Reply to post: Re: Needs domain admin and can allow you to impersonate any user.

Insert 'Skeleton Key', unlock Microsoft Active Directory. Simples – hackers

P. Lee

Re: Needs domain admin and can allow you to impersonate any user.

>But if you have Domain Admin rights, you could just edit the schema and create some random account buried deep in the System container and give yourself every right you want.

And the audit logs would record you doing it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon