Active Directory Accelerator Guide

Active Directory Accelerator Guide

BlackList Rules

BlackList Rules

The BlackList rule is a rule folder that defines LDAP groups or users with LDAP attribute values that receive masked data.
To use the BlackList masking method, enable the BlackList rule folder and disable the WhiteList rule folder.
The BlackList rule folder contains BlackListGroups, BlackListAttributeName, BlackListAttributeValue, and MaskIfLDAPMatch rules.
If you want to mask data based on the LDAP group of a user, enable the BlackListGroups rule and disable the BlackListAttributeName and BlackListAttributeValues rules. You define the LDAP groups that receive masked data in the BlackListGroups rule and set the Groups symbol value to the list of the LDAP groups. Enter the LDAP groups that receive masked data in the Symbol Value field. Separate groups with a pipe symbol ( | ).
If you want to mask data based on the LDAP attribute values of users, disable the BlackListGroups rule and enable the BlackListAttributeName and BlackListAttributeValues rules. Define the attribute in the BlackListAttributeName rule. Set the ATTR_NAME Symbol Value to the name of the attribute. In the BlackListAttributeValues rule, define the attribute values of the attribute that you specified in the BlackListAttributeName rule. Set the ATTR_VALUES Symbol Value to the attribute values that you use to identify a user that receives masked data.
You must identify users that receive masked data based on the LDAP group or attribute values. You cannot identify LDAP groups and attribute values. If you enable the BlackListGroups rule, the LDAP matcher does not verify the values of the ATTR_NAME and ATTR_VALUES that you define in the BlackListAttribueName and BlackListAttributeValues rules.
Configure the MaskIfLDAPMatch rule to define how to mask the data. The rule contains table columns that commonly contain personally identifiable information. Modify the rule based on the data that you want to mask.
The following table describes the BlackList rules:
Rule
Description
BlackListGroups
Defines the value of the Groups symbol. Enter the LDAP groups that you want to receive masked data.
You cannot use the BlackListGroups rule with the BlackListAttributeName and BlackListAttribueValues rules.
BlackListAttributeName
Defines the ATTR_NAME symbol. Enter the LDAP attribute that you use to identify users that receive masked data.
You cannot use the BlackListAttributeName rule with the BlackListGroups rule.
BlackListAttributeValues
Defines the ATTR_VALUES symbol. Enter the LDAP attribute values that you use to identify users that receive masked data.
You cannot use the BlackListAttributeName rule with the BlackListGroups rule.
MaskIfLDAPMatch
Defines how to mask the sensitive data.

0 COMMENTS

We’d like to hear from you!