<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Frequently Asked Questions Archives - SecurEnds</title>
	<atom:link href="https://www.securends.com/documentation-category/faq/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.securends.com/documentation-category/faq/</link>
	<description>SecurEnds - User Access / Entitlement Reviews, Identity Access Management, Cloud Access Management, Identity Governance, IGA, IAM</description>
	<lastBuildDate>Thu, 27 Feb 2025 10:01:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.securends.com/wp-content/uploads/2022/02/cropped-se-favicon-new-32x32.png</url>
	<title>Frequently Asked Questions Archives - SecurEnds</title>
	<link>https://www.securends.com/documentation-category/faq/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Login</title>
		<link>https://www.securends.com/documentation/faq-login/</link>
					<comments>https://www.securends.com/documentation/faq-login/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:29:47 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6339</guid>

					<description><![CDATA[<p>What happens if I did not receive an email? Check your spam folder and ask your Email Admin to whitelist the @securends.com domain Once logged in, I do not have access beyond the homepage? Contact your SecurEnds Admin to provision your access accordingly What If I forgot password? If you forgot your password, you can easily reset it using the forgot password link on the login page. All you need is your email.</p>
<p>The post <a href="https://www.securends.com/documentation/faq-login/">Login</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-flow wp-block-group-is-layout-flow">
<h6 class="wp-block-heading" id="h-what-happens-if-i-did-not-receive-an-email"><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-very-dark-gray-color"><strong>What happens if I did not receive an email?</strong></mark></h6>
</div></div>



<ul class="wp-block-list"><li>Check your spam folder and ask your Email Admin to whitelist the @securends.com domain</li></ul>



<h6 class="wp-block-heading" id="h-once-logged-in-i-do-not-have-access-beyond-the-homepage"><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-very-dark-gray-color"><strong>Once logged in, I do not have access beyond the homepage</strong></mark><strong>?</strong></h6>



<ul class="wp-block-list"><li>Contact your SecurEnds Admin to provision your access accordingly</li></ul>



<h6 class="wp-block-heading" id="h-what-if-i-forgot-password"><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-very-dark-gray-color"><strong>What If I forgot password?</strong></mark></h6>



<ul class="wp-block-list"><li>If you forgot your password, you can easily reset it using the forgot password link on the login page. All you need is your email. </li></ul>
<p>The post <a href="https://www.securends.com/documentation/faq-login/">Login</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/faq-login/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>System of Record</title>
		<link>https://www.securends.com/documentation/best-practices-system-of-record/</link>
					<comments>https://www.securends.com/documentation/best-practices-system-of-record/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:28:27 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6335</guid>

					<description><![CDATA[<p>Utilizing the sample data file, the file being uploaded must contain the following headers with the bolded columns&#160;headers&#160;being the required fields. If a field is not marked as required, then that column can remain blank, but the header must still be within the file. Column header order does not have to be in the order listed below as long as the file contains all the headers :&#160; Does it matter if after I sync my SOR application that I have unmatched credentials? What happens if a record is skipped?  What if the System of Record does not have an unrequired column such as “Employee Middle Name”?&#160;</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-system-of-record/">System of Record</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-file"><a id="wp-block-file--media-29a78009-feac-4d1f-a4c4-144475559683" href="https://www.securends.com/wp-content/uploads/2020/12/Sample_File_System_of_Record.csv">Sample_File_System_of_Record</a><a href="https://www.securends.com/wp-content/uploads/2020/12/Sample_File_System_of_Record.csv" class="wp-block-file__button wp-element-button" download aria-describedby="wp-block-file--media-29a78009-feac-4d1f-a4c4-144475559683">Download</a></div>



<p>Utilizing the sample data file, the file being uploaded must contain the following headers with the bolded columns&nbsp;headers&nbsp;being the required fields. If a field is not marked as required, then that column can remain blank, but the header must still be within the file. Column header order does not have to be in the order listed below as long as the file contains all the headers :&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Employee First Name</strong>&nbsp;</li>



<li>Employee Middle Name&nbsp;</li>



<li><strong>Employee Last Name</strong>&nbsp;</li>



<li><strong>Employee Email ID&nbsp;(required if used as a unique identifier)</strong>&nbsp;</li>



<li><strong>Employee</strong>&nbsp;<strong>ID</strong>&nbsp;</li>



<li>Employee Type&nbsp;</li>



<li>Employee Access Status&nbsp;</li>



<li><strong>Manager Email ID</strong>&nbsp;</li>



<li>Group Owner&nbsp;</li>
</ul>



<p><strong>Does it matter if after I sync my SOR application that I have unmatched credentials?</strong></p>



