We help IT Professionals succeed at work.
Get Started

How to effectively Audit Active Directory groups?

720 Views
Last Modified: 2012-05-09
We have some 4-5000 groups in our Active Directory environment. We would like to setup a quartly review process to ensure that the people within these groups still indeed need that access (This is a IT Security driven project). Any advice on how to tackle this?
1) our first hurdle is to identiy owners for each group.
Any recommendations? Right now are thoughts are to have a standard string that we can search with a script in the description field, and parse out a username from it.

2) Once we have a standard and automatic process for identifing the owner, how do we go about getting the relevant information (Group name and users in the group) to the owners for review? Right now we are thinking a PowerShell script could perform this function for, grab the group name, the members, identify the owner, compile a spreadsheet, and then email the spreadsheet to the owner.

Thoughts? Advice?
Comment
Watch Question
PowerShell Developer
CERTIFIED EXPERT
Top Expert 2010
Commented:
This problem has been solved!
Unlock 1 Answer and 3 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE