Admin Right

G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

We are 2 domain admins in the company, and one of us has
assigned admin rights to one of the users and when I asked
the domain admin he said he didn't so it.

So is there anyways to discover who assigned admin right
to that user?
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Controller wrote:
| We are 2 domain admins in the company, and one of us has
| assigned admin rights to one of the users and when I asked
| the domain admin he said he didn't so it.
|
| So is there anyways to discover who assigned admin right
| to that user?
Are you saying that this user has domain admin rights, or that they have
admin level rights on some files or folders?

I THINK that if you have 'full control' on a file you can assign rights
to it even if you are not a domain admin, but somebody with more
experience could please confirm or deny this (Steve U possibly LOL).
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBUUCXqmlxlf41jHgRAnLiAJwKHz+FDOdmSUaagUTyd8H0ILErqgCfeKvB
dzgmrWOr9OInUStgnzTzoLI=
=ZOpB
-----END PGP SIGNATURE-----
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

Both of us has same level of rights, we are domain admins.
One of us has given admin level right to one of the users
and when I asked him he said he didn't do it.

I need a way to find out who gave that access to that user?

>-----Original Message-----
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>Controller wrote:
>| We are 2 domain admins in the company, and one of us has
>| assigned admin rights to one of the users and when I
asked
>| the domain admin he said he didn't so it.
>|
>| So is there anyways to discover who assigned admin right
>| to that user?
>Are you saying that this user has domain admin rights, or
that they have
>admin level rights on some files or folders?
>
>I THINK that if you have 'full control' on a file you can
assign rights
>to it even if you are not a domain admin, but somebody
with more
>experience could please confirm or deny this (Steve U
possibly LOL).
>-----BEGIN PGP SIGNATURE-----
>Version: GnuPG v1.2.5 (MingW32)
>Comment: Using GnuPG with Thunderbird -
http://enigmail.mozdev.org
>
>iD8DBQFBUUCXqmlxlf41jHgRAnLiAJwKHz+FDOdmSUaagUTyd8H0ILErqg
CfeKvB
>dzgmrWOr9OInUStgnzTzoLI=
>=ZOpB
>-----END PGP SIGNATURE-----
>.
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

anonymous@discussions.microsoft.com wrote:
| Both of us has same level of rights, we are domain admins.
| One of us has given admin level right to one of the users
| and when I asked him he said he didn't do it.
|
| I need a way to find out who gave that access to that user?
|
|
|>-----Original Message-----
| Controller wrote:
| | We are 2 domain admins in the company, and one of us has
| | assigned admin rights to one of the users and when I
|
|> asked
|
| | the domain admin he said he didn't so it.
| |
| | So is there anyways to discover who assigned admin right
| | to that user?
| Are you saying that this user has domain admin rights, or
|
|> that they have
|
| admin level rights on some files or folders?
|
| I THINK that if you have 'full control' on a file you can
|
|> assign rights
|
| to it even if you are not a domain admin, but somebody
|
|> with more
|
| experience could please confirm or deny this (Steve U
|
|> possibly LOL).
|

So the user is in either the Domain Admins or the Administrators group?

There are two of you with Domain Admin rights and you use your 'own'
login accounts? There is also an 'Administrator' account, which makes
three accounts we know of with administrator privilages. You are sure
that there are NO other accounts with this level of access?

Are you TOTALLY sure that a)both of your passwords are secure, maybe
change them anyway b)neither of you left a machine logged in with admin
rights an unattended and c)nobody knows the password for 'Administrator?

Before you start trying to find out who did it, ensure you know the
number of accounts who could have done it.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (MingW32)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBUYTlqmlxlf41jHgRArOxAKDZNlbk8GfXFpAPjA0EY3jeEAPXsQCeMBUI
f0/AtTeY0YyRP6Tkf60DipU=
=lmbe
-----END PGP SIGNATURE-----
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

If you enable auditing of account management in the Domain Controllers Security
Policy an event will be recorded in the security log on one of the domain
controllers, probably Event ID 632. The same can be done for a local computer
security policy if this user was added to the administrators group on a domain
computer. Any administrator however can clear the security logs though that itself
will record an event with the user name that cleared the log. The link below goes
into a lot more detail on auditing if interested. --- Steve

http://www.microsoft.com/technet/security/guidance/secmod144.mspx

"Controller" <anonymous@discussions.microsoft.com> wrote in message
news:37e601c4a074$c94fd7c0$a501280a@phx.gbl...
> We are 2 domain admins in the company, and one of us has
> assigned admin rights to one of the users and when I asked
> the domain admin he said he didn't so it.
>
> So is there anyways to discover who assigned admin right
> to that user?