ActiveDirSec.Org

The world's most trusted forum on Active Directory Security


Post Info TOPIC: How to determine delegated access in Active Directory?


Member

Status: Offline
Posts: 6
Date: May 31, 2011
How to determine delegated access in Active Directory?
 
 


Hi again. As I had mentioned, we were in the midst of a thorough review of our Active Directory, and are looking at everything, from DC security to auditing to delegated access in our Active Directory.

We natively delegate administration in Active Directory, and in fact having been doing so for a few years now. The problem is that in the last two/three years. we've had some administrative churn, and so have had to make a fairly non-trivial set of changes to delegated rights in our Active Directory.

The problem is that we now don't really know who is delegated what access, and that's a huge problem. For political reasons, its a little difficult to discuss internally, because the notion is that everyone is trusted internally. All that's good, but then why delegate if everyone's supposed to have equal access. Anyways, I seem to be meandering here.

Getting back to the point, I'd like to know if there is a way to efficiently find out just how might be delegated what access in the Active Directory? We're not even sure where to actually start from, given how complicated it is, especially with inheritance and nested groups and so many different kinds of permissions, not all of which seem to apply half the time anyway.

As always, all helpful pointers and guidance are much appreciated. Thanks.



__________________

I’m sorry, but having a DB9 on the drive and not driving it is a bit like having Keira Knightley in your bed and sleeping on the couch.

Page 1 of 1  sorted by
Quick Reply

Please log in to post quick replies.

Post to Facebook Post to Digg Post to Del.icio.us
Members Login
Username 
 
Password 
    Remember Me