Solved

Security Groups - How to find out the unused ones

Posted on 2007-04-02
7
406 Views
Last Modified: 2013-12-04
We have a windows 2003 active directory environment. we are doing a group audition because we are migrating the AD into a new domain. My question is this : if I want to check what Security groups are actually used and which ones are not. I know it's not a straightforward thing to do. But if someone can give me some directions that willl be great. The Security groups are used to permission for :
.NTFS/SHARE
.SQL
.GPOs
.Citrix applications
.Grant local administrative rights on servers/laptops and desktops.
.Miscellineous 3rd party apps

Now how do I find out which group is actually in use and which is not. We have around 3000 groups in domain. lol
0
Comment
Question by:gtrivedi
7 Comments
 
LVL 70

Expert Comment

by:KCTS
ID: 18835114
Double click on the security group in Active Directory Users and Computers. Go the the Members Tab.
If there are no members the group is not in use.
0
 
LVL 3

Expert Comment

by:hbbw063
ID: 18835187
What do you exactely mean by "not in use" ?
0
 

Author Comment

by:gtrivedi
ID: 18835402
[quote]
What do you exactely mean by "not in use" ?
[/quote]

some groups are there AD but they may not be used anywhere. Is there any property in AD which tells me when that group was added for permissioning on Share/SQL/Local Admin etc ?
That way I will not have to migrate such groups and the new domain will be a lot tidier.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 1

Expert Comment

by:proservis
ID: 18835983
Go to
start->administrative tools-> group policy management

There is Group Policy Modeling and Group Policy Results
setup new model or result and look at applied/denied GPOs
0
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 250 total points
ID: 18837007
Unfortunately this is a tough nut to crack, because you would need to query all of your member servers, application servers, workstations, etc., to determine if a particular security group is listed in any ACLs.

The quick-and-dirty way that most of us use?  Convert it to a distribution group, then wait a few days and see if anyone complains.

A reporting tool like SomarSoft's DumpSec might also help you determine which groups are not in use: http://www.somarsoft.com/

Hope this helps.

Laura E. Hunter - Microsoft MVP: Windows Server - Networking
0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 19707859

No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I will leave the following recommendation for this question in the Cleanup Zone:
ACCEPT: LauraEHunterMVP {18837007}

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

Chris-Dent
Experts Exchange Cleanup Volunteer
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question