Administer > Audit and compliance > Compliance > Audit compliance > Audit compliance remediation

Audit compliance remediation

The Compliance view allows you to view all audits that target a server or group of servers and to remediate those results that are out of compliance. This ensures that a server’s configuration complies with the rules defined in an audit.

For each audit rule that is out of compliance on the target server (the server’s configuration either did not match the rule definition or simply did not exist), remediation copies the rule object to the target server so it matches the rule. Or, in the case of a value-based audit rule, remediation changes the target server’s configuration to match the rule.

Example: You have an audit that checks a group of Windows servers to make sure that they contain certain registry keys and ACLs. After the audit runs against a Windows server, it is possible that several of the rules are out of compliance. This means the Registry keys specified in the audit rules were not found on the target servers. When you remediate, the audit feature copies the Registry keys specified in the audit rule to the target servers. This ensures that the servers have the specific keys and associated ACLs. For a group of servers, remediation has the same results—where only the remediation operation applies to all servers in the group, including all servers contained in any sub-groups.

Remediating audits attached to servers

You can remediate an audit that is attached to a single server or an audit that is attached to multiple servers. You can only remediate individual audits. You cannot aggregate audits at the top level. For any group that is selected, all direct server children in that group are the subject of the remediation.

When the Remediate button is not enabled in the Compliance view, even though a single policy is selected in the detail pane and one or more servers are selected in the summary pane, it typically means that there is no audit result for that policy to remediate.

You cannot run an audit on a group of servers from the Compliance view. However, you can create an audit that runs against a group of servers and remediate those audit results for a group of servers from the Audit Results window.

To remediate an individual audit on a single server:

  1. In the navigation pane, select Devices > Servers > All Managed Servers.
  2. In the content pane, select a server.
  3. Right-click and then select Open to open the Device Explorer.
  4. In the navigation pane, select ManagementPolicies > Compliance.
  5. In the details pane of the Compliance view, expand the Audit category and then select an individual policy.
  6. Click Remediate and then complete the steps in the Remediate wizard.

To remediate an individual audit on multiple servers:

  1. In the navigation pane, select Devices > Device Groups, and then select a group.
  2. From the View drop-down list, select Compliance.
  3. Select multiple servers by selecting the check boxes next to each server.
  4. In the details pane of the Compliance view, expand the Audit category and select an individual audit that is targeting all of the selected servers.
  5. Click one of the following buttons to perform a type of remediation for an audit on a single server or on multiple servers:
    • Details: Displays the Audit Result window that shows all differences found between the audit and the target, and allows you to remediate the differences by rule or by server. Click the View Rules Details link to open the Rules window and view the audit rules. Select a server and click Run Partial Audit to launch the Audit Servers wizard.
    • Run Audit: Launches the Audit Servers wizard and allows you to run the audit immediately or schedule to run the audit at a later time. The audit will run against all servers targeted by the audit.
    • Remediate: Launches the Remediate wizard, which allows you to remediate target server configurations that are out of compliance with the audit rules. You can remediate differences by rule or by server. If none of the selected servers have remediate results for the selected policy, a No Results Found to Remediate! message will display.
    • Scan Devices: Displays the Scan for Compliance dialog where you first select the types of policies you want scanned and then click Scan to launch the job. This processes scans the selected servers for all Audit, Audit Policy, Software, Patch, and Configuration policies attached to the servers, and does not have any effect on the audits that target this server.

To monitor the scan’s progress, refresh the Compliance window (press F5).

Note You can also choose Action > Scan to view a scan’s progress.