Skip to main content

Active Directory Permissions Analyzer reports are outdated

Symptoms

Old data in the Active Directory Permissions Analyzer (ADPA) reports from deprecated Domains.
Example of the incorrect data:
Chart  Description automatically generated

Cause

ADPA Data is not cleared when running only the ADInventory (ADI): Category >> Drop Domain – Remove host domain related data from SQL server option seen under the following:
https://docs.netwrix.com/docs/auditor/10_8

Resolution

We will need to create a new Job to work with the APDA data in question.
To do so you can follow the steps below.

  1. Create a new Job in the Netwrix Auditor console: right click the Jobs Node in the left-hand window and select Create Job:

    Graphical user interface, application  Description automatically generated

    Select the Local host in the jobs host list:

    Graphical user interface, application  Description automatically generated

  2. Click on the Create Query:

    Graphical user interface, application, Word  Description automatically generated

  3. Configure the jobs query Properties.
    Under the Data Sources tab, select the ADPERMISSIONS option from the dropdown menu then click on Configure.

    Graphical user interface, application, Word  Description automatically generated

    Select Remove Tables and click Next:

    Graphical user interface, text, application, email  Description automatically generated

    Check the Results option: Click NextFinishOk.

    Graphical user interface, text, application  Description automatically generated

  4. Now run the new Job.

  5. Once the job completes run the ADPA report; it should complete with an error.
    Examples: Invalid object name 'dbo.SA_ADPerms_PermissionsView'.
    Invalid object name 'dbo.SA_ADPerms_Permissions*View'.

Now you can run the Active Directory Permissions Analyzer Job Group to repopulate for the active Domains.

This will recreate the needed ADPA Tables and Views needed for the Reports.