<ul class="wp-block-list">
<li>We at SecurEnds are not big fans of artificially adding People records (identities) into SecurEnds to simply allow unmatched credentials to move to matched.  If your other applications do not have any credentials associated with these unmatched SOR users, then they can stay unmatched in you SOR application.  Doesn&#8217;t hurt anything.</li>



<li>As you start bringing in more applications and if the applications start to have a lot of unmatched records.  Visually inspect those applications credentials with the unmatched SOR users to see if they are associated with unmatched SOR users.  If yes, please inquire with your HR app owner to get those unmatched SOR users an accurate email addresses or update the HR system with their email address so the next sync carries so previously unmatched SOR users into the People data.</li>
</ul>



<p><strong>What happens if a record is skipped? </strong></p>



<ul class="wp-block-list">
<li>Export the skipped records and refer to the&nbsp;“Error Description”&nbsp;column for an explanation on the skipped record&nbsp;</li>
</ul>



<p><strong>What if the System of Record does not have an unrequired column such as “Employee Middle Name”?</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Include the header within your file but leave the column blank&nbsp;</li>
</ul>
<p>The post <a href="https://www.securends.com/documentation/best-practices-system-of-record/">System of Record</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-system-of-record/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Applications</title>
		<link>https://www.securends.com/documentation/best-practices-applications/</link>
					<comments>https://www.securends.com/documentation/best-practices-applications/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:29:01 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6337</guid>

					<description><![CDATA[<p>You can use connectors or CSV files to bring app data into SecurEnds. For the csv file, it can be imported as a CVS, XLSX, or XLS.&#160; Best practices dictate to Save AS a CSV so that data issues, formulas, additional tabs do not become an issue. The mapping exercise for importing will guide you to how the columns in your data are assigned to SecurEnds columns. Each application will require an attribute to make a match with the People records. This attribute can be a first name/last name (separated), an Email address or an Employee ID. Without this matching attribute, SecurEnds cannot lookup the matching identity coming in from your System of Record. If the matching attrinute is not found in the People records, the application credential will be classified as unmatched. Unmatched credentials will not be a part of campaigns. Therefore it is important to get those resolved. While importing a CSV, you will be asked which attribute within your app data will be used to match to identities within the People records. You have the Default option of using a First and Last Name (not full name) or an email address. The second option is by an Employee ID. Note, if matching choice is Employee ID, these values must also exist in your System of Record data so it can be matched. The following bolded fields are required to be matched with columns from your imported file.&#160;If a field is not bolded below, then&#160;it that data is not required. What happens&#160;if&#160;a record is skipped?&#160; What if the&#160;application&#160;does not have an optional data column such as “Employee Middle Name”?&#160; What if the application does not&#160;contain a First Name or Last Name?&#160; I have a batch of unmatched users and I know their unique identifier that corresponds with the SOR data. How can I quickly match these unmatched users? How do I delete an Application?</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-applications/">Applications</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>You can use connectors or CSV files to bring app data into SecurEnds.  For the csv file, it can be imported as a CVS, XLSX, or XLS.&nbsp;  Best practices dictate to Save AS a CSV so that data issues, formulas, additional tabs do not become an issue.  The mapping exercise for importing will guide you to how the columns in your data are assigned to SecurEnds columns.</p>



<p>Each application will require an attribute to make a match with the People records. This attribute can be a first name/last name (separated), an Email address or an Employee ID.  Without this matching attribute, SecurEnds cannot lookup the matching identity coming in from your System of Record.  If the matching attrinute is not found in the People records, the application credential will be classified as unmatched. Unmatched credentials will not be a part of campaigns.  Therefore it is important to get those resolved.</p>



<p>While importing a CSV, you will be asked which attribute within your app data will be used to match to identities within the People records. You have the Default option of using a First and Last Name (not full name) or an email address. The second option is by an Employee ID. Note, if matching choice is Employee ID, these values must also exist in your System of Record data so it can be matched. The following bolded fields are required to be matched with columns from your imported file.&nbsp;If a field is not bolded below, then&nbsp;it that data is not required.</p>



<ul class="wp-block-list">
<li><strong>Employee First Name</strong>&nbsp;&#8211; required if email address is not present</li>



<li><strong>Employee Last Name</strong>&nbsp;&#8211; required if email address is not present&nbsp;</li>



<li><strong>Employee Email ID</strong> &#8211; required if either first name or last name is not present.  You can choose Not Present in File if needed.</li>



<li><strong>Login ID or Username&nbsp;(Credential)</strong> &#8211; Required</li>



<li>Employee Middle Name&nbsp;</li>



<li>Employee ID&nbsp;(required if used as the matching attribute option)&nbsp;</li>



<li>Employee Access Status&nbsp;(keep in mind that this status will be shown in the managers reviews.  You it will be blank if you do not provide one.)</li>



