Full Access Permission Lists
This report identifies PeopleSoft permission lists that have an unusually high number of menu authorizations.
Eight reports against PSOPRDEFN, PSCLASSDEFN, PSROLECLASS, PSAUTHITEM, and PSMSGNODEDEFN. They answer: who has too much, who has stale credentials, and which IB nodes will let any caller in.
| Report | Description |
|---|---|
| Full Access Permission Lists | Identifies permission lists with excessive menu authorizations |
| Nodes with No Password | Finds active message nodes with no authentication or missing passwords, which could allow unauthorized integration access |
| PeopleTools Access Audit | Lists users with special PeopleTools access (Application Designer, Data Mover, Object Security, Query, Import Manager), traced through permission lists and roles |
| Stale Password Audit | Identifies unlocked users who have not changed their password in a configurable number of days |
| User Full Access Report | Full report of everything a user can access: roles, permission lists, tools, menus, service operations, and more |
| Dangerous Permissions Audit | Identifies permission lists granting access to dangerous capabilities such as SOAP-to-CI, WSDL generation, user profile management, and node configuration |
| SOAP to CI Access Audit | Identifies users with access to the SOAP-to-CI WebLib (WEBLIB_SOAPTOCI), mapping their access path and accessible Component Interfaces |
| SSO Bypass Password Audit | Identifies users with native passwords in PSOPRDEFN when using Single Sign-On |
This report identifies PeopleSoft permission lists that have an unusually high number of menu authorizations.
This report identifies active PeopleSoft message nodes that have no authentication configured or have authentication enabled but no passwords set.
This report identifies unlocked PeopleSoft user accounts whose passwords have not been changed within a configurable number of days.
This report generates a consolidated view of everything a single PeopleSoft user can access.
This report identifies permission lists that grant access to dangerous capabilities in PeopleSoft.
‘SOAP to CI’ is a powerful tool that allows using excel or any web client to interact with PeopleSoft Component Interfaces via SOAP web services.
This page documents the SSO Bypass Password Audit report, which identifies native PeopleSoft user passwords stored in the PSOPRDEFN table.
Special PeopleTools access (Application Designer, Data Mover, Object Security, Query, Import Manager, 2-Tier Client) is granted on the PeopleTools …