Solved

Tracing back where the Domain & Enterprise Administrator account is used ?

Posted on 2014-10-21
5
176 Views
Last Modified: 2014-10-30
Hi,

Is there any way to trace back where the Domain & Enterprise Administrator account is used in an AD domain ?

I need to get the list of where it is used before I rename the AD account and change the password in my company.

Any help would be greatly appreciated.

Thanks
0
Comment
  • 2
  • 2
5 Comments
 
LVL 19

Assisted Solution

by:Miguel Angel Perez Muñoz
Miguel Angel Perez Muñoz earned 167 total points
ID: 40394455
0
 
LVL 9

Accepted Solution

by:
dlb6597 earned 333 total points
ID: 40394477
you can also check the lastlogon attribute for the accounts to see the last time they were used.
you can dump out the services for each server to make sure the accounts aren't being used to run services.
One last resort (if you aren't in a critical environment) is to temporarily disable each account and see who calls.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
ID: 40394496
Somehow the active directory functionality level is still on Windows Server 2003. So does that feature still available ?

I don't have SCCM in the domain.
0
 
LVL 9

Assisted Solution

by:dlb6597
dlb6597 earned 333 total points
ID: 40394507
not sure which functionality you are specifically referring to, but both auditing and the lastlogon information are available in 2003.
0
 
LVL 7

Author Comment

by:Senior IT System Engineer
ID: 40394515
Ok so what's the powershell script to query that on each AD DC servers ?
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Utilizing an array to gracefully append to a list of EmailAddresses
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now