<li>Last Authentication Date&nbsp;</li>



<li>Role/Group/Permission &#8211; required if&nbsp;performing an entitlement review &nbsp;</li>



<li>Role/Group/Permission Description&nbsp;&#8211; not required if this is a duplicate of the entitlement text.</li>



<li>Role Created Date&nbsp;</li>



<li>Login Created Date&nbsp;&nbsp;</li>
</ul>



<p><strong>What happens&nbsp;</strong><strong>if&nbsp;</strong><strong>a record is skipped?</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>Export the skipped records and refer to the “Error Description” column for an explanation on the skipped record.  This typically means there are duplicates in the data file.  Or you have additional unnecessary attributes in the file causing records to appear to be duplicated.</li>



<li>Sometimes, the data in the CSV or table may have true duplicates. First, dedup your data to be sure.  Next, if you have other attributes in the table or columns in the CSV other than the core attributes needed for ingestion, that may cause a duplication. Meaning, maybe 2 records have the same data but extra attribute in the table or column have 2 different values for the same 2 rows for the same data. Since we are not bringing in these extra attributes, SecurEnds will drop those extra attributes and look at it like a duplicate when ingesting or executing the SELECT statement. Also, if you have 2 different Entitlement Descriptions for the same Entitlement, SecurEnds will skip the other entitlement record. So, important that a single entitlement have only one description.</li>
</ul>



<p><strong>What if the&nbsp;application&nbsp;does not have an optional data column such as “Employee Middle Name”?</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>You are not required to match that column to the SecurEnds column header and can leave it blank&nbsp;or not include.</li>
</ul>



<p><strong>What if the application does not&nbsp;</strong><strong>contain a First Name or Last Name?</strong>&nbsp;</p>



<ul class="wp-block-list">
<li>You will then need to have an email address so SecurEnds can match to an identity among the People records.  An employee ID will also work as the matching attribute but only if your system of record is bringing that data into SecurEnds.  Best practice says that you should bring in the first name and last name even if you have email address so that SecurEnds can utilize the First Name or Last Name for the Fuzzy Logic matching logic used for unmatched credentials.&nbsp;</li>
</ul>



<p><strong>I have a batch of unmatched users and I know their unique identifier that corresponds with the SOR data. How can I quickly match these unmatched users?</strong></p>



<ul class="wp-block-list">
<li>In a scenario where a group of users are unmatched for a known reason and you wish to manually match them within SecurEnds, you can do this in bulk.
<ul class="wp-block-list">
<li>Navigate to <strong>Users &gt; Applications &gt; </strong>the application with unmatched users</li>



<li><strong>Actions &gt; More &gt; Bulk Assign</strong></li>



<li>Select the UnMatched radio button and select Download</li>
</ul>
</li>
</ul>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="634" height="289" src="https://www.securends.com/wp-content/uploads/2021/07/image-13.png" alt="" class="wp-image-9326" srcset="https://www.securends.com/wp-content/uploads/2021/07/image-13.png 634w, https://www.securends.com/wp-content/uploads/2021/07/image-13-300x137.png 300w" sizes="(max-width: 634px) 100vw, 634px" /></figure>



<ul class="wp-block-list">
<li>The CSV will contain some data of the unmatched users (see below).  Update the<strong> IAM User</strong> column/attribute (column H) with the email address that corresponds to the identity from the People records (System of Record).  This is not a manager assignment.  You are assigning the unmatched credential to an identity in the People view which will already have a manager assigned.</li>
</ul>



<figure class="wp-block-image size-large"><img decoding="async" width="661" height="331" src="https://www.securends.com/wp-content/uploads/2021/07/image-12.png" alt="" class="wp-image-9325" srcset="https://www.securends.com/wp-content/uploads/2021/07/image-12.png 661w, https://www.securends.com/wp-content/uploads/2021/07/image-12-300x150.png 300w" sizes="(max-width: 661px) 100vw, 661px" /></figure>



<ul class="wp-block-list">
<li>Save your changes as a CSV.  Drop or upload the file and <strong>Bulk Assign</strong> to update the new matches.</li>
</ul>



<p><strong>How do I delete an Application?</strong></p>



<ul class="wp-block-list">
<li>Before you can delete any application, you need to restore any Purged/Excluded/Deleted credentials. Then Bulk Unassign all the credentials so all credentials become unmatched. Go to the app-&gt;Gear icon-&gt;More-&gt;Bulk Assign. Take the CSV and remove all the email address in column H (IAM User). Then Bulk Assign that csv file into SecurEnds for that application. All credentials will move to unmatched and will allow you to delete the application.</li>
</ul>
<p>The post <a href="https://www.securends.com/documentation/best-practices-applications/">Applications</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-applications/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>User Access Reviews</title>
		<link>https://www.securends.com/documentation/best-practices-user-access-reviews/</link>
					<comments>https://www.securends.com/documentation/best-practices-user-access-reviews/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sun, 13 Dec 2020 13:16:59 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6418</guid>

