Skip to main content
Version: On prem: 15.0.2

Account reports

The accounts reports show information of accounts in a system.

An account is a specific user account in a specific system, for example an Active Directory user. An account can be personal, if matched one to one with an identity or non-personal if not. Examples of non-personal accounts are administrative or service accounts.

WAC001 Account list

The Account list is a list report that shows the accounts that belong to a system. The report shows account (account UID), account name, the identity that is the owner of the account (if matched) and the account type.

The account list will show the following fields for each account within the report scope. The report links to the following reports:

  • System details (WSY002)
  • Account details (WAC002)
  • Identity details (WID002)
WAC001 fields

FieldDescription
Color iconLeft side color coding indicates compliance status.

If the Role and Policy Engine is not used, the color icon shows approval state.Red indicates rejected or not attested; green indicates approved. This field links to the Resource assignment details report.
AccountThe unique ID of the account. This field links to the Account details report.
NameThe full account name.
IdentityIf the account has been matched to an identity (by exact or fuzzy match or a custom join) the identity field shows the identity name.The field links to the Identity details report for matched identities.
TypeShows the account type. Accounts that are matched to an identity via exact or fuzzy match will have the value of “Personal” in this column. For a custom join match, the type may be something other than “Personal”. Unless customizations have been made to the ODW import logic, the type field will be empty for accounts that are not matched to an identity.
CategoryCategory of the account. Source system dependent
Compliance statusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None
ReasonShows the reason for the resource assignment, as calculated in the Role and Policy Engine.

If the Role and Policy Engine is not used, the Reason field indicates if the resource assignment is implicit or explicit. An implicit resource assignment is associated with an identity through a reference, for example a context assignment.Assignments to resources that are child resources are also implicit resource assignments.

WAC001 parameters

ParameterDescription
Effective time (required)The time the report is effective. Change the time to see a snapshot for another time. Click View Report to refresh after changing this parameter.
TypeThe type of the account.
Max. items (required)The maximum number of returned items. By default this parameter is set to 100 items.Change to view more results.
CategoryCategory of the account. Source system dependent.
AccountUse the Account parameter to search for a specific account. This parameter filters the Name column.
This parameter supports wildcards.
Compliance StatusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None

WAC002 Account details

The Account details report shows details for an account. An account is a specific user in a specific system. An account can be personal, if matched one to one with an identity, or non-personal if not.Examples of non-personal accounts are administrative or service accounts.

The Account details report contains a trend graph, trend matrix, details section and a resource assignments list.

The Account details trend graph shows changes to resource assignments for the account in the period chosen for the report. The change points in the line links to the Resource assignments change log report (WRE007). The Account details trend matrix allows you to drill down to see resource assignments for the account per status and period chosen.The hyperlink in the resource assignments column links to the Resource assignments in period (WRE006) report.

WAC002 fields

FieldDescription
AccountAccount unique ID. This field links to the Account details report
Approval ReasonShows the comment given in attestation, if any.
Approval StateShows if the account has been recertified in an attestation survey. If recertified the field will show approval state (Approved or Rejected), approver unique ID and the time of recertification.
CategoryCategory of the account. Source system dependent
Color iconLeft side color coding indicates compliance status.

If the Role and Policy Engine is not used, the color icon shows approval state. Red indicates rejected or not attested; green indicates approved. This field links to the Resource assignment details report.
Compliance statusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None
DescriptionAccount description.
**Display name**
Distinguished nameDistinguished name of the account. Specific to AD accounts.
DomainDomain the account belongs to.
IdentityIf the account has been matched to an identity (by exact or fuzzy match or a custom join) the identity field shows the identity name. The field links to the Identity details report for matched identities.
Last logonThe date and time the account was last logged on.
Last password changeThe date and time the password was last changed for the account.
NameThe full account name.
PathThe relative path of the account.Specific to AD accounts.
ReasonShows the reason for the resource assignment, as calculated in the Role and Policy Engine.

If the Role and Policy Engine is not used the Reason field indicates if the resource assignment is implicit or explicit. An implicit resource assignment is associated with an identity through a reference, for example a context assignment. Assignments to resources that are child resources are also implicit resource assignments.
ResourceThe name of the resource the account has an assignment to. This field links to the Resource details report.
SourceThe source system the account has been imported through.
StatusStatus of the resource assignment: Active or Inactive. This field links to the Resource assignment details report.
Status maskStatus mask. Specific to AD accounts.
SystemShows the system the account belongs to. This field links to the System details report.
TypeShows the account type. Accounts that are matched to an identity via exact or fuzzy match will have the value of “Personal” in this column.For a custom join match, the type may be something other than “Personal”. Unless customizations have been made to the ODW import logic, the type field will be empty for accounts that are not matched to an identity.
Valid fromThe date the account is valid from.
Valid toThe date the account is valid to.

WAC002 parameters

ParameterDescription
Effective timeThe time the report is effective. Change the time to see a snapshot for another time.Click View Report to refresh after changing this parameter.
Max.itemsThe maximum number of returned items. By default this parameter is set to 100 items.Change to view more results.
Include indirect resources assignmentsAn indirect resource assignment is associated with an identity through a reference. Assignments to resources that are child resources are also indirect resource assignments.

