Please do advise if I am posting in the wrong place, I have not found this the easiest site to navigate (or maybe it is me…).
I have been tasked with auditing and fixing our privileged accounts after a Microsoft CSAT scan. I have inherited an absolutely shocking number of accounts that are ‘affective domain administrators’ – 293!
It seems the previous attitude has been security anethema – giive service accounts Domain Admin status to ensure they are not part of the problem…Â sigh
I have investigated numerous powershell options and come to the conclusion that I need to:
- Find out which SERVERS each account is authenticating against (Inluding DCs obviously).
- Find out the least required access for each server.
- Amend access accordingly and test.
Would anyone be able to advise on the best way to proceed please?
Thank you in advance.