					<description><![CDATA[<p>I finished my last review and it did not save, why? Each page during the review process has a Next button to transition to the next user to be reviewed. This Next has a &#8220;next and save&#8221; functionality. On the last reviewer, there will be no next button. Be sure to Save the last review as changes will not be saved automatically upon closing out. Are updates automatically changed within my applications? Unless you have opted for our LCM module which pushed changes directly into Active Directory, all updates must be made on your end within the application. After updates are acted on within application, make sure to Sync the application to verify the changes. Can users self-certify? No; however, delegations can be made for specific individuals being reviewed. For example: If any application owner is reviewing the application and his own data is housed in the review, it best practice to have someone else review his access rights. He can delegate his credential review to someone else using the delegations tab. Here one can assign the reviewer (potentially themselves) they wish to delegate along with a delegatee email representing the person to conduct the review in their place. If I terminate a user during a review, will those entitlements/credential be revoked and included with the ticketing process? Yes. If a manager marks a user as Terminated during the review, the credential and any entitlements will be marked as revoked and included with the ticketing file that is generated and emailed to the address designated within the application ticketing configuration. One thing to remember, this file is an end of campaign file and will not be generated until the campaign is closed. So, if you have a month-long campaign going on, the action to revoke access for terminated users will not go to your help desk (who ever actions the tickets) until after the campaign is completed. Of course, the manager always has the option to proactively send an internal request to remove the terminated users access within the respective application before the campaign completes. But that is a process outside of the SecurEnds tool and would not impact anything.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-user-access-reviews/">User Access Reviews</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>I finished my last review and it did not save, why?</strong></p>



<p>Each page during the review process has a <strong>Next</strong> button to transition to the next user to be reviewed. This <strong>Next </strong>has a &#8220;next and save&#8221; functionality. On the last reviewer, there will be no next button. Be sure to <strong>Save</strong> the last review as changes will not be saved automatically upon closing out.</p>



<p><strong>Are updates automatically changed within my applications?</strong></p>



<p>Unless you have opted for our LCM module which pushed changes directly into Active Directory, all updates must be made on your end within the application. After updates are acted on within application, make sure to Sync the application to verify the changes.</p>



<p><strong>Can users self-certify?</strong></p>



<p>No; however, delegations can be made for specific individuals being reviewed. For example: If any application owner is reviewing the application and his own data is housed in the review, it best practice to have someone else review his access rights. He can delegate his credential review to someone else using the <strong>delegations</strong> tab. Here one can assign the reviewer (potentially themselves) they wish to delegate along with a delegatee email representing the person to conduct the review in their place.</p>



<p><strong>If I terminate a user during a review, will those entitlements/credential be revoked and included with the ticketing process?</strong></p>



<p>Yes.  If a manager marks a user as Terminated during the review, the credential and any entitlements will be marked as revoked and included with the ticketing file that is generated and emailed to the address designated within the application ticketing configuration. One thing to remember, this file is an end of campaign file and will not be generated until the campaign is closed. So, if you have a month-long campaign going on, the action to revoke access for terminated users will not go to your help desk (who ever actions the tickets) until after the campaign is completed. Of course, the manager always has the option to proactively send an internal request to remove the terminated users access within the respective application before the campaign completes. But that is a process outside of the SecurEnds tool and would not impact anything.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-user-access-reviews/">User Access Reviews</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-user-access-reviews/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Azure Active Directory</title>
		<link>https://www.securends.com/documentation/best-practices-azure-active-directory/</link>
					<comments>https://www.securends.com/documentation/best-practices-azure-active-directory/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:31:32 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6347</guid>

					<description><![CDATA[<p>Best Practices 7 Permissions are required when setting up Azure AD connection, they are listed below: Delegated permissions: User.Read User.Read.All User.ReadBasic.All Directory.AccessAsUser.All Directory.Read.All Application permissions: User.Read.All Directory.Read.All We recommend using a service account when setting up (ex. tenant ID, client ID, client secret) When connecting to Azure, we have separate applications when using for SSO or when using for a connector to pull data. Int he event you have Azure SSO and important information housed within Azure AD, SecurEnds will need two applications set up, one for each.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-azure-active-directory/">Azure Active Directory</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Best Practices</strong></p>



<p>7 Permissions are required when setting up Azure AD connection, they are listed below:</p>



<ul class="wp-block-list"><li>Delegated permissions:<ul><li>User.Read</li><li>User.Read.All</li><li>User.ReadBasic.All</li><li>Directory.AccessAsUser.All</li><li>Directory.Read.All</li></ul></li><li>Application permissions:<ul><li>User.Read.All</li><li>Directory.Read.All</li></ul></li></ul>



