Verifying Authentication (Compliance Scans)

Successful authentication is a requirement for compliance scanning. To identify which hosts passed and failed authentication, review the compliance scan results Appendix section and run the Authentication Report.

 

Verify Authentication from Scan Results

The Appendix section in the compliance scan results lists: 1) hosts for which authentication was successful, 2) hosts for which authentication failed, and 3) hosts for which authentication was successful but the login account had insufficient privileges. An appendix section lists the scan options set in the compliance profile used. You'll notice that authentication is automatically enabled for all authentication types. This is because successful authentication is required for compliance scans.

 

Verify Authentication using the Authentication Report

A policy compliance report called "Authentication Report" is available to identify whether authentication to hosts was successful for the most recent compliance scans. Run this report to identify the pass/fail status for each compliance scanned host.

1.    Select nav_report.jpg Report from the left menu.

2.    Go to New > Compliance Report > Template Based.

3.    For Report Details, enter a report title (optional), select the report type Authentication Report, and select a report format (PDF, HTML pages, MHT, XML or CSV).

4.    For Report Source, select one or more asset groups. You may select asset groups or business units if you are a Manager or Auditor.

5.    Deselect display and filter options (optional).

6.    Click Run to launch the report. Your report appears on the report history list. When completed you can view the report.

View Pass/Fail Status

View the completed report. The Status column in the Results section of the Authentication Report identifies the authentication status (Passed, Failed or Passed with insufficient privileges) for each compliance scanned host. If the scanning engine was able to successfully authenticate to a host, then the status Passed appears. If the scanning engine was not able to authenticate to a host, then the status Failed appears. If the scanning engine was able to authenticate to a host but there were insufficient privileges to perform posture evaluation, then the status Passed* appears.

When authentication fails, the credentials used in the authentication attempt appear in the Cause column of the report so that you can troubleshoot the issue.

View Cause for Failed Status

View the Cause column to see the reason why authentication failed for a host. The credentials used in the authentication attempt appear so that you can troubleshoot the issue. If a Cyber-Ark PIM Suite authentication vault was included in the scan settings and authentication failed due to a problem with accessing your Cyber-Ark PIM Suite environment, a Cyber-Ark generated message will be shown.

 

Related Reading

Running Policy Compliance Reports

Authentication Report