Symantec Security Expressions Server manual Windows Group Access, Editing Scheduled Tasks

Page 79

Audit-On-Schedule

15.If you want to use specific credentials to access all systems whenever this audit task runs, type those credentials in the Login box.

If you do not want to specify credentials, skip to step 18.

16.In the Password box, type the password of the credentials you specified in the previous

step.

17.If you want to make sure these credentials are used to access target systems instead of any credentials that might be delegated from other credential stores or from the console application, check the Always use my credentials over delegated ones box.

Windows Group Access

18.Set Windows Group Access. Enter Windows groups, separated by a comma, that can edit this scheduled task and use it to perform audits. This establishes which users can access this task and its audit results due to their role. If a Windows User Group isn't on the local computer, you'll need to enter the group in domain\groupname format.

In the Edit Task field, enter the Windows groups who should be able to modify the task. In the Run Task field, enter the Windows groups who should be able to use the task to perform audits. To grant all users access, type Everyone. To restrict all users, type None.

19.Click the Add New button to create this scheduled task.

Now the task appears in the table at the top of the Scheduled Tasks page.

Editing Scheduled Tasks

You can edit the tasks you created, plus any task created by someone else who selected the Allow others to edit this task option.

Note: You can view tasks created by someone else who did not opt to allow others to edit the task. You cannot make changes to them, however.

To edit a scheduled task:

1.Click the Audit-On-Schedule tab and then the Scheduled Tasks link.

2.In the table at the top of the Scheduled Tasks page, click the Edit hyperlink in the same row as the task you want to edit.

The Edit Task options appear. Make the necessary changes.

Basic Settings

3.In the Description box, type a brief statement identifying the scheduled task.

4.In the Policies list, select one or more policies on which you want to base any audits this task performs.

Policies are configured on the Policies page. If none of the existing policies meet your needs, you can configure a new one by clicking the Edit Policy List link, which opens the Policies page.

5.Select which machine list(s) you want to audit every time this task runs.

You may select any combination of machine lists from the Global Machine Lists, My Machine Lists, and Other User's Shared Machine Lists sections.

71

Image 79
Contents SecurityExpressions Server User Guide Page Table Of Contents Page Table Of Contents Page Vii Page Contacting Us Page Contacting Technical Support Technical SupportPage SecurityExpressions Console Other ProductsPage About SecurityExpressions Audit & Compliance Server OverviewPage How to Audit your Local Computer Self-Service AuditWhat is Self-Service Auditing? Self-Service Audit AgreementDisplays on the page. No detailed audit results appear Pages with Role Settings Configure ServersAbout Server Configuration Local Server SettingsViewing Audit Results SetupDatabase Connection Windows 2000 Servers Secure ConnectionCredential Store User Click OK on the Default Web Site Properties windowCreating Credential Stores Site Preferences Enable Web ServicesSecurityExpressions Console Credential Stores Software RegistrationAccess Item Rights Global Machine List Access User RolesLibrary Synchronization Policy File LibraryCheck the Synchronize with a policy file library box How System Scores are Calculated About Policy FilesDefault method for remote execution on Windows Agent & Service ConfigurationTarget Options SSH Agent Authentication Database Cleanup Add Task Update TaskCancel PoliciesSite Preferences Agent DownloadsClick Use the Following Agreement Allow Remediation Page Policies Table What is Audit-on-Connect?Audit-On-Connect PoliciesPage Adding Policies Editing Policies Deleting Policies Configuring with Run-Time Policy VariablesPage Scopes ScopesAdd a New Scope Page Edit a Scope Scopes Table Supported Operators Deleting ScopesDNS Domain Name Scopes Expression ScopesOrg Unit Scopes Supported FunctionsDetection Method Scopes Notifications Editing Notifications Creating New Command NotificationsCreating New Email Notifications Click Add NewClick Add New Creating New Command Notifications Notification Variables Deleting NotificationsAdding Exceptions ExceptionsExceptions Exceptions Table Column DescriptionConnection Monitors Specify Password and Encrypted PasswordConnection Monitors Deleting ExceptionsRemove Configuring Connection MonitorsEnabling Connection Monitors IP Range Section Connection Monitor Configuration FileOptions DefaultConfiguration File Syntax Processing the Configuration FileActive Directory Active Directory Connection Monitor only Slow Links NetworkInitial Token Trace Route InformationNetwork Admissions Control Unmanaged SystemsRedirection Web HealthyQuarantined/Unknown Reaudit if quarantinedRedirection Web Page Behavior Audit on Connect TracingAudit on Connect Tracing Page Page Audit-On-Schedule What is Audit-on-Schedule?Page Adding Policies Editing Policies Deleting Policies Page Notifications Click Add New Click Add New Deleting Notifications My Machine Lists My Machine ListsEditing Machine Lists Adding Machine ListsScheduled Tasks Scheduled TasksDeleting Machine Lists Editing Global Machine ListsAdding Scheduled Tasks Basic SettingsSchedule Settings Hosts Not Connected Settings Credentials Settings Other Options SettingsEditing Scheduled Tasks Windows Group AccessSchedule Settings Notifications Other Options Settings Deleting Scheduled Tasks Page Adding a New Audit-On-Connect Report Profile View Audit-On-Connect ActivityBrowse Audit-On-Connect Activity Audit-On-Connect Activity Table Column DescriptionDeleting Report Profiles Editing Report ProfilesAudit-On-Connect Exceptions Report Audit-On-Connect Error Log ReportPage Browse Audit Results View Audit ResultsAdding a New Audit Results Report Profile Page Deleting Audit Report Results Profiles Scheduled Audits Log ReportAdding Custom Reports to the Server Application Editing Audit Report Results ProfilesPage Glossary Page Index ConfigureIP address 33, 44, 45 Rule weights