RE: [ActiveDir] AD Security Auditing

2007-01-28 Thread joe
object type and alert you to delta's there. -- O'Reilly Active Directory Third Edition - http://www.joeware.net/win/ad3e.htm _ From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Thursday, January 25, 2007 5:21 PM To: ActiveDir@ma

Re: [ActiveDir] AD Security Auditing

2007-01-25 Thread AFidel
ActiveDir@mail.activedir.org To cc Subject [ActiveDir] AD Security Auditing We are embarking on a project to clean up our OUs structure and reassign permissions that have grown unmanageable over time. To accomplish this it would be nice to be able to dump permissions on all OU objects

RE: [ActiveDir] AD Security Auditing

2007-01-23 Thread Almeida Pinto, Jorge de
Dir@mail.activedir.org Subject: [ActiveDir] AD Security Auditing We are embarking on a project to clean up our OUs structure and reassign permissions that have grown unmanageable over time. To accomplish this it would be nice to be able to dump permissions on all OU objects and individual obj

RE: [ActiveDir] AD Security Auditing

2007-01-23 Thread Akomolafe, Deji
@mail.activedir.org Subject: [ActiveDir] AD Security Auditing We are embarking on a project to clean up our OUs structure and reassign permissions that have grown unmanageable over time. To accomplish this it would be nice to be able to dump permissions on all OU objects and individual object types

[ActiveDir] AD Security Auditing

2007-01-23 Thread Casey Robertson
We are embarking on a project to clean up our OUs structure and reassign permissions that have grown unmanageable over time. To accomplish this it would be nice to be able to dump permissions on all OU objects and individual object types (users, computers, etc) so that we can determine who has rig

RE: [ActiveDir]AD SECURITY."Run As" command used - to impersonate Administrators

2006-11-13 Thread Robert Rutherford
PROTECTED] W:    www.quostar.com     From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ramon Linan Sent: 13 November 2006 14:39 To: ActiveDir@mail.activedir.org Subject: [ActiveDir]AD SECURITY."Run As" command used - to impersonate Administrators   Hi, So I

[ActiveDir]AD SECURITY."Run As" command used - to impersonate Administrators

2006-11-13 Thread Ramon Linan
Hi, So I decided to try out GFI event monitor, I am loving it so far, but I am not a security expert so I am easy to impress. Anyway, I got a bunch of emails like the one below. Have you guys seen something similar in your logs? Is this someone trying to hack or a service trying to run

RE: [ActiveDir] AD Security Group Information

2006-11-01 Thread joe
chael M.Sent: Tuesday, October 31, 2006 7:17 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security Group Information adfind -default -f "&(objectclass=group)(groupType=-2147483646)" -tdc whenChanged   hth, Mike Thommes   From: [EMAIL PROTECTED] [mailto:[EMAIL PRO

RE: [ActiveDir] AD Security Group Information

2006-10-31 Thread Thommes, Michael M.
ct: [ActiveDir] AD Security Group Information   I'm having a clear up of my domain and there are approx 8000 security groups. Some of these are no longer required, how is the best way to determine whether the groups are still in use? Is there any way to query the groups to identify

RE: [ActiveDir] AD Security Group Information

2006-10-31 Thread Almeida Pinto, Jorge de
PROTECTED] On Behalf Of Frank AbagnaleSent: Tuesday, October 31, 2006 09:51To: activedir@mail.activedir.orgSubject: [ActiveDir] AD Security Group Information I'm having a clear up of my domain and there are approx 8000 security groups. Some of these are no longer required, how i

RE: [ActiveDir] AD Security Group Information

2006-10-31 Thread neil.ruston
edir@mail.activedir.orgSubject: [ActiveDir] AD Security Group Information I'm having a clear up of my domain and there are approx 8000 security groups. Some of these are no longer required, how is the best way to determine whether the groups are still in use? Is there any way to query the

[ActiveDir] AD Security Group Information

2006-10-31 Thread Frank Abagnale
I'm having a clear up of my domain and there are approx 8000 security groups. Some of these are no longer required, how is the best way to determine whether the groups are still in use? Is there any way to query the groups to identify when they were last modified? thanks Frank Single Domain, Wi

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-25 Thread joe
Dir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Okay, now that is a script I would like to see :) Todd From: joe [mailto:[EMAIL PROTECTED] Sent: Fri 6/23/2006 5:46 PM To: ActiveDir@mail.activedir.org Sub

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Deji Akomolafe
-3.23Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: Myrick, Todd (NIH/CC/DCRI) [E]Sent: Fri 6/23/2006 3:07 PMTo: ActiveDir@mail.activedir.org; ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed&

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
Okay, now that is a script I would like to see :) Todd From: joe [mailto:[EMAIL PROTECTED] Sent: Fri 6/23/2006 5:46 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Hi D

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Deji Akomolafe
we know ITwww.akomolafe.com -5.75, -3.23Do you now realize that Today is the Tomorrow you were worried about Yesterday? -anon From: joeSent: Fri 6/23/2006 11:15 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" I read t

Re: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Al Lilianstrom
CTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DCRI) [E] Sent: Friday, June 23, 2006 12:59 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Not a big fan of "Security" people. :) Todd -

