Skip to main content
Version: Angophra

Reconciliation

Overview​

Reconciliation is a key feature and concept in Apporetum. It will give you the ability to control access management and take action on malicious users. The reconciliation can be either run manually or scheduled.

In this article, you can find the information and how-to guide on running reconciliation, including app reconciliation or particular app role reconciliation. You can also review alerts of the suspicious users that are not in both Apporetum and the associated directory. You can either authorise membership or remove membership of those users or choose ignore alert till the next reconciliation comes up. After reconciliation, you can view reconciliation log or download report for auditing purposes to identify cyber incidents. You also have the option to set up or update reconciliation period for each app role.

info

You can view and/or initiate app reconciliation or specific (app) role reconciliation tasks if you are an App Owner, SecOps Manager, System Admin or Global Admin.

What is Reconciliation​

Reconciliation is an Identity Governance audit process, which compares user access, access rights, and privileged accounts, against Apporetum, the agreed-upon authoritative identity source of truth. This process is used to confirm what data is present in a directory, and sync that data with Apporetum to ensure the right access to systems for the right people.

Run Reconciliation​

Reconcile App​

  1. Click the Access main menu option

  2. Click the vertical three dots icon next to the app

icon

  1. Click Reconcile App
tip

If you only want to reconcile specific role, you can read Reconcile Role.

  1. Choose Run now

run reconcile

  1. Check if the system notification status is successful
  2. Click the Alerts tab to check the reconciliation result

alerts

Reconcile Role​

  1. Click the Access main menu option
  2. Click the App Roles tab
  3. Search and click the role
  4. Click the vertical three dots icon next to the role
  5. Click Reconcile Role

reconcile role

  1. Click Run now from the pop-up window

  2. Check if the system notification status is successful

  3. Click the Alerts tab to check the reconciliation result

Review Alerts, Authorise/Remove Membership, Ignore Alert​

tip

As Apporetum is the governance over your directories, we suggest that you do not use other tools to add and remove users from groups. This ensures that Apporetum can audit and track accounts access.

  1. Click the Access main menu option
  2. Select Alerts from the sub-menu
info

Alert Types are Mismatched and Unsanctioned. Status can tell you if those users have been actioned yet.

  • Mismatched: user is in Apporetum, not in the directory
  • Unsanctioned: user is in the directory, not in Apporetum
  1. Select one or more users
  1. Choose Authorise membership, or Remove membership, or Ignore alert for the time being
note

If you choose to ignore any alerts, those users will be hidden from the Alerts till the next reconciliation.

info

Choosing Authorise membership or Remove membership will allow you to make the user list match between Apporetum and the associated directory.

  • For a mismatched user, if you choose to Authorise membership, the user will be added into the associated directory so that the user is in both Apporetum and the directory. If you choose to Remove membership, the user will be removed from Apporetum so that the user will be in neither Apporetum nor the directory.

  • For an unsanctioned user, if you choose to Authorise membership, the user will be added into Apporetum while keeping access on the directory. If you choose to Remove membership, the user will be removed from the directory so that this user will be in neither Apporetum nor the directory.

  1. After actioning successfully, your actions will be recorded in Apporetum
tip

You can view the reconciliation activity log and/or download a report of those reconciliation tasks. You can also read the Recon Log to see all actions that have been done in this app.

The following section is the how-to guide on viewing reconciliation log and download report.

View Recon Log, Download Report​

info

After running reconciliation on an app or a role under Alerts, you can download the report immediately on the page.

download report

Quick Pathway​

  1. Click the Apps main menu option
  2. Click the vertical three dots icon next to an app or a role within an app
  3. Click Download
info

The report that you will download here is the recent reconciliation result.

  1. Click the Acess main menu option
  2. Click the Recon Log tab
note

The column is in chronological order starting with the most recent log.

  1. Click the download icon download icon to Download report

Update Reconciliation Period​

info

Reconciliation Period is the frequency in which Apporetum will reconcile the user access of the App Role. A longer period will reduce the number of notifications that Access Providers and App Owners will receive.

You can Navigate to App Role Configuration and then Modify/Remove Current Role Settings.