<p>We recommend using a service account when setting up (ex. tenant ID, client ID, client secret)</p>



<p>When connecting to Azure, we have separate applications when using for <strong>SSO</strong> or when using for a <strong>connector to pull data</strong>. Int he event you have Azure SSO and important information housed within Azure AD, SecurEnds will need two applications set up, one for each.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-azure-active-directory/">Azure Active Directory</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-azure-active-directory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>SecurEnds Agent</title>
		<link>https://www.securends.com/documentation/best-practices-securends-agent/</link>
					<comments>https://www.securends.com/documentation/best-practices-securends-agent/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:32:45 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6355</guid>

					<description><![CDATA[<p>When you try to execute the .bat file from command prompt and you get &#8221; ERROR: Access to the registry path is denied.&#8220; This error is due to command prompt not being accessed with Administrative privilege&#8217;s. Open command prompt with &#8220;Run as Administrator&#8221; When you install and start the SecurEnds Agent from command prompt and you get &#8220;Unable to access jarfile D:\\Generic_Agent-xxx.jar.&#8221; Review and correct the .jar file name in Generic_Agent.xml When you install and start the SecurEnds Agent from command prompt and you get &#8221; EndPoint sync faild due to:::I/O error on GET request for http://23.23.195.159:8083/api2/getPendingEndpoints&#8221; in Generic Agent log file (C:\securends\logs\GenericAgent) You will get this error, if IP/port is incorrect or if you are not able to access the IP/ port link. This may happen if IP has been blocked/restricted in your system. To Resolve the error: Try accessing the link from the error message (http://23.23.195.159:8083/api2/getPendingEndpoints) &#160;from another system, if it works then it is due to IP being restricted and you need to whitelist that IP in client system. If the above resolution does not help, reach out to SecurEnds. When you install and start the SecurEnds Agent from command prompt and you get &#8221; Caused by: java.net.BindException: Address already in use: bind &#8220; This error occurs if the port (8082 given in the .bat file) is already in use by some other application. Is SecurEnds Agent suitable for any type of system? (Unix, Windows, Mainframe, AS400, RACF, cloud-platforms like AWS, etc. ) Yes. There are options to integrate to connect to various directory services, operating systems, cloud systems, databases, etc. Most integration protocols use HTTPS, SFTP, and any available secured connection when linking with target system. The UI shows that the remote Agent Status is not working as shown below. What do I do? The agent should be restarted. Go to the server where the agent is installed. Click on Windows and search for services. With the list of services, search for generic agent. Right click on the service and restart the GA.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-securends-agent/">SecurEnds Agent</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>When you try to execute the .bat file from command prompt and you get <em>&#8221; ERROR: Access to the registry path is denied.</em>&#8220;</strong></p>



<p>This error is due to command prompt not being accessed with Administrative privilege&#8217;s. Open command prompt with &#8220;Run as Administrator&#8221;</p>



<p><strong>When you install and start the SecurEnds Agent from command prompt and you get &#8220;<em>Unable to access jarfile D:\\Generic_Agent-xxx.jar</em>.&#8221;</strong></p>



<p>Review  and correct the .jar file name in Generic_Agent.xml</p>



<p><strong>When you install and start the SecurEnds Agent from command prompt and you get <em>&#8221; EndPoint sync faild due to:::I/O error on GET request for <a href="http://23.23.195.159:8083/api2/getPendingEndpoints">http://23.23.195.159:8083/api2/getPendingEndpoints</a>&#8221; </em>in Generic Agent log file (C:\securends\logs\GenericAgent)</strong></p>



<p>You will get this error, if IP/port is incorrect or if you are not able to access the IP/ port link. This may happen if IP has been blocked/restricted in your system.</p>



<p>To Resolve the error:</p>



<ol class="wp-block-list" type="1"><li>Try accessing the link from the error message (<em><a href="http://23.23.195.159:8083/api2/getPendingEndpoints">http://23.23.195.159:8083/api2/getPendingEndpoints</a>) </em>&nbsp;from another system, if it works then it is due to IP being restricted and you need to whitelist that IP in client system.</li><li>If the above resolution does not help, reach out to SecurEnds.</li></ol>



<p><strong>When you install and start the SecurEnds Agent from command prompt and you get &#8221; <em>Caused by: java.net.BindException: Address already in use: bind</em> &#8220;</strong></p>



<p>This error occurs if the port (8082 given in the .bat file) is already in use by some other application.</p>



<p><strong>Is SecurEnds Agent suitable for any type of system? (Unix, Windows, Mainframe, AS400, RACF, cloud-platforms like AWS, etc. </strong>)</p>



