Exporting LDAP Integrated Users from EEM for SOX Audit
search cancel

Exporting LDAP Integrated Users from EEM for SOX Audit

book

Article ID: 448235

calendar_today

Updated On:

Products

Autosys Workload Automation

Issue/Introduction

Users integrated into CA Embedded Entitlements Manager (EEM) via LDAP/Active Directory groups for Autosys Workload Automation need to pull a list of users for SOX audit purposes. The EEM UI or standard export tools may not display or export these external users directly.

Environment

Product: Autosys Workload Automation AE / WCC
Component: CA Embedded Entitlements Manager (EEM)
Configuration: External User Store (LDAP/Active Directory)

Cause

When EEM is configured with an external LDAP user store, it does not store the users locally in its own database; they remain in the LDAP directory. Standard EEM export tools (like Safex or the Export Application option in the UI) are designed for internal user stores and application policies. Consequently, global users and groups from LDAP are not exported or listed because EEM acts as an authorization engine, not an LDAP browser.

Resolution

To satisfy SOX audit requirements for integrated LDAP users, use the following methods:

Method 1: Export Application Policies
Auditors typically require proof of what users can do. You can export the application policies for both AutoSys (AE) and WCC.

  1. Log in to the EEM UI specific to the Application (WCC004, WorkloadAutomationAE)
  2. Navigate to the Configure tab.
  3. Select Export Application.
  4. Export the policies to an XML or Excel file for auditor review.

Method 2: EEM Reporting Utility (ERU)
Use the ERU to provide an audit trail of user access.

  1. Install the EEM Reporting Utility (ERU).
  2. Run reports to extract audit data showing which users were granted or denied access based on policies.

Method 3: LDAP/AD Direct Export
Since the source of truth for the user identities is the external directory:

  1. Work with your LDAP/Active Directory Administrator.
  2. Request a direct export of users belonging to the specific AD groups mapped within EEM.
  3. Use LDAP tools (such as JDeveloper or native AD export commands) to obtain the full list of members.

 

Code Fix: No code fix.

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on the respective region.

Related KD Articles: 247802, 198511,