We have a paper form to keep track of who gets access to what. This works well unless they need access to something else, now they have 2 forms and we miss one.Is there software to track who has access to what? At some point we may want to make the request available to directors from a web portal. Any ideas?

Our paper form tracks who has email, voicemail, an account for our radiology software, labor and delivery software, clinical software, hospital software, respiratory software etc.

9 Spice ups

Network Detective can give good reporting on access, CJWDEV also has some good reporting tools at Cjwdev | NTFS Permissions Reporter

I’ve used both in an MSP environment and have had really good success in getting the reporting I needed out of both.

Netwrix does the best job I’ve seen for all access requests, even “Reads”.

AccessEnum from Sysinternals is great too for a quick and dirty look.

@Netwrix

2 Spice ups

Depending on scale of your investigation you can use powershell to get report (I won’t repost code here as there are a lot of how-tos you might consider quite useful):

How to Detect Who Has Access to What Data on Windows File Servers

How to Detect Who Tried to Modify a File or a Folder on Your Windows File Server

How to Get ACL for a Folder

How to Get an NTFS Permissions Report

or even How to Detect Who Installed What Software on Your Windows Server

But, as @pmandryk ​ mentioned, Netwrix Auditor for File Servers will provide you complete visibility into changes, data access
and data usage on file servers. After 20 days of free trial you can either choose to buy commercial license or switch to Community Free Edition - it’s restricted in comparison to full version yet still quite powerful tool to have at your disposal. :wink:

@anthoneyfryfogle0284

1 Spice up

LepideAuditor for File Server evaluates the current effective permissions . With numerous options available, you can get a summarized view of the different kinds of permissions very easily.

You can also check our Permissions & Privileges Analysis solution to determine who has access to sensitive data within your organization and whether access levels are appropriate.

Elastic search and Kibana console will have this feature with the client agent installed on your network resource and which can monitor and give you a cool dashboard and reports.