Forum Discussion

mnagel's avatar
mnagel
Icon for Professor rankProfessor
5 years ago

windows domain admin account info

I intend to extend this to include more track-worthy account attributes such as Expired, Locked, etc, but to start I wanted to enable expiration tracking for domain admin accounts as we can get caught off-guard on those when they happen unexpectedly.  This involved creating a new propertysource that tags domain controllers with one or more categories tied to their FSMO roles, then for the PDCEmulator role (arbitrarily chosen, mainly wanted to pick just one), scans the Domain Admins group list and reports days until expiration.  No graphs or thresholds yet, will be extending soon.  May also genericize a bit and use an input property for the list of groups to include (with a default of Domain Admins).

DataSource: YDYFXH

PropertySource: 2JNTAL