Chat now with support
Chat with Support

Enterprise Reporter 3.5.2 - Installation and Deployment Guide

Product Overview Installation Considerations for Enterprise Reporter Installing and Configuring Enterprise Reporter Managing Your Enterprise Reporter Deployment Troubleshooting Issues with Enterprise Reporter Appendix: Database Content Wizard Appendix: Encryption Key Manager Appendix: Log Viewer

Permissions for Enterprise Reporter discoveries on NAS devices

The following table outlines the permissions required for Enterprise Reporter discoveries.

NetApp Cluster Mode

Multiple virtual machines belong to a single cluster. All of these virtual machines can be specified as discovery targets. These virtual machines must be part of a domain.

The NAS configuration must point to the cluster (name or IP address) with credentials that have read access to the cluster. These would typically be administrator credentials.

NetApp 7 Mode

In NetApp 7 mode, data can be collected on the storage controller or vFilers that are derived from the storage controller. Credentials with read access to the controller and vFiler are required.

NetApp Storage Controller

In NetApp 7 mode, data can be collected on the storage controller or vFilers that are derived from the storage controller. Credentials with read access to the controller and vFiler are required.

NetApp Filer

The vFiler can be a discovery target. In this case, the NAS configuration must point to the storage controller from which the vFilers are derived and the credentials must have read access to the storage controller.

Dell Fluid FS

The discovery target can be any Fluid FS VM. The NAS configuration must be the machine name or IP where Dell Enterprise Manager is installed and credentials must have access to Dell Enterprise Manager.

EMC Isilon

The discovery target can be any Isilon virtual machine. The NAS configuration must be the machine or IP that hosts the OneFS administration site and the credentials must have read access to it. By default, the connection is established using https and, if the connection is not deemed to be secure, the discovery will fail.

Permissions for Enterprise Reporter tenant applications

Enterprise Reporter requires Microsoft Entra applications for the collection of Microsoft Entra and Microsoft 365 objects and attributes. These applications must be registered in the Azure portal and consent must be granted for delegated permissions. To manage tenant applications used by Enterprise Reporter, you use the Configuration | Application Tenant Management option.

For the Microsoft Entra ID discovery and the collection of nested group members for the OneDrive, Exchange Online, and Azure Resource discovery, an application with a name that begins with “Quest Enterprise Reporter Microsoft Entra Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Enterprise Reporter Microsoft Entra discovery application, the following permissions are required:

 

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Group.Read.All

Read all groups

 

Microsoft Graph

IdentityRiskyUser.Read.All

Read identity risky user information

Delegated

Microsoft Graph

SecurityEvents.Read.All

Read your organization's security events

Delegated

Microsoft Graph

User.Read.All

Read all users' full profiles

Delegated

Microsoft Graph

Reports.Read.All

Read all usage reports

Delegated

Microsoft Graph

UserAuthenticationMethod.Read.All

Read all users' authentication methods

Delegated

If you want to collect details about Microsoft 365 user activity, such as which licenses are assigned to a user and dates when a user last used a licensed service, the following delegated permission is required:

Also, you must clear the Microsoft default setting that anonymizes the user-level data. To include user activity data in the Enterprise Reporter reports, do the following steps:

2
Navigate to Settings | Org Settings | Services.
3
Select Reports.
4
Clear the Display concealed user, group, and site names in all reports check box.

For more information, see https://learn.microsoft.com/en-US/microsoft-365/troubleshoot/miscellaneous/reports-show-anonymous-user-name

For the Exchange Online discovery, an application with a name that begins with “Quest Enterprise Reporter Exchange Online Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter Exchange Online Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Application

Microsoft Graph

Group.Read.All

Read all groups

Application

Microsoft Graph

User.Read.All

Read all users' full profiles

Application

Exchange Online

Exchange.ManageAsApp

Allows an application to impersonate a user and perform actions on their behalf.

Application

For the OneDrive discovery, an application with a name that begins with “Quest Enterprise Reporter OneDrive Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter OneDrive Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Files.Read.All

Read all files that user can access

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Microsoft 365 SharePoint Online

MyFiles.Read

Read user files

Delegated

For the Azure Resource discovery, an application with a name that begins with “Quest Enterprise Reporter Azure Resource Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Enterprise Reporter Azure Resource discovery application, the following permissions are required:

 

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Windows Azure Service Management API

user_impersonation

Access Azure Service Management as organization users

Delegated

For the Microsoft Teams discovery, an application with a name that begins with “Quest Enterprise Reporter Microsoft Teams Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter Microsoft Teams Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

User.ReadBasic.All

Read all users' basic profiles

Delegated

Microsoft Graph

Files.Read

Read user files

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

Microsoft Graph

Directory.AccessAsUser.All

Access directory as the signed in user

Delegated

Microsoft Graph

Group.Read.All

Read all groups

Delegated

Microsoft Graph

Organization.Read.All

Read all organizations

Application

Microsoft Graph

AppCatalog.Read.All

Read all application catalogs

Application

For the SharePoint Online discovery, an application with a name that begins with “Quest Enterprise Reporter SharePoint Online Discovery” is created. To create this application in your tenant, you must specify an account with administrative access to create applications. The account must have the Global Administrator role to be able to create and consent to the application.

Once created, the application must also be delegated permissions and an administrator must consent to the application’s permissions using the Microsoft consent wizard. For the Quest Enterprise Reporter SharePoint Online Discovery application, the following permissions are required:

 

Microsoft Graph

Directory.Read.All

Read directory data

Delegated

Microsoft Graph

Sites.FullControl.All

Have full control of all site collections

Delegated

IDG Managing Your Deployment.4.25.html

Troubleshooting Issues with Enterprise Reporter

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating