Auditing GPO permissions and gPLink rights
Find who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
Guides tagged
Find who can edit, create and link GPOs in Active Directory: GPO ACLs, gPLink rights on OUs and sites, Group Policy Creator Owners and WMI filters.
Stop any domain user from creating computer accounts: set ms-DS-MachineAccountQuota to 0, find who relies on it, and delegate domain join to an OU.
Configure KCD and RBCD without new attack paths: protocol transition, SPN scoping, and auditing who can write msDS-AllowedToActOnBehalfOfOtherIdentity.
Find every non-DC account trusted for unconstrained delegation, map what depends on it, and migrate to constrained delegation or RBCD without outages.
Audit unconstrained, constrained, and resource-based constrained delegation in Active Directory, and lock down privileged accounts against abuse.
Lock down GPO delegation, purge Group Policy Preferences cpassword secrets from SYSVOL, and add change control to prevent silent GPO abuse.