<p>Yes. There are options to integrate to connect to various directory services, operating systems, cloud systems, databases, etc. Most integration protocols use HTTPS, SFTP, and any available secured connection when linking with target system.</p>



<p><strong>The UI shows that the remote Agent Status is not working as shown below.  What do I do?</strong></p>



<p>The agent should be restarted.  Go to the server where the agent is installed.  Click on Windows and search for services. With the list of services, search for generic agent.  Right click on the service and restart the GA.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="929" height="274" src="https://www.securends.com/wp-content/uploads/2022/01/image.png" alt="" class="wp-image-10911" srcset="https://www.securends.com/wp-content/uploads/2022/01/image.png 929w, https://www.securends.com/wp-content/uploads/2022/01/image-300x88.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-768x227.png 768w" sizes="(max-width: 929px) 100vw, 929px" /></figure>
<p>The post <a href="https://www.securends.com/documentation/best-practices-securends-agent/">SecurEnds Agent</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-securends-agent/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>FTP/SFTP</title>
		<link>https://www.securends.com/documentation/best-practices-ftp-sftp/</link>
					<comments>https://www.securends.com/documentation/best-practices-ftp-sftp/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:32:28 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6353</guid>

					<description><![CDATA[<p>Best Practices Ensure headers are exact match Traditional file uploads into SecurEnds allow header matching within the tool; however, when using FTP/SFTP Flex Connector, files uploaded must have exact header match for system to recognize. Accepted File Format .csv (comma separated values) Traditional file uploads allow more formatting options, but for this Flex Connector only .csv (comma separated values) is accepted.</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-ftp-sftp/">FTP/SFTP</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Best Practices</strong></p>



<ul id="block-3c326053-d880-4e04-8dd7-1c2a369feb7c"><li>Ensure headers are exact match<ul><li>Traditional file uploads into SecurEnds allow header matching within the tool; however, when using FTP/SFTP Flex Connector, files uploaded must have exact header match for system to recognize.</li></ul></li><li>Accepted File Format<ul><li>.csv (comma separated values)<ul><li>Traditional file uploads allow more formatting options, but for this Flex Connector only .csv (comma separated values) is accepted.</li></ul></li></ul></li></ul>
<p>The post <a href="https://www.securends.com/documentation/best-practices-ftp-sftp/">FTP/SFTP</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-ftp-sftp/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>DB Extract</title>
		<link>https://www.securends.com/documentation/best-practices-db-extract/</link>
					<comments>https://www.securends.com/documentation/best-practices-db-extract/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Sat, 12 Dec 2020 19:32:12 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6351</guid>

					<description><![CDATA[<p>Best Practices We recommend using a service account upon set up. Ensure the server housing our generic agent is able to communicate with the DB we wish to extract data from. Need read only access</p>
<p>The post <a href="https://www.securends.com/documentation/best-practices-db-extract/">DB Extract</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Best Practices</strong></p>



<ul class="wp-block-list"><li>We recommend using a service account upon set up.</li><li>Ensure the server housing our generic agent is able to communicate with the DB we wish to extract data from.<ul><li>Need read only access</li></ul></li></ul>
<p>The post <a href="https://www.securends.com/documentation/best-practices-db-extract/">DB Extract</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/best-practices-db-extract/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How do I review role or group permissions for CSV applications?</title>
		<link>https://www.securends.com/documentation/group-reviews/</link>
					<comments>https://www.securends.com/documentation/group-reviews/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Wed, 10 Mar 2021 18:38:01 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=7415</guid>