Select: True/False
Show trendSelect: True/False to display/hide the chart showing the trend over time.
Trend fromThe from time used for the trend graph and matrix. Change the time to see data in another period. Click View Report to refresh after changing this parameter.
ResourceUse the Resource parameter to search for a resource assignment for a particular resource. This searches the resource column.Supports wildcards.

info

The Account details report is accessed from the any report that contains a reference to an account.The Identity details report for example will contain a link to the Account details reports for each account that is associated with the identity.

WAC003 Account ownership

Each account is ideally associated (matched) to an identity.Accounts are matched to identities in the ODW import by built-in or custom logic. The account ownership report is a list report of the ownership status for accounts in a system.

info

The Account ownership report can only be accessed from the System details report.

WAC003 fields

FieldDescription
AccountThe unique ID of the account. This field links to the Account details report.
Last updatedThe time the account ownership was last changed for the account.
IdentityThe Identity unique ID of the matched identity. This field links to the Identity details report.
StatusOwnership status.

The standard available values are: Confirmed, Auto Confirmed, Confirmed by Owner, Pending, Suspected Orphan. The values may be different if the ODW import logic has been customized.
SimilarityShows the similarity between account and identity as a percentage.
TypeShows the account type. Accounts that are matched to an identity via exact or fuzzy match will have the value of “Personal” in this column. For a custom join match, the type may be something other than “Personal”. Unless customizations have been made to the ODW import logic, the type field will be empty for accounts that are not matched to an identity.
ReasonShows the reason for the resource assignment, as calculated in the Role and Policy Engine.

If the Role and Policy Engine is not used the Reason field indicates if the resource assignment is implicit or explicit. An implicit resource assignment is associated with an identity through a reference, for example a context assignment.Assignments to resources that are child resources are also implicit resource assignments.
Compliance statusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None

WAC003 parameters

ParameterDescription
Effective time (required)The time the report is effective. Change the time to see a snapshot for another time. Click View Report to refresh after changing this parameter.
Max.items (required)The maximum number of returned items. By default this parameter is set to 100 items.Change to view more results.
Join statusUse the Join status drop down list to filter the report on a particular join status.The available values are: Confirmed, Auto Confirmed, Confirmed by Owner, Pending, Suspected Orphan.
AccountUse the Account parameter to search for a specific account.This searches the Account column.Supports wildcards.
Compliance statusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None

WAC004 Account ownership log

The Account ownership log report shows changes to account ownership for accounts within a chosen period.

info

The report can only be accessed from the Account ownership report.

WAC004 fields

FieldDescription
AccountThe unique ID of the account. This field links to the Account details report.
Last updatedThe time the account ownership was last changed.
IdentityThe Identity unique ID for the matched identity. This field links to the Identity details report.
StatusOwnership status.

The standard available values are: Confirmed, Auto Confirmed, Confirmed by Owner, Pending, Suspected Orphan. The values may be different if the ODW import logic has been customized.
ProbabilityShows the probability (confidence) of the match as a percentage.
TypeShows the account type. Accounts that are matched to an identity via exact or fuzzy match will have the value of “Personal” in this column. For a custom join match, the type may be something other than “Personal”.

Unless customizations have been made to the ODW import logic, the type field will be empty for accounts that are not matched to an identity.
EventShows the event for the particular object. Can be "New" or "Changed".
ReasonShows the reason for the resource assignment, as calculated in the Role and Policy Engine.

If the Role and Policy Engine is not used, the Reason field indicates if the resource assignment is implicit or explicit. An implicit resource assignment is associated with an identity through a reference, for example a context assignment.Assignments to resources that are child resources are also implicit resource assignments.
Compliance statusShows the compliance status as calculated by the Omada Identity Role and Policy Engine. The possible values are:

Explicitly Approved
Implicitly Approved
Not Approved
Orphan Assignment
Pending Deprovisioning
In Violation
Implicitly Assigned
None

WAC004 parameters

ParameterDescription
Effective time (from)The time the report is effective from. Change the time to change the “from date” for the report. Click View Report to refresh after changing this parameter.
Effective time (to)The time the report is effective to. Change the time to change the “to date” for the report. Click View Report to refresh after changing this parameter.
Max.items (required)The maximum number of returned items.By default, this parameter is set to 100 items. Change to view more results.
Join statusUse the Join status drop down list to filter the report on a particular join status.The available values are: Confirmed, Auto Confirmed, Confirmed by Owner, Pending, Suspected Orphan.
AccountUse the Account parameter to search for a specific account. This searches the Account column. Supports wildcards.

WAC005 Accounts pending deprovisioning

The Accounts pending deprovisioning report lists accounts that have been rejected in attestation but not yet removed in the source system.

info

The report can only be accessed from the System details report.

WAC005 fields

FieldDescription
AccountThe unique ID of the account. This field links to the Account details report.
NameThe full account name.
IdentityIf the account has been matched to an identity (by exact or fuzzy match or a custom join) the identity field shows the identity name. The field links to the Identity details report for matched identities.
StatusThe account status. The available values are Active, All, Disabled, Enabled and Inactive.
Approval stateShows the decision from the attestation survey. In this report, the state will be Rejected, as these are accounts that have been rejected and await deprovisioning.
Approval ReasonShows the comment given in attestation, if any.

WAC005 parameters

ParameterDescription
Effective time (required)The time the report is effective. Change the time to see a snapshot for another time. Click View Report to refresh after changing this parameter.
Max. items (required)The maximum number of returned items. By default this parameter is set to 100 items. Change to view more results.
AccountUse the Account parameter to search for a specific account. This searches the Account column. Supports wildcards.