Skip to main content

3-FSAA Exceptions Job

The 3-FSAA Exceptions job doesn't use the FSAA Data Collector. Instead it runs analysis on the data returned by the Access Auditing collection jobs to identify potential security concerns.

Parameter Configuration​

Use the Configuration section on a Job's overview page to modify any customizable parameters used by analysis tasks in the job. See the Parameter Configuration topic for instructions on how to edit parameters on a job overview page.

The 3-FSAA Exceptions job has the following customizable parameter:

  • Well Known high risk SIDS – Add any additional custom SIDS, but don't remove the default SIDS.

See the Analysis Tasks for the 3-FSAA Exceptions Job topic for additional information.

Analysis Tasks for the 3-FSAA Exceptions Job​

View the analysis tasks by navigating to the FileSystem > 0.Collection > 3-FSAA Exceptions > Configure node and select Analysis.

warning

Most of these analysis tasks are preconfigured and shouldn't be modified and/or deselected. You can deselect particular tasks as specified, but doing so isn't recommended.

Analysis Tasks for the 3-FSAA Exceptions Job

The following analysis tasks are selected by default:

  • Open resources – Any folders that are openly accessible through file shares. Deselect this task if you don't need open resource information.

  • Disabled users – Any folders where disabled users have access

    • Deselect this task if you don't need disabled user information
  • Stale users – Any folders where stale users have access. Stale users are users who haven't logged in for more than 120 days.

    • Deselect this task if you don't need stale user information
  • Reindex Exception IDs – Displays views within the Results node of the Enterprise Auditor Console