Security

Security audit reports for PeopleSoft: permission list analysis, password audits, user access reviews, and more.

Eight reports against PSOPRDEFN, PSCLASSDEFN, PSROLECLASS, PSAUTHITEM, and PSMSGNODEDEFN. They answer: who has too much, who has stale credentials, and which IB nodes will let any caller in.

ReportDescription
Full Access Permission ListsIdentifies permission lists with excessive menu authorizations
Nodes with No PasswordFinds active message nodes with no authentication or missing passwords, which could allow unauthorized integration access
PeopleTools Access AuditLists users with special PeopleTools access (Application Designer, Data Mover, Object Security, Query, Import Manager), traced through permission lists and roles
Stale Password AuditIdentifies unlocked users who have not changed their password in a configurable number of days
User Full Access ReportFull report of everything a user can access: roles, permission lists, tools, menus, service operations, and more
Dangerous Permissions AuditIdentifies permission lists granting access to dangerous capabilities such as SOAP-to-CI, WSDL generation, user profile management, and node configuration
SOAP to CI Access AuditIdentifies users with access to the SOAP-to-CI WebLib (WEBLIB_SOAPTOCI), mapping their access path and accessible Component Interfaces
SSO Bypass Password AuditIdentifies users with native passwords in PSOPRDEFN when using Single Sign-On

Full Access Permission Lists

This report identifies PeopleSoft permission lists that have an unusually high number of menu authorizations.

Nodes with No Password

This report identifies active PeopleSoft message nodes that have no authentication configured or have authentication enabled but no passwords set.

Stale Password Audit

This report identifies unlocked PeopleSoft user accounts whose passwords have not been changed within a configurable number of days.

User Full Access Report

This report generates a consolidated view of everything a single PeopleSoft user can access.

Dangerous Permissions Audit

This report identifies permission lists that grant access to dangerous capabilities in PeopleSoft.

SOAP to CI Access Audit

‘SOAP to CI’ is a powerful tool that allows using excel or any web client to interact with PeopleSoft Component Interfaces via SOAP web services.

SSO Bypass Password Audit

This page documents the SSO Bypass Password Audit report, which identifies native PeopleSoft user passwords stored in the PSOPRDEFN table.

PeopleTools Access Audit

Special PeopleTools access (Application Designer, Data Mover, Object Security, Query, Import Manager, 2-Tier Client) is granted on the PeopleTools …