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Brian Desmond
Done that   Thanks, Brian Desmond [EMAIL PROTECTED]   c - 312.731.3132   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe Sent: Friday, June 23, 2006 11:13 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread joe
ttp://www.joeware.net/win/ad3e.htm      From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DCRI) [E]Sent: Friday, June 23, 2006 12:57 PMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" I gues

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
day, June 23, 2006 2:01 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Why? Do they make you change how you want to do admin work. ;o) LOL couldn't resist. -- O'Reilly Active Directory Third Edition - http:/

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread joe
C/DCRI) [E] Sent: Friday, June 23, 2006 12:59 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Not a big fan of "Security" people. :) Todd -Original Message- From: Al Lilianstrom [mailto:[EMAIL PROTECTED]

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
Not a big fan of "Security" people. :) Todd -Original Message- From: Al Lilianstrom [mailto:[EMAIL PROTECTED] Sent: Friday, June 23, 2006 12:35 PM To: ActiveDir@mail.activedir.org Subject: Re: [ActiveDir] AD Security permission continues to be "auto-removed" Myric

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
[mailto:[EMAIL PROTECTED] Sent: Friday, June 23, 2006 12:13 PM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed"   Yeah, like rename Domain Admins to "Unimportant People" and create a new group called Domain Admin

Re: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread J B
--- Original Message - From: joe To: ActiveDir@mail.activedir.org Sent: Friday, June 23, 2006 9:12 AM Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Yeah, like rename Domain Admins to "Unimportant People" and create

Re: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Al Lilianstrom
:* RE: [ActiveDir] AD Security permission continues to be "auto-removed" There is no debate on admins having multiple creds, one for admin work and one for normal work. Just do it. :) We took that one step farther. - Regular user account for 'normal' work - An admi

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread joe
to:[EMAIL PROTECTED] On Behalf Of Myrick, Todd (NIH/CC/DCRI) [E]Sent: Friday, June 23, 2006 11:01 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" Only Sith deal in absolutes… :P   When you have a CIO that likes to be i

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Marcus.Oh
Behalf Of Myrick, Todd (NIH/CC/DCRI) [E] Sent: Friday, June 23, 2006 11:01 AM To: ActiveDir@mail.activedir.org Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed"   Only Sith deal in absolutes… :P   When you have a CIO that likes to be in the Domain Ad

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
: [ActiveDir] AD Security permission continues to be "auto-removed"   There is no debate on admins having multiple creds, one for admin work and one for normal work. Just do it. :)   To put it nicely, if a company doesn't do this, they are just being silly[1].   I am trying to figure

Re: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread J B
Thanks for the info! - Original Message - From: [EMAIL PROTECTED] To: ActiveDir@mail.activedir.org Sent: Thursday, June 22, 2006 6:33 PM Subject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" I have a 2-part discussi

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread joe
D] On Behalf Of Myrick, Todd (NIH/CC/DCRI) [E]Sent: Friday, June 23, 2006 6:50 AMTo: ActiveDir@mail.activedir.orgSubject: RE: [ActiveDir] AD Security permission continues to be "auto-removed" One more thing to add to this from my experience.   I think we had situations arise wh

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-23 Thread Myrick, Todd \(NIH/CC/DCRI\) [E]
iveDir@mail.activedir.org Subject: [ActiveDir] AD Security permission continues to be "auto-removed" We have some users that have mobile devices that connect to Exchange.  The 3rd party application uses a dedicated account to send mail from the devices.  This account needs to have "Sen

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-22 Thread deji
olafe.comDo you now realize that Today is the Tomorrow you were worried about Yesterday? -anon   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of J BSent: Thursday, June 22, 2006 5:08 PMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] AD Security permission continues to be &qu

RE: [ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-22 Thread joe
, June 22, 2006 8:08 PMTo: ActiveDir@mail.activedir.orgSubject: [ActiveDir] AD Security permission continues to be "auto-removed" We have some users that have mobile devices that connect to Exchange.  The 3rd party application uses a dedicated account to send mail from the devices. 

[ActiveDir] AD Security permission continues to be "auto-removed"

2006-06-22 Thread J B
 We have some users that have mobile devices that connect to Exchange.  The 3rd party application uses a dedicated account to send mail from the devices.  This account needs to have "Send As..." permissions on each of the user accounts' security settings.  We have set it in all users (about

Re: [ActiveDir] AD security

2005-12-12 Thread Tomasz Onyszko
Myke wrote: all, How can I lock down my AD? (docs, papers, best practices...) Check this documents from microsoft: http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/DepKit/c283b699-6124-4c3a-87ef-865443d7ea4b.mspx http://www.microsoft.com/windowsserver2003/techinfo/overvie

[ActiveDir] AD security

2005-12-12 Thread Myke
all, How can I lock down my AD? (docs, papers, best practices...) tkx List info : http://www.activedir.org/List.aspx List FAQ: http://www.activedir.org/ListFAQ.aspx List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

[ActiveDir] AD Security

2002-12-30 Thread John Hicks/MIS/HQ/KEMET/US
I am in the process of testing rights for our remote LAN Admins and have a couple questions. I have created an OU for the MFG plant, created a local security group in the OU and created a user that is a member of that group in the OU. I added all but full control on the OU for the group I created.