Spread the word.

Share the link on social media.

Share
  • Facebook
Have an account? Sign In Now

Sign Up

Create your WindowsTechno Community account. It’s free and only takes a minute.

Have an account? Sign In
Continue with Facebook
Continue with Google
or use

Have an account? Sign In Now

Sign In

Continue with Facebook
Continue with Google
or use

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Continue with Facebook
Continue with Google
or use

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

WindowsTechno Community

WindowsTechno Community Logo WindowsTechno Community Logo

WindowsTechno Community Navigation

  • Home
  • About Us
  • Write For Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • About Us
  • Write For Us
Home/ Questions/Q 979
Next
Anonymous
  • 1
Anonymous
Asked: February 19, 20232023-02-19T15:22:52+05:30 2023-02-19T15:22:52+05:30In: Active Directory

Auditing Domain Administrators – Best practice / Advice needed please

  • 1

Please do advise if I am posting in the wrong place, I have not found this the easiest site to navigate (or maybe it is me…).

I have been tasked with auditing and fixing our privileged accounts after a Microsoft CSAT scan. I have inherited an absolutely shocking number of accounts that are ‘affective domain administrators’ – 293!

It seems the previous attitude has been security anethema – giive service accounts Domain Admin status to ensure they are not part of the problem… sigh

I have investigated numerous powershell options and come to the conclusion that I need to:

  1. Find out which SERVERS each account is authenticating against (Inluding DCs obviously).
  2. Find out the least required access for each server.
  3. Amend access accordingly and test.

Would anyone be able to advise on the best way to proceed please?

Thank you in advance.

  • 0 0 Answers
  • 13 Views
  • 0 Followers
  • 0
Share
  • Facebook

    Leave an answer
    Cancel reply

    You must login to add an answer.

    Continue with Facebook
    Continue with Google
    or use

    Forgot Password?

    Need An Account, Sign Up Here
    Continue with Facebook
    Continue with Google

    Sidebar

    Ask A Question

    Stats

    • Questions : 119
    • Answers : 26
    • Posts : 15
    • Comment : 1
    • Best Answers : 4
    • Users : 8
    • Groups : 2
    • Group Posts : 0
    • Popular
    • Comments
    • Tags
    • Vipan Kumar

      DFSR no longer replicates files

      • 1 Comment
    • Vipan Kumar

      Wintel Administrator Interview Questions

      • 0 Comments
    • Vipan Kumar

      What is Active Directory?

      • 0 Comments
    • Vipan Kumar

      Active Directory Domain Services Overview

      • 0 Comments
    • Vipan Kumar

      How to fix the issue with the slow authentication

      • 0 Comments
    • Manoj
      Manoj added a comment Nice explanation ? February 4, 2023 at 11:21 am

    Users

    Shawn Davis

    Shawn Davis

    • 0 Questions
    • 0 Answers
    Manoj Kumar

    Manoj Kumar

    • 0 Questions
    • 0 Answers
    Vipan Thakur

    Vipan Thakur

    • 0 Questions
    • 0 Answers

    Explore

    • Home
    • Questions

    Footer

    © 2023 WindowsTechno. All Rights Reserved
    by WindowsTechno.