﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / IT Audit / Active Directory  / Privileged access / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Wed, 08 Sep 2010 20:35:03 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Privileged access</title><link>http://forum.ultimatewindowssecurity.com/Topic335-8-1.aspx</link><description>It's a great question and the best way and really only way to do is to monitor for the exercize of the "Change Permission" permission (i.e. WRITE_DAC) on the root of the domain and OUs.  Explained in my free recorded webinar: &lt;U&gt;&lt;FONT color=#800080&gt;Top 10 Active Directory Changes to Monitor in the Security Log &lt;/FONT&gt;&lt;/U&gt;</description><pubDate>Tue, 16 Mar 2010 20:58:10 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Privileged access</title><link>http://forum.ultimatewindowssecurity.com/Topic335-8-1.aspx</link><description>What logged events could be used to indicate that a new Active Directory group has been added that has Domain Admin equivalent access?  In theory, a group could be added that's called "Inquiry" and is given Full Control to everything in the domain - is there a logged event or series of logged events that could identify this activity?  Certainly the naming convention is not useful in this example...</description><pubDate>Tue, 16 Mar 2010 11:18:07 GMT</pubDate><dc:creator>kkscfb</dc:creator></item></channel></rss>