Active Directory-Reports dot com

Helpful Active Directory Reports Coverage for Security Audit & Regulatory Compliance

Brought to you by former Microsoft Program Manager for Active Directory Security
Home
Account Reports
Group Reports
Computer Reports
Exchange Reports
Permission Reports
Schema Reports
Trust Reports
GPO Reports
SCP Reports
OU Reports
Reporting Options
Reporting Tools

Active Directory Security Permissions (ACL) Reports

Active Directory security permissions play a vital role in protecting all content stored in the Active Directory, such as user accounts and groups. The need to have insight into their state and security is thus critical to security, and Security Permissions Reports provide organizations this vital insight.

Active Directory Security Permissions (ACL) Reports

ACTIVE DIRECTORY SECURITY PERMISSIONS (ACL) REPORTS


The following is a list of the Top-20 Active Directory Security Permissions Reports that are vital for security and are the starting point in determining who is delegated what access in Active Directory –


I. Security State Reports –

   The following security permissions reports are helpful in determining who really has what access
   in Active Directory. It is very important to note that just because a user/security group has some
   permissions granted in an Active Directory ACL it does NOT mean that they really have that
   access. They MAY OR MAY NOT have that access as it could very well be negated by the
   presence of others permissions in the ACL of the same object, or by numerous other factors.

  1. All Active Directory objects on which a user or group has any permissions
  2. All Active Directory objects on which a user or group has allow permissions
  3. All Active Directory objects on which a user or group has deny permissions
  4. All Active Directory objects on which a user or group has explicit permissions
  5. All Active Directory objects on which a user or group has inherited permissions
  6. All Active Directory objects on which a user or group has list child permissions
  7. All Active Directory objects on which a user or group has list object permissions
  8. All Active Directory objects on which a user or group has read property permissions
  9. All Active Directory objects on which a user or group has write property permissions
  10. All Active Directory objects on which a user or group has create child permissions
  11. All Active Directory objects on which a user or group has standard delete permissions
  12. All Active Directory objects on which a user or group has delete child permissions
  13. All Active Directory objects on which a user or group has delete tree permissions
  14. All Active Directory objects on which a user or group has read permissions permissions
  15. All Active Directory objects on which a user or group has modify permissions permissions
  16. All Active Directory objects on which a user or group has modify owner permissions
  17. All Active Directory objects on which a user or group has extended right permissions
  18. All Active Directory objects on which a user or group has validated write permissions


II. Delegated Administrative Access Reports –

   The following security permissions reports provide critical insight into who all can modify* the
   state of these AD ACLs, i.e. who all have sufficient privilege to modify the state of these ACLs –

* SECURITY NOTE – It is very important to understand that where all a user/group has specific permissions in Active Directory is NOT the same as who is delegated what administrative access in Active Directory. In order to correctly determine who is delegated what access, one needs to determine resultant access in Active Directory. Also, depending on the specific report, it may not be sufficient to determine resultant access on just one object.

  1. Who can change security permissions in Active Directory, and on which objects?
  2. Who can change object ownership in Active Directory, and of which objects?

   These delegated administrative access reports are absolutely mission-critical to security because
   they reveal exactly who has the ability to change the security state of these security groups.



How to Generate these Group Reports:

   Organizations generally have two predominant reporting options to fulfill their AD reporting needs,
   and most prefer to use reporting tools, especially to fulfill their delegated access reporting needs.

   The Microsoft-endorsed Gold Finger Active Directory reporting tool can also generate these reports.

Gold Finger - Microsoft-endorsed, Active Directory Resultant Access/Security Auditing/Reporting Tool
Copyright ActiveDir-Reports.Com 2010. All Rights Reserved
Active Directory Security Community Active Directory Reporting Tools Active Directory Security Reference Identity, Security & Access Blog