					<description><![CDATA[<p>Summary At its core, SecurEnds was built around performing reviews at a user level. However, there are some alternate solutions that can be taken to leverage existing functionality to review permissions associated to roles or groups. The premise is built around creating a user (or &#8220;pseudo-user&#8221;) to represent the group/role. The specific permissions for that group/role are then added to this pseudo-user as entitlements. This allows for reviewing of the permissions at the entitlement level when performing a campaign. Depending on the number of role/group owners that will be performing the review, configuration will need to be adapted appropriately within the SecurEnds tool. Below are the steps for setting up the system for different scenarios. A Single Role/Group Owner for an Application If an application has a single role/group owner, then one pseudo-user can be utilized in the system. This user will represent the application level pseudo-user that will then have the group/role credentials and permission assigned to it. For a single pseudo-user, they can be added directly to the People tab and the appropriate fields populated. (NOTE: For the below examples, Active Directory is the application that is being used to demonstrate the process so the pseudo-user information being used reflects that) Once this user has been added they can be viewed in the system from the People tab The next step is to utilize the sample CSV file provided within the SecurEnds tool to create credential records to assign to the newly created pseudo user. The first and last name will be the same as the pseudo-user but the Employee ID will reflect the name of the group/role. The Group Owner will also remain the same, and should correlate to the role/group owner that will be performing the review. A &#8220;Permission&#8221; column will also need to be added, and a separate line included for each permission that is being reviewed. Import this CSV file to the People tab and map the columns appropriately. The credentials (representing the groups) as well as their permissions will now be assigned to the pseudo-user. If roles/groups are to be reviewed at the same time as the users of the application, be sure to add this pseudo user to the application CSV going forward. This will ensure it is included in the scope of the campaign. If the roles/groups are reviewed separately from the users in the campaign, create a separate application that includes just the pseudo-user and have that application included in the campaign template. Below is an example of what it looks like when reviewing the above added user. Each permission has its own approve/revoke option to allow for individual reviewal. Multiple Role/Group Owners for an Application For the use case where there are multiple role/group owners that will be performing the review, the steps are very similar, but the credentials cannot be assigned to a single pseudo-user. Instead, each of the credential records need to be created as separate pseudo-users and included in the application being reviewed. This is to allow for each role/group based pseudo-user to be assigned accordingly to the appropriate role/group owner. The first step is to utilize the sample CSV file provided within the SecurEnds tool to create a CSV that contains each group/role represented as a pseudo-user. This CSV can then be imported into the &#8220;People&#8221; tab to create these pseudo-users in the system. A separate SOR can also be created and the CSV imported using that method if that is preferred. These users then need to also be added to the Application CSV, with each entitlement as a separate line item. NOTE: Be sure to assign the appropriate Manager, Entitlement Owner/Custodian, or Application Custodian depending on who will be responsible for reviewing these group/role pseudo-users. With the pseudo-users now a part of the application, they will be a part of the campaigns and the groups/roles can be reviewed as individual elections.</p>
<p>The post <a href="https://www.securends.com/documentation/group-reviews/">How do I review role or group permissions for CSV applications?</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h5 class="wp-block-heading" id="h-summary">Summary</h5>



<p>At its core, SecurEnds was built around performing reviews at a user level. However, there are some alternate solutions that can be taken to leverage existing functionality to review permissions associated to roles or groups. The premise is built around creating a user (or &#8220;pseudo-user&#8221;) to represent the group/role. The specific permissions for that group/role are then added to this pseudo-user as entitlements. This allows for reviewing of the permissions at the entitlement level when performing a campaign. Depending on the number of role/group owners that will be performing the review, configuration will need to be adapted appropriately within the SecurEnds tool. Below are the steps for setting up the system for different scenarios.</p>



<h5 class="wp-block-heading" id="h-a-single-role-group-owner-for-an-application">A Single Role/Group Owner for an Application</h5>



<p>If an application has a single role/group owner, then one pseudo-user can be utilized in the system. This user will represent the application level pseudo-user that will then have the group/role credentials and permission assigned to it.</p>



<ul class="wp-block-list"><li> For a single pseudo-user, they can be added directly to the People tab and the appropriate fields populated. (NOTE: For the below examples, Active Directory is the application that is being used to demonstrate the process so the pseudo-user information being used reflects that)</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/03/image-15.png" alt="" class="wp-image-7615" width="490" height="151" srcset="https://www.securends.com/wp-content/uploads/2021/03/image-15.png 554w, https://www.securends.com/wp-content/uploads/2021/03/image-15-300x93.png 300w" sizes="(max-width: 490px) 100vw, 490px" /></figure></div>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/03/image-16.png" alt="" class="wp-image-7616" width="491" height="443" srcset="https://www.securends.com/wp-content/uploads/2021/03/image-16.png 630w, https://www.securends.com/wp-content/uploads/2021/03/image-16-300x270.png 300w" sizes="(max-width: 491px) 100vw, 491px" /></figure></div>



<ul class="wp-block-list"><li>Once this user has been added they can be viewed in the system from the People tab</li></ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/03/image-17-1024x145.png" alt="" class="wp-image-7633" width="869" height="126"/></figure>



<ul class="wp-block-list"><li>The next step is to utilize the sample CSV file provided within the SecurEnds tool to create credential records to assign to the newly created pseudo user. The first and last name will be the same as the pseudo-user but the Employee ID will reflect the name of the group/role. The Group Owner will also remain the same, and should correlate to the role/group owner that will be performing the review. A &#8220;Permission&#8221; column will also need to be added, and a separate line included for each permission that is being reviewed. </li></ul>



<div class="wp-block-image"><figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1024" height="141" src="https://www.securends.com/wp-content/uploads/2022/05/doc-csv-file-upload.png" alt="" class="wp-image-13584" srcset="https://www.securends.com/wp-content/uploads/2022/05/doc-csv-file-upload.png 1024w, https://www.securends.com/wp-content/uploads/2022/05/doc-csv-file-upload-300x41.png 300w, https://www.securends.com/wp-content/uploads/2022/05/doc-csv-file-upload-768x106.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure></div>



