﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 552 - Logon attempt using explicit credentials  / Why Enterprise Admin Rights / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 09 Sep 2010 16:35:40 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Why Enterprise Admin Rights</title><link>http://forum.ultimatewindowssecurity.com/Topic194-35-1.aspx</link><description>look at who the domain user is.  most likely this is&lt;/P&gt;&lt;P&gt;- a legit admin following best practive of using 2 accounts (1 unprivileged, 1 privileged) and then using RunAs to open an admin program requiring his privileged account&lt;/P&gt;&lt;P&gt;- task scheduler starting up a logon session for a program to run under admin authority</description><pubDate>Tue, 01 Sep 2009 06:16:36 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Why Enterprise Admin Rights</title><link>http://forum.ultimatewindowssecurity.com/Topic194-35-1.aspx</link><description>Why would a domain user want to use explicit rights as the enterprise domain admin to logon?  Please see example with confidential details changed.&lt;/P&gt;&lt;P&gt;&lt;TABLE cellSpacing=0 cellPadding=2 width="100%" border=0&gt;&lt;TBODY&gt;&lt;TR bgColor=#cccccc&gt;&lt;TD&gt;Audit Success&lt;/TD&gt;&lt;TD&gt;1/28/2009&lt;/TD&gt;&lt;TD&gt;6:20:24 PM&lt;/TD&gt;&lt;TD&gt;552&lt;/TD&gt;&lt;TD&gt;Security&lt;/TD&gt;&lt;TD&gt;Logon/Logoff&lt;/TD&gt;&lt;TD&gt;\SYSTEM&lt;/TD&gt;&lt;TD&gt;COMPUTER&lt;/TD&gt;&lt;/TR&gt;&lt;TR bgColor=#cccccc&gt;&lt;TD colSpan=10&gt;Logon attempt using explicit credentials:&lt;BR&gt;Logged on user:&lt;BR&gt;User Name: domain user&lt;BR&gt;Domain: domain&lt;BR&gt;Logon ID: (******)&lt;BR&gt;Logon GUID: {****}&lt;BR&gt;User whose credentials were used:&lt;BR&gt;Target User Name: administrator&lt;BR&gt;Target Domain: DOMAIN&lt;BR&gt;Target Logon GUID: {*****}&lt;BR&gt;&lt;BR&gt;Target Server Name: (null)&lt;BR&gt;Target Server Info: (null)&lt;BR&gt;Caller Process ID: (null)&lt;BR&gt;Source Network Address: (null)&lt;BR&gt;Source Port: (null)&lt;BR&gt;Caller Process Name: (null)&lt;BR&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description><pubDate>Sun, 30 Aug 2009 22:13:57 GMT</pubDate><dc:creator>tnrdhdhllblly</dc:creator></item></channel></rss>