[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

aduc reports misc (domain policy last amended)

Posted on 2011-09-08
7
Medium Priority
?
397 Views
Last Modified: 2012-05-12
I am trying to use ad users and comptuers to get a full list of servers in a domain, a full list of workstations in a domain, and also identify when the default domain password policy was last changed - any idea on these 3? By last changed I mean it recently became policy for domain passwords to have the complex (3/4 character sets represented). But we have loads of accounts that were setup to not expire, and I think most were setup before the domain password policy was changed

0
Comment
Question by:pma111
  • 4
  • 3
7 Comments
 
LVL 57

Accepted Solution

by:
Mike Kline earned 2000 total points
ID: 36502955
If you do a find in ADUC you can search for operating system there, you could also do it via an LDAP query.

There is a nice free GUI tool called adinfo that makes that easier   http://www.cjwdev.co.uk/Software/ADReportingTool/Info.html

Screenshot of the tool attached

In GPMC you can look at the modified date for the GPO.  That however just means the GPO was modified.  If there are other settings in the GPO they could have been changed.  To get more granular on what setting exactly was modified you would need to enable auditing and use a tool like AGPM or other third party tool.

More on group policy auditing here (question I helped with)   http://www.experts-exchange.com/Software/Server_Software/File_Servers/Active_Directory/Q_24534479.html


Thanks

Mike

adinfo-computer-version.jpg
GPMC-modified.jpg
0
 
LVL 3

Author Comment

by:pma111
ID: 36503016
so in advanced tab if I just chose field and "windows server" in starts as that will list every server?

Cheers
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 36503106
The field for that would be operating system.

Thanks

Mike
0
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

 
LVL 3

Author Comment

by:pma111
ID: 36503146
I assume you cant see scheduled tasks per device in aduc?
Is there any remote tool to see scheduled tasks setup on a remote server?
Or do you know any tool that can? I couldnt see them in computer management console either.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 36503216
No not in ADUC, not sure about a remote tool, you can connect to the remote box   http://social.technet.microsoft.com/Forums/en/w7itproui/thread/b1e4edd1-c155-4e17-9056-c13e693c4a5a

you may want to open a separate question about that to get new eyes on it.

Thanks

Mike
0
 
LVL 3

Author Comment

by:pma111
ID: 36503277
0
 
LVL 3

Author Comment

by:pma111
ID: 36503312
That link seems for windows 7 - we are still on XP
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, Microsoft released a best-practice guide for securing Active Directory. It's a whopping 300+ pages long. Those of us tasked with securing our company’s databases and systems would, ideally, have time to devote to learning the ins and outs…
In the absence of a fully-fledged GPO Management product like AGPM, the script in this article will provide you with a simple way to watch the domain (or a select OU) for GPOs changes and automatically take backups when policies are added, removed o…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question