<ul class="wp-block-list"><li>Import this CSV file to the People tab and map the columns appropriately.</li></ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/03/image-20-1024x65.png" alt="" class="wp-image-7653" width="880" height="59"/></figure>



<ul class="wp-block-list"><li>The credentials (representing the groups) as well as their permissions will now be assigned to the pseudo-user.</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/03/image-21.png" alt="" class="wp-image-7654" width="512" height="435" srcset="https://www.securends.com/wp-content/uploads/2021/03/image-21.png 616w, https://www.securends.com/wp-content/uploads/2021/03/image-21-300x255.png 300w" sizes="(max-width: 512px) 100vw, 512px" /></figure></div>



<ul class="wp-block-list"><li>If roles/groups are to be reviewed at the same time as the users of the application, be sure to add this pseudo user to the application CSV going forward. This will ensure it is included in the scope of the campaign. If the roles/groups are reviewed separately from the users in the campaign, create a separate application that includes just the pseudo-user and have that application included in the campaign template.</li></ul>



<p></p>



<ul class="wp-block-list"><li>Below is an example of what it looks like when reviewing the above added user. Each permission has its own approve/revoke option to allow for individual reviewal. </li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="573" src="https://www.securends.com/wp-content/uploads/2021/03/image-22-1024x573.png" alt="" class="wp-image-7657" srcset="https://www.securends.com/wp-content/uploads/2021/03/image-22-1024x573.png 1024w, https://www.securends.com/wp-content/uploads/2021/03/image-22-300x168.png 300w, https://www.securends.com/wp-content/uploads/2021/03/image-22-768x430.png 768w, https://www.securends.com/wp-content/uploads/2021/03/image-22.png 1303w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h5 class="wp-block-heading" id="h-multiple-role-group-owners-for-an-application">Multiple Role/Group Owners for an Application</h5>



<p>For the use case where there are multiple role/group owners that will be performing the review, the steps are very similar, but the credentials cannot be assigned to a single pseudo-user. Instead, each of the credential records need to be created as separate pseudo-users and included in the application being reviewed. This is to allow for each role/group based pseudo-user to be assigned accordingly to the appropriate role/group owner.</p>



<ul class="wp-block-list"><li>The first step is to utilize the sample CSV file provided within the SecurEnds tool to create a CSV that contains each group/role represented as a pseudo-user. </li></ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/04/image-1-1024x70.png" alt="" class="wp-image-7743" width="1041" height="78"/></figure>



<ul class="wp-block-list"><li>This CSV can then be imported into the &#8220;People&#8221; tab to create these pseudo-users in the system.<ul><li>A separate SOR can also be created and the CSV imported using that method if that is preferred. </li></ul></li></ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/04/image-2-1024x161.png" alt="" class="wp-image-7744" width="984" height="159"/></figure>



<ul class="wp-block-list"><li>These users then need to also be added to the Application CSV, with each entitlement as a separate line item.<ul><li>NOTE: Be sure to assign the appropriate Manager, Entitlement Owner/Custodian, or Application Custodian depending on who will be responsible for reviewing these group/role pseudo-users.</li></ul></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="212" src="https://www.securends.com/wp-content/uploads/2022/05/doc-role-pseudo-users.png" alt="" class="wp-image-13394" srcset="https://www.securends.com/wp-content/uploads/2022/05/doc-role-pseudo-users.png 1024w, https://www.securends.com/wp-content/uploads/2022/05/doc-role-pseudo-users-300x62.png 300w, https://www.securends.com/wp-content/uploads/2022/05/doc-role-pseudo-users-768x159.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list"><li>With the pseudo-users now a part of the application, they will be a part of the campaigns and the groups/roles can be reviewed as individual elections.</li></ul>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/04/image-7-1024x401.png" alt="" class="wp-image-7749" width="939" height="369" srcset="https://www.securends.com/wp-content/uploads/2021/04/image-7-1024x401.png 1024w, https://www.securends.com/wp-content/uploads/2021/04/image-7-300x118.png 300w, https://www.securends.com/wp-content/uploads/2021/04/image-7-768x301.png 768w, https://www.securends.com/wp-content/uploads/2021/04/image-7.png 1288w" sizes="(max-width: 939px) 100vw, 939px" /></figure>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/04/image-8-1024x135.png" alt="" class="wp-image-7750" width="940" height="127"/></figure>
<p>The post <a href="https://www.securends.com/documentation/group-reviews/">How do I review role or group permissions for CSV applications?</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/group-reviews/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
