Discovery Task
The Discovery Task enables you to scan a range of IP addresses associated to a Gateway to achieve the following:
-
Locate available IP Addresses to establish a host or service within a Gateway.
-
Identify the IP Addresses that are already associated to a host or a service within a Gateway.
This document contains the step-by-step guide to create a Discovery task and the available actions for you to use the Discovery task.
-
Discovery Tasks for services and credentials are available for VPAM and PAM users.
-
Discovery Tasks for endpoints and accounts are available only for PAM users.
Requirements
To use the Discovery task, you must comply with the following requirements:
-
Server Version: Your server must be version 26.1.3
-
Admin Role or Permissions: You must be a System Administrator of your server or be a user with a role that has the following permissions:
-
LOGIN_TO_WEB_UI -
VIEW_TASK -
CREATE_TASK -
EDIT_TASK -
DELETE_TASK -
VIEW_TASK_PASSWORD_POLICY -
EXECUTE_TASK_ON_DEMAND -
VIEW_APPLICATION -
EDIT_APPLICATION -
EDIT_SERVICES -
VIEW_GATEWAY
-
How-To Use the Feature
The Discovery task enables you to do the following actions:
-
Create a Discovery Task
-
View the Discovery Tasks
-
Edit a Discovery Task
-
Review a Discovery Task's Report
-
Review a Discovery Task's History
To create a new Discovery Task, navigate to the Tasks menu of the VPAM new UI. Use the following steps to create a new Discovery task:
-
Open the Tasks sub-menu.
-
Select Add New Task.
-
Select Discovery.
-
Select the type of discovery:
-
IP Range: Enables you to scan a determined range of IP Addresses associated to a Gateway and identify the available services and accounts in the range.
NOTE:Other types of discovery are planned for release in the future.
-
-
Click Next.
-
Complete the form and Create Task considering the details in the following table:
| Field in Form | Description |
|---|---|
| Task Name | Provide a name for the task. Ensure it is a unique name. |
| IP Address From | Provide the starting IP Address that you want to scan. |
| IP Address To | Provide the ending IP Address that you want to scan. |
| Gateway |
Select an existing Gateway that you want to scan with this task. Note: A single IP Discovery task can only be associated to a single Gateway. |
| Account Discovery* |
Select to enable Account discovery in the IP Range you provide. |
| Services |
Select one or multiple services that you want to search for in the range of IPs. |
| Discovery Schedule* |
Establish the frequency in which this task will run. Select one or both options:
|
To view the available Discovery tasks, navigate to Tasks.
The Tasks sub-menu contains a table of all available tasks in your VPAM server, including Credential Rotation and Discovery.
To view a Discovery Task details, click the name of the task.
The Task Details page of a Discovery task contains the information added when creating a task.
To view more details, you can use the Discovery Reports or Task History tabs.
To edit an Discovery task, navigate to the Task Details page of the task you want to modify.
Locate the section you want to edit:
-
Task Information: Modify the task's name, associated Gateway, range, or services.
-
Discovery Schedule: Modify the rules to run the tasks, including frequency and on-demand availability.
This option also enables you to Delete the task.
The Discovery Report and Task History tabs enable you to do the following:
-
Discovery Report: Open the information generated by the task during the latest execution.
-
Task History: View all the task's executions, dates, triggering (by system or on demand), range, and execution status.
Hosts Report
The Hosts Report page in the Reports tab displays the hosts reached by the system during the IP Range Discovery task.
Accounts Report
The Accounts Report page in the Reports tab displays the accounts reached by the system during the IP Range Discovery task.
The Account Discovery feature is driven by PAM and may require additional licensing. Contact your Imprivata Customer Support for more information.
When you select Account Discovery, the system displays the following additional configurations required to run the Account discovery:
-
Select account type to discover:
-
All Accounts: The account discovery reveals all the accounts in the IP Range you specified.
-
Privileged Accounts: The account discovery reveals only the privileged accounts in the IP Range you specified.
-
SSH Privileged Accounts: The system extracts a deduplicated list of usernames that belong to any of the privileged groups sudo, wheel, or admin on a Linux system.
-
Windows Privileged Accounts: The PowerShell script produces a deduplicated list of enabled local user accounts that are members of the local Administrators group. It deliberately excludes domain-based admin groups and local service or system accounts that are disabled.
