may want to list all users whose first name is 'Mike' or 'Michael'. All profile attributes are available, except for request-only attributes and encrypted attributes.

If no attributes are specified, the report lists all user profiles filtered by user ID.

Value type

This field is displayed if a Profile attribute field is other than Attribute not required. Select the value type of comparator to apply on selected the profile attribute. Different types of attributes have access to different sets of value types.

  • is empty if you want Bravura Security Fabric to search on empty values.

  • is not empty if you want Bravura Security Fabric to search on non empty values.

  • is equal to if you want Bravura Security Fabric to search on values equal to a specified string.

  • is not equal to if you want Bravura Security Fabric to search on values not equal to a specified string.

  • is less than if you want Bravura Security Fabric to search on values that are less than a specific integer.

  • is less than or equal to if you want Bravura Security Fabric to search on values that are less than or equal to a specific integer.

  • is greater than if you want Bravura Security Fabric to search on values that are greater than a specific integer.

  • is greater than or equal to if you want Bravura Security Fabric to search on values that are greater than or equal to a specific integer.

  • is greater than or equal to if you want Bravura Security Fabric to search on values that are greater than or equal to a specific integer.

  • Is later than today + N days if you want Bravura Security Fabric to search on dates that are later than N days after today.

  • is earlier than, or equal to, today - N days if you want Bravura Security Fabric to search on dates that are earlier or equal to N days before today.

Value

This field is displayed and required if a Value type field is set to something other than is empty or is not empty. Type or select the value to compare with.

Display of attributes

Choose the display mode for attributes. Select:

  • All attributes if you want all non null account attributes to be displayed by the report.

  • Searched on attributes if you only want the account attributes that are searched on to be displayed by the report.

  • No attributes if you want no account attributes to be displayed by the report.

Attributes that are searched on will be displayed in the All attributes and Searched on attributes modes, regardless of whether they are null.

Attribute match

Select:

  • Match on all if you want Bravura Security Fabric to match on all the profile attribute rows.

  • Match on any if you want Bravura Security Fabric to match on any profile attribute rows.



The columns displayed depend on the Display of attributes setting.

Table 27. Profile and request attributes report output

Column

Condition

Description

User ID

Always

The profile ID of the user.

User name

Always

The full name of the user.

Attribute

Display of attributes is not "No attributes"

The profile attribute name.

Value

Display of attributes is not "No attributes"

The profile attribute value.

Display value

Display of attributes is not "No attributes"

The display value of the attribute.

Attribute type

Display of attributes is not "No attributes"

The data type of the attribute.



Profiles

Purpose: Provides information about user profiles, including accounts, group memberships, and identity attributes.

Executable: users

Table 28. Profiles report search criteria

Criteria

Description

User ID

Type a comma-and-space-delimited list of profile IDs to only include information about certain users. Alternatively, you can search for one or more profile IDs.

User name

Type the full name of the user for whom you want to generate the report.

User attribute to search

Select a profile attribute on which to filter users. The options include all available profile attributes, excluding request-only attributes.

Attribute value to search

This field is displayed if User attribute to search is other than Attribute not required. Type the value of the user attribute.

This searches against the attribute's stored string value in the database, regardless of attribute type.

User attributes to display

Select one or more profile attributes that you want to add to the report output.

List only product administrators

Filter the report to list only product administrators. This applies only to individual product administrators, not users added to administrator groups.

Account restriction

Select one of the following options to filter users based on whether they have accounts:

  • (No restriction)

  • Only users with accounts.

  • Only users without accounts.

Profile status

Select one or more of the following options to filter users based on the profile status:

  • Locked.

  • Unlocked.

  • Enabled.

  • Disabled.

RBAC enforcement

Select one of the following options to filter users based on RBAC enforcement:

  • All users.

  • Users under RBAC enforcement.

  • Users not under RBAC enforcement.

Show accounts

Select this checkbox to include a list of each user's accounts in the report output.

Users must have accounts on at least one of these target systems

Type a comma-and-space-delimited list of target system IDs on which users must have accounts. Alternatively, you can search for one or more target systems.

Target system group

Select the target system groups that you want to add to the report output.

Show managed groups

Select this checkbox to include a list of each user's managed groups in the report output.

Managed groups

Type the long ID of one or more managed groups in which users must have accounts. Alternatively, you can search for one or more managed groups.

Last login time

(Optional) Choose a date range to define a date range for the last login time.

Summarize report

Select this checkbox to summarize the report details.

In this mode, the report includes the number of users, the number of users without accounts, and the license size.



If you do not specify any search criteria or select any options, the report output includes the profile ID and full name of every Bravura Security Fabric user.

Table 29. Profiles detail

Column

Condition

Description

User ID

Always

The profile ID of the user.

User name

Always

The full name of the user.

Profile status

Always

The lock and enable state of the profile. Displayed as a comma-separated pair, for example "Locked, Enabled" or "Unlocked, Disabled".

User attributes

User attributes to display is selected

One column per selected profile attribute, showing the attribute value for each user.

Last login

Last login time date range is specified

The date of the user's last login.

Account long ID

Show accounts is selected

The long ID of the user's account.

Target system ID

Show accounts or Show managed groups is selected

The target system short ID.

Target system description

Show accounts or Show managed groups is selected

The target system display name.

Target system group

Show accounts is selected and Bravura Pass is licensed

The target system group ID.

Group ID

Show managed groups is selected

The managed group name.

Group description

Show managed groups is selected

The description of the managed group.



Table 30. Profiles summary

Column

Description

Statistic

The summary category. Values: Number of users, Users without accounts, Licensed users.

Value

The count for each statistic.



Userstat

Purpose: Lists information about users with associated tags in the userstat database table.

Executable: userstat

Table 31. Userstat report search criteria

Criteria

Description

User ID

Type the profile ID of the user for whom you want to generate the report. Alternatively, you can search for one or more profile IDs.

User name

Type the full name of the user for whom you want to generate the report.

Tags

Select one or more tags to list the users associated with these tags.

This field is not displayed if there is no data available.

Tag value

Type a tag value to list the tags and associated users.

Report type

Choose a report type from the drop-down list. The Details report is selected by default.

  • Detailed: lists accounts with tags by User ID, User name, Tag ID and Tag value.

  • Users without tag or not matching tag value: lists accounts without tags or not matching tag value by User ID, Username and Tag ID.

  • Summary: lists a summary of each tag; includes the total number of users with, and without the tag value for each tag.



The columns displayed in the report output depend on the selected report type.

Detailed
Table 32. Userstat report output — Detailed

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Tag

The tag identifier.

Tag value

The value of the tag.



Users without tag or not matching tag value
Table 33. Userstat report output — Users without tag or not matching tag value

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Tag

The tag identifier.



Summary
Table 34. Userstat report output — Summary

Column

Description

Tag

The tag identifier.

Tag value

The tag value.

Users with tag

The number of users with this tag value.

Users without tag

The number of users without this tag value.



Resources per user

Purpose: View resources (accounts, group memberships, roles, user classes, delegations, authorizer power and access privileges) associated with a given set of users.

Executable: userresources

Criteria

Description

User ID

Type a comma-and-space-delimited list of the profile IDs you want to include in the report. Alternatively, you can search for one or more profile IDs.

User attributes to display

Select the profile attributes that you want to add to the report output. This option is only available when Summarize report is unselected. Default: none.

Sections to display

Select the sections you want to add to the report output. Default: all.

Number of entitlements

Select an option to filter out users by total number of entitlements. This option is only available when Summarize report is selected.

  • No threshold: lists all users.

  • Threshold for minimum number of entitlements: only lists the users whose total number of entitlements is not less than the threshold.

  • Threshold for maximum number of entitlements: only lists the users whose total number of entitlements is not greater than the threshold.

Threshold value

Type a number to define the threshold. The default value is 1. This option is only available in summary mode when 'Threshold for minimum number of entitlements' or 'Threshold for maximum number of entitlements' is selected for Number of entitlements.

Summarize report

Check to summarize the report details.

This report has two output modes depending on whether Summarize report is selected.

Detailed mode (default)

When Summarize report is not selected, the report displays one section per user in a vertical (long) view, with rows for each resource type. Selected user attributes are displayed as additional rows.

Table 35. Resources per user report output — detailed mode

Column

Description

Attribute

The resource attribute name (for example, account, group, role, user class, delegation).

Value

The resource attribute value.

Description

A description of the resource.



Summary mode

When Summarize report is selected, the report displays one row per user with counts for each resource type. The columns displayed depend on the Sections to display selection.

Table 36. Resources per user report output — summary mode

Column

Condition

Description

User ID

Always

The profile ID of the user.

User name

Always

The full name of the user.

Last login

Always

The date of the user's last login.

Profile status

Always

The lock and enable state of the profile.

Total entitlements

Always

The total number of entitlements for the user.

Accounts

Sections to display includes accounts

The number of accounts.

Groups

Sections to display includes groups

The number of group memberships.

Roles

Sections to display includes roles

The number of role assignments.

Subordinates

Sections to display includes subordinates

The number of subordinates.

User classes

Sections to display includes user classes

The number of user class memberships.

Delegations from

Sections to display includes delegations

The number of delegations from this user.

Delegations to

Sections to display includes delegations

The number of delegations to this user.

Explicit authorizer (targets, roles, groups, templates, policies)

Sections to display includes authorizer

Counts per resource type for explicit authorizer assignments. Multiple columns.

User class authorizer (targets, roles, groups, templates, policies)

Sections to display includes authorizer

Counts per resource type for user class authorizer assignments. Multiple columns.

Access privileges (global help desk, self-service, delegated admin requester, delegated admin recipient)

Sections to display includes access privileges

Counts per access privilege type. Multiple columns.



Account attributes

Purpose: Lists accounts and account attributes

Executable: accountattr

Table 37. Account attributes report search criteria

Criteria

Description

Account

Type a comma-and-space-delimited list of long IDs (not short IDs) that match the accounts you want to include in the report. Alternatively, you can search for one or more accounts.

User ID

Type a comma-and-space-delimited list of profile IDs to only include accounts belonging to certain users. Alternatively, you can search for one or more profile IDs.

Target system ID

Type a comma-and-space-delimited list of target system IDs to only include accounts from those systems. Alternatively, you can search for one or more target systems.

Account attribute

Select an attribute on which to filter accounts. You can select up to eight attributes. You can also select the same attribute multiple times; for example, you may want to list all accounts where 'givenName' is 'Mike' or 'Michael'.

Value

Type the value of the account attribute. This field is only displayed if an attribute is selected to filter accounts.

Display of attributes

From the drop-down list, select:

  • All attributes if you want all account attributes to be displayed in the report. By default, all attributes are shown.

  • Searched on attributes if you want only the account attributes selected for filtering to be displayed in the report.

  • No attributes if you want no account attributes to be displayed in the report.

Encrypted attribute values are masked.

Attribute match

From the drop-down list, select:

  • Match on all if you want Bravura Security Fabric to match on all the account attribute rows.

  • Match on any if you want Bravura Security Fabric to match on any account attribute row.



The report displays the following columns:

Table 38. Account attributes report output

Column

Condition

Description

User ID

Always

The profile ID of the account owner.

User name

Always

The full name of the account owner.

Account long ID

Always

The long ID of the account.

Target system ID

Always

The target system short ID.

Attribute

Display of attributes is not "No attributes"

The account attribute name.

Value

Display of attributes is not "No attributes"

The account attribute value. Encrypted values are masked.



Password profile attribute fulfillment

Purpose: Provides details about who has set a password for profile attributes of type password.

Executable: PasswordUserAttrFulfilment

Table 39. Password profile attribute fulfillment report search criteria

Criteria

Description

User ID

Type a comma-and-space-delimited list of profile IDs to only include profile attributes for certain users. Alternatively, you can search for one or more profile IDs.

User attribute to search

Select a profile attribute on which to filter users. The options include profile attributes of type password.

Condition

Select one or more of the following options of the following options to filter users based on whether they set a value for a profile attribute of type password:

  • Is set

  • Is not set



Table 40. Password profile attribute fulfillment report output

Column

Description

User ID

The profile ID of the user.

User name

The full name of the user.

Attribute

The profile attribute name (password type).

Is set

Whether the user has set a value for this attribute. Values: Yes, No.