Windows Audit Report
the windows local user audit report is used to report the current security status of local windows accounts create the report configuration navigate to audit report > windows audit report open the report configuration tab create the report configuration by filling the fields after clicking add the report job can be executed manually or periodically (as scheduled) exclude service accounts parameter can be enabled on the device group if enabled, then it excludes all service accounts from fetch in the windows audit report when we execute the audit report, we enable this highlighted parameter to execute the report job manually, click the options pop up menu button and select run to execute the report job periodically, the scheduled field needs to be configured in the report configuration the period can also be configured from the jobs scheduler by editing the windowsauditjob for the audit report, the selected device groups must have the globalusername and globalpassword properties defined see also section device group properties to be able to access the report detail, the user defined as globalusername should be a privileged user globalusername should be entered in \<username> format if it is a vault account it should be entered in \<username>@\<ipaddress> format if it’s an account defined on another server, like an ldap server globalpassword would be discarded if globalusername is defined as a vault account report details when a job finishes, the reports are listed in the reports tab to access the report navigate to audit report > windows audit report open the report tab click the options drop down menu button and select show details report details are shown in the windows audit report details section dashboard navigate to audit report > windows audit report open the dashboard tab choose the desired fields and click the display reports button