Accounts in Domain Admin Group

Greetings,
I'm doing an account inventory in our network and a bunch of accounts belong to the Domain Admin Group in Active Directory. There is no good documentation as to why these accounts were made part of that group but I'm sure most of them are legit. Is there an easy way to find out if any of these accounts are been used for services other than disabling and hoping for the best? Any good ideas on how to accomplish this?

Thanks
menendezaAsked:
Who is Participating?
 
Nick RhodeIT DirectorCommented:
I had that issue a while ago.  I used a script that was created by another user.  There are a few other options down in the forum part where you can target individual servers otherwise the script basically scans the entire domain.

You can check it out here

To see what services on which server are currently running via user account make sure you include the full line:  meaning add the >> servicechecker.log

Read through it and take a peak to if this is what your looking for.  I have run the script and it works fine and the environment I used it on is Windows 2008 R2
0
 
menendezaAuthor Commented:
Perfect! Exactly what I need.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.