Blog

Utilizing New Reporting in Access Risk Management

Author

  • robgarrett

    SailPoint

During this year’s Navigate conference, we announced expanded support for multiple Fiori-enabled capabilities within Access Risk Management.

One of these key enhancements announced is centered around our new reporting structure, which embeds PowerBI dashboards directly within our ARM application. These reports provide a very common business intelligence user experience and allow you to analyze and drill down into granular permission level details across all your SAP SOD risks.

(Sample of the new reporting UI)

If you are currently using or looking to take advantage of these new reports within ARM, the process required for generating these new reports is carried out slightly differently than for our legacy reports.

All new PowerBI reports are generated from what’s known as a “risk analysis”. A risk analysis takes a given rulebook along with an associated security extract (and utilization data if enabled) to create an assessment of the SOD-related risks within your SAP system.

A risk analysis is the sole required input used to create these new report visualizations. Once an analysis has successfully completed, you will be able to select that analysis to view the associated report via the Analysis Selector button located in the top right corner of the new Online Reports screen.

(Analysis Selector button)

 

(Sample list of completed analyses to choose from to power the report visualizations)

IMPORTANT: Configuration Requirements to use New Reports

  1. New Reports will NOT be generated by scheduling or manually running the legacy Security Extracts.
    1. Users must create and select a Risk Analysis to generate these new reports. Learn more in the FAQ section below.
  2. Requires ARM Agent version from July 2024 or newer.
  3. Utilization must be enabled in order to read SM20 tables and be provided with utilization data in reports
  4. EAM Profile reports will still automatically be generated

To run the new Risk Analyses:

  1. Go to Schedule Jobs > Risk Analysis - NEW.
  2. Use the Rulebook dropdown to select a rulebook to apply to your risk
    snapshot.
  3. In the Extract field, use the Edit icon to choose an extract. If you want to
    remove it, select Clear.
  4. Utilization Data Range defaults to one year. Select the calendar icons to
    customize your date range. Some Notes:
    1. Utilization data is pulled from the SAP Security Audit Log (SM20). If the data does not exist in SAP, it cannot be extracted.
    2. You must also be using an agent released in July 2024 or newer.
      1. To pull data prior to that release, you’ll need to perform utilization extracts for those months.
        • Here’s how: Once you’ve configured your agent, schedule utilization extracts for each of the prior months. After running those jobs and extracting the data you need from the new data source, the new risk snapshots will include the appropriate data.
  5. Select Submit.
  6. View your snapshot at Activity History > Reports.

For additional information on our new reports, please visit our documentation.

FAQ’s

  1. I’m not currently taking advantage of the new Fiori-enabled capabilities or using the new Multi-System Rulebook format.
    1. Can I take advantage of the new PowerBI reports?
    2. Do I have start using these new reports right now?
      • No, but they are a drastic improvement over our legacy reporting capabilities and will be the only location where new reports and reporting capabilities will be developed going forward. Also, later in 2025, we will work with all customers still using legacy functionality and our legacy rulebooks to migrate over to use our new rulebook and associated features.
  2. I’m currently taking advantage of the new reports, but I have used the legacy security extract process to generate analyses for reports. Do I have to start using this new RISK ANALYSIS screen instead going forward?
    • Yes, all customers that wish to use the new interactive reports will need to generate the underlying risk analyses powering them through this new RISK ANALYSIS screen regardless of whether you have been using the new reports already or are just planning to start.
  3. Will this update introduce any breaking changes into my workflow?
    • The only possible impact would be if you were relying on scheduled security extracts for the purposes of automatically generating new reports. Until we build in the ability to schedule these new risk analyses, you will have to manually create a new risk analyses in order to see a new updated report.
  4. When will I be able to schedule these analyses?
    • The ability to schedule these analyses on a recurring basis will not be available until early 2025, so even if you continue to schedule security extracts, you will need to manually run these analyses in order to use them to generate the new PowerBI reports.
  5. Why are you updating reports to run off of these new risk analyses?
    • We decided to separate this commingled process in order to give users better ability to control which rulebooks, associated security extracts, and utilization dates would make up these analyses. Previously, scheduling or manually running security extracts would automatically schedule and generate the underlying analyses used in our legacy reports.
  6. As a current user of the integration between ARM and ISC, do I need to change anything as a result of this change?
    • If you use the ARM integration with ISC, you should continue to use the legacy security extract process to generate analyses used in the ISC access request process. Once we have the ability to schedule these new risk analyses, we will deprecate this legacy process, and the new risk analysis screen will become the single place powering all ARM related SOD reporting and what-if functionality.