NOTE:The task does not discover accounts in Active Directory or Entra ID.
-
-
-
Select the Platforms to discover accounts: Platform selection automatically adds the required services for account discovery (SSH for Linux/Unix, WinRM Secure for Windows).
-
Windows
-
Linux/Unix
-
-
Credentials: Select the credentials the task will use for the task.
Discovery Schedule
The Schedule Discovery frequency considers the following rules:
-
Daily: Click the clock button to set a time of day when this task runs.
-
Weekly: Select the day (or days) and time on which the task runs.
-
Monthly: Select the days of the month and time on which the task runs.
Next Steps After Discovery
After you have successfully run a Discovery task, the Discovery Reports tab displays the following information:
-
Checkbox: Select the row.
-
Host: Displays the IP Address discovered by the task, within the range you provided.
-
Service: Displays the service that you can assign to the host.
-
Port: Displays the port associated to the host and service.
-
Status: Displays a status for the host:
-
In Progress: The task is currently running
-
Listening: The server can configure the service for the host.
-
Not Reachable: The server can not configure the service for the host.
A Not Reachable status might imply that the IP Address is protected or it already has a configured service.
-
-
Run Time: Displays the date and time of the discovery.
-
User: Displays the user that ran the task.
-
Actions: Displays the available actions for the Host:
-
Import: Enables you to pull the Host into an existing application in the Gateway.
-
Imported to: Displays that this Host has already been imported to an application in the Gateway.
-
To import the host to an application, click the Import button in the Reports table. The Import dialog opens.
If you have selected more that one row in the Reports table, use the Import Selected button. The Import dialog opens and associates all the selected hosts to the same application.
Select the application in your Gateway for which you want to configure the host.
To configure the host, read the Services documentation.
The Accounts Report page contains the following information:
-
Host: Displays the IP Address discovered by the task, within the range you provided.
-
Display Name: Displays the account found in discovery.
-
User Name: Displays the name of the user related to the account.
-
Run Time: Displays the date and time of the discovery.
-
Platform: Displays the Operating System where the account was found.
-
Status: Displays a status for the account:
-
Active: The server can import the account.
-
Not Found: The server can not import the account.
A Not Found status might imply that the account is protected.
-
-
Actions: Displays the available actions for the account:
-
Import: Enables you to pull the account into an existing application in the Gateway. The Import Account page opens.
-
Importing Accounts
The Import Account page enables you to configure the account found in Discovery.
Configuring discovered accounts enable you to assign a credential to the account, establish the services that the account can access, assign a Secret Scope, grant Vendor-level access to the secret to the account, and configure the credential information and rotation policy.
You can import accounts using:
-
Standard onboarding (manual or bulk)
-
Credential association with services
Additional options, such as credential rotation integration, may be available in future releases.
To configure credentials, read the Vault (New UI) or Legacy Credentials documentation.
Discovery Logs
Discovery tasks logs are available for System Administrators to review in: System Administration > Admin Log > User Activity. To identify the logs related to a Discovery Task, do the following:
-
Click the options menu (three dots) of the Object Type column.
-
Select Filter.
-
Search Task keyword.
-
Identify the task using the Time, User ID, and Details columns:
-
Time: Locate date and time when you created and ran the task.
-
User ID: Tasks can only be run by a System Administrator or a user with relevant permissions. Use the Filter option to locate these users.
-
For tasks run On Demand: Locate your user ID or the ID of the person you are auditing.
-
For tasks run by Schedule Discovery: Locate the system user ID and validate with the Time and Details columns.
-
-
Details: Locate the DISCOVERY key word in the Type attribute of the Details column.
-
When a Discovery task is run On Demand, the logs reflect the following information:
| Method | Object Type | Definition | Triggered by | Details |
|---|---|---|---|---|
| CREATE | Task |
The task was created in the Tasks menu by a permitted user. |
User | Use this column to identify your task by the name you assigned, and the type of task. |
| UPDATE | Task | The task was updated in the Tasks Details page by a permitted user. | User | Review the changes made to the task. |
| USE | Task | The task was run by a permitted user. | User | The task was executed on demand. |
Tasks run with a Schedule Discovery do not show up in the System Administration > Admin Log > User Activity. Use the Task History and Discovery Reports tab to audit the Schedule Discovery tasks.