Click here to get back home

Domain Admin removed

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Domain Admin removed Dennis Burgess 03-30-2006
Posted by Dennis Burgess on March 30, 2006, 4:20 pm
Please log in for more thread options
I have a user that was a domain admin. I have found several folders sitting
out there on various servers that have been restricted to his user account
only, I had to take ownership to be able to delete the folders.

Is there a program that can scan my servers for these weird security
permissions looking for other things that he may have done?

Dennis



Posted by Steven L Umbach on March 30, 2006, 11:26 pm
Please log in for more thread options
I would not think what he did was unusual necessarily but I don't know all
the details. There are free tools you can use such as dumpsec that can scan
computers for folder and share permissions but it can not be configured to
look for only folders that a specific user has only permissions for his user
account. Showacls is supposed to be able to look for permissions by user but
I have had flaky results for it. You can use subinacl to search for the
owner of folders and a WHOLE lot more on a computer once you figure out it's
syntax. That user may be the owner of such folders. The links below may
help. --- Steve

http://www.somarsoft.com/ -- dumpsec
http://technet2.microsoft.com/WindowsServer/en/Library/ed34eee3-7dbd-44c6-8fb8-8b8b2c6f06dc1033.mspx

--- showacls, subinacl, and others
http://www.microsoft.com/downloads/details.aspx?FamilyID=E8BA3E56-D8FE-4A91-93CF-ED6985E3927B&displaylang=en

--- subinacl download


>I have a user that was a domain admin. I have found several folders sitting
>out there on various servers that have been restricted to his user account
>only, I had to take ownership to be able to delete the folders.
>
> Is there a program that can scan my servers for these weird security
> permissions looking for other things that he may have done?
>
> Dennis
>
>



Similar ThreadsPosted
Added to Domain Admins but removed again automatically March 7, 2008, 1:53 pm
Inheritable rights that cannot be removed February 15, 2007, 5:39 pm
Allowing a Domain User Admin Rights to a Couple of Domain Servers June 29, 2005, 8:13 pm
Adding another domain users to your local domain admin group December 28, 2005, 12:19 pm
Want to make an Admin for only one Domain Controller April 7, 2006, 4:42 pm
domain admin account impersontating November 6, 2006, 8:20 am
Rename Domain Admin Account June 10, 2008, 4:03 am
Problem with Domain Admin becoming Administrator (builtin) April 11, 2006, 10:07 am
Domain Users to have Local Admin rights April 28, 2006, 3:17 pm
Need limited domain admin rights user account. August 8, 2005, 2:33 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap