Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add LAPS Created-Owner Check #170

Open
DonDom86 opened this issue Oct 17, 2022 · 0 comments
Open

Add LAPS Created-Owner Check #170

DonDom86 opened this issue Oct 17, 2022 · 0 comments
Labels
enhancement New feature or request

Comments

@DonDom86
Copy link

DonDom86 commented Oct 17, 2022

"Why this happens ?

This happen because by default the joiner of the computer has creator owner privilege by default and this privilege give him a set of permissions that were defined by defaultSecurityDescriptor on the computer class in schema , the defaultSecurityDescriptor define the default security permission over the objects , for more information about it check this please https://docs.microsoft.com/en-us/windows/win32/ad/default-security-descriptor

So how we can check the defaultSecurityDescriptor for the computer class ?"
Source:
azurecloudai.blog

Links:
learn.microsoft.com
learn.microsoft.com

@DonDom86 DonDom86 changed the title Add LDAP Created-Owner Check Add LAPS Created-Owner Check Oct 17, 2022
@PrzemyslawKlys PrzemyslawKlys added the enhancement New feature or request label Oct 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants