Skip to main content

Create Review Wizard

Open the Create Review wizard with the Create button on the Resource Reviews interface. See the Manage Reviews Page topic for additional information.

Create Review wizard

It contains four pages:

  • 1. Review Type

    • Review Name — Visible only to Review Administrators

    • Select the type of review to create:

      • Membership – Review group membership

      • Access – Review user access rights to resources

      • Permissions – Review trustee permissions to resources

      • Sensitive Data – Review files containing potentially sensitive data stored within resources

        note

        The Sensitive Data content within reports and reviews is visible to all users and roles. The report populates the Matches table only for Console Users with Security Team and Administrator roles.

    • Select whether to notify the review creator when the resources have been reviewed

    • For Access and Permissions reviews, indicate whether to include child resources with permission changes.

      note

      This typically occurs due to broken inheritance and permissions being explicitly set. This option lets you review the entire resource hierarchy where permissions have changed. It isn't applicable to Membership and Sensitive Data reviews.

    • For Sensitive Data reviews, select whether to include child resources that contain sensitive content.

  • 2. Criteria — Only applies to Sensitive Data reviews. Select the type of sensitive criteria to review.

  • 3. Resources — Select resources to include in the review

  • 4. Summary — Preview of the review selections

See the Create a Review topic for additional information.

Create a Review

Create a review.

Step 1 – On the Manage Reviews page, click Create. The Create Review wizard opens.

Create Review wizard Review Type page

Step 2 – On the Review Type page, provide the following information and click Next:

  • Review Name — Enter a unique, descriptive name for the review. The review name is only visible to Review Administrators.

  • Select Type — Reviews are limited to one type. Select the type of review from the buttons provided:

    • Membership – Review group membership
    • Access – Review user access rights to resources
    • Permissions – Review trustee permissions to resources
    • Sensitive Data – Review files containing potentially sensitive data stored within resources
  • Notify the review creator when resources are reviewed — When selected, the application sends an email to the review creator when the resource owner completes the review. If the review contains multiple resources, the application sends an email when each resource is reviewed. See the Resource Reviewed Email topic for additional information.

    note

    This option isn't available for the Builtin Administrator account as it has no email to receive notifications.

  • Include children with permission changes — When checked, this option automatically includes any child folders and resources in the review that have different permissions than the selected resource.

  • Include children with sensitive content — When checked, this option automatically includes any child folders and resources in the review that contain sensitive content.

note

If creating a Sensitive Data review, continue to Step 3. For all other review types, skip to Step 5.

Create Review wizard Criteria page

Step 3 – On the Criteria page, select the types of sensitive criteria to include in the Sensitive Data review from the list on the left and click Add. Select multiple items by using the Ctrl or Shift key with mouse click combinations. The system adds the selected criteria to the Selected Criteria list. Repeat this until you have all required criteria selected. To remove a criteria, select it in the Selected Criteria list and click Remove.

note

The sensitive data criteria listed is limited to what the Netwrix Access Analyzer (formerly Enterprise Auditor) data collection scans are configured to collect.

Step 4 – Optionally check the Reviewers can see the sensitive data match if available option to allow the owner with Console Access roles of Security Team or Administrator to view potentially sensitive data within the review. Click Next to continue.

warning

If you check this option but Netwrix Access Analyzer (formerly Enterprise Auditor) hasn't collected the data with matches stored for all of the resources selected in Step 5, the One or more resources selected have not been scanned error occurs. The Create Review wizard blocks review creation until you remove those resources or clear the option.

Create Review wizard Resources page

Step 5 – On the Resources page, select the resources to include in the review. Use the Search feature to filter resources by review type.

  • The table shows the following information:

    • Resources — The icon indicates the type of resource. The resource name includes its location, such as the UNC path for a file system resource, the URL for SharePoint resource, or Group name (e.g., [Domain][Group]).
    • Description — Description or explanation of the resource as supplied by either the Ownership Administrator or the assigned owner
    • Reviewer — Primary owner assigned to the resource
    • Confirmed — Shows whether the assigned owner confirmed ownership of the resource. Hover over icons to see whether ownership has been confirmed, declined, is pending a response, or wasn't requested.
    • Scan Data — A checkmark indicates the resource has been scanned. Only resources with scan data can be included in a review.
    • Active Review — Indicates whether there is a pending review
  • Select the resources you want and click Add. The View Selections button indicates how many resources you've selected. Click the button to open the Selected Resources window, where you can view and modify the selections. See the Selected Resources Window topic for additional information.

  • Alternatively you can import a list of resources from a CSV file. Click the Import button and then select the CSV file. A message appears if items aren't found or not valid for the review. The application selects any valid resources, and you can view them in the Selected Resources window. See the Missing Items Window topic for additional information

    The CSV file must use the following format for the resources:

    • File system: \\HOST\Share\file
    • SharePoint: https://abc/def
    • Groups: Domain\GroupName
    • Distribution lists: Name@domain.com
  • After you've selected the resources you want, click Next.

Create Review wizard Summary page

Step 6 – On the Summary page, review the settings and click Next. The Access Information Center begins to create the review.

Create Review wizard review created message

Step 7 – The page shows the action status. When the review is created (100%), click Close. The Create Review wizard closes.

The new review appears in the table on the Manage Reviews page. The application sends an email to the primary owner assigned to the resources in this review. By default, the application sends notifications only to the primary owner. You can customize this on the Configuration > Notifications page to send notifications to all assigned owners. See the Notifications Page topic for additional information.