Domain Documentation

  

 

 

 

 

 

 

 

 

 

09/10/2007


Index

Domain: adscribe