Re: Domain Admin removed



I would not think what he did was unusual necessarily but I don't know all
the details. There are free tools you can use such as dumpsec that can scan
computers for folder and share permissions but it can not be configured to
look for only folders that a specific user has only permissions for his user
account. Showacls is supposed to be able to look for permissions by user but
I have had flaky results for it. You can use subinacl to search for the
owner of folders and a WHOLE lot more on a computer once you figure out it's
syntax. That user may be the owner of such folders. The links below may
help. --- Steve

http://www.somarsoft.com/ -- dumpsec
http://technet2.microsoft.com/WindowsServer/en/Library/ed34eee3-7dbd-44c6-8fb8-8b8b2c6f06dc1033.mspx
--- showacls, subinacl, and others
http://www.microsoft.com/downloads/details.aspx?FamilyID=E8BA3E56-D8FE-4A91-93CF-ED6985E3927B&displaylang=en
--- subinacl download


"Dennis Burgess" <dmburgess@xxxxxxxxxxxx> wrote in message
news:uYT%23W$DVGHA.5592@xxxxxxxxxxxxxxxxxxxxxxx
I have a user that was a domain admin. I have found several folders sitting
out there on various servers that have been restricted to his user account
only, I had to take ownership to be able to delete the folders.

Is there a program that can scan my servers for these weird security
permissions looking for other things that he may have done?

Dennis




.



Relevant Pages

  • RE: Starting over on fileshares...
    ... To re-arrange the permission on share, you can use a tool called subinacl. ... security information about files, registry keys, and services, and transfer ... -Only a few out of the 120+ top level folders of the departmental share ... permissions, rather than giving domain users full control share ...
    (microsoft.public.windows.server.migration)
  • Re: Find NTFS Assignment?
    ... Two possibilities come to mind - dumpsec and fileacl. ... Fileacl is a command line utility with some pretty good abilities. ... You can also use it to display permissions in a number of ways and the /sub ... > Is there a clean method to find the folders where NTFS permissions have ...
    (microsoft.public.win2000.security)
  • Re: Finding folders where user was specifically given access
    ... share permissions and then review for the user names. ... http://www.sysinternals.com/Utilities/ShareEnum.html --- ShareEnum ... http://www.somarsoft.com/ --- Dumpsec ... folders where their name was specifically given access. ...
    (microsoft.public.windows.server.security)
  • Re: NTFS Security Question.
    ... A subordinate object DOES not inherit the PARENT perms (in ... will assume "Nebulous" permissions that refer to the LINK ... The trick is to PROPOGATE to all FILES (not Folders and Files - that would ... Since Windows 2000 deny NTFS permission does not work ...
    (microsoft.public.windowsxp.security_admin)
  • RE: ISA 2004 REPORT FAILURE
    ... Did as you suggested and turned auditing on for the system and folders ... that is setting the wrong permissions of the folders ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)