Unathorised AD Use

  • Thread starter Thread starter Billy
  • Start date Start date
B

Billy

Hi all.

I have a strange problem.
I started work at a company a few weeks ago and lets say
its not the best set up company.

Some things have been happening on AD I.E
OU's Added that are slanderous or abusive.
Users being moved.

I have checked all the permissions and even tested logging
on as a user and it cant be done.
Only way i can see is that someone knows the admin
password which i have changed twice. They could log onto
the server through terminal services and change it but
like i said they need admin password or privelages.
I have checked and the groups and members of everyone etc.
They cant do it though MMC unless they have the rights.

I have put some logging on Failed and Sucess Logon
attempts and also started Auditing OU creation and
deletion.

Any one else have any ideas?
 
Could someone have been given delegated rights to all or
part of the AD? They don't need to be an administrator
then.

Ian
 
How can we know which users are delegated controls. Is
there any tool which we can run on Active Directory to
find out such user??

Shaan
 
Back
Top