Solved

Delegate Control of an OU - Reporting?

Posted on 2013-06-19
7
317 Views
Last Modified: 2014-07-31
Is there any way or tool you know of that I can use to look through our AD structure to see what OU's have someone assigned as a Delegate Control?
0
Comment
Question by:iNetSystem
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
7 Comments
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 39260565
Yes you can use dsrevoke with the /report command.

dsrevoke /report /domain:{domain name} {domain\username}
0
 
LVL 35

Expert Comment

by:Joseph Daly
ID: 39260571
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 500 total points
ID: 39260590
dsrevoke might not work depending on the version, good powershell work around here

http://blogs.technet.com/b/askds/archive/2011/10/28/friday-mail-sack-they-pull-me-back-in-edition.aspx#dsrevoke

There is another Microsoft tool that I've been using recently.   The AD ACL Scanner

http://blogs.technet.com/b/pfesweplat/archive/2013/05/13/permissions-in-ad-lost-control.aspx

Thanks

Mike
0
Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 35

Expert Comment

by:Joseph Daly
ID: 39260614
That AD ACL scanner is pretty cool.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39260618
Agree, I think they should build that into AD but I think they are focusing all development time on the cloud :)

Thanks

Mike
0
 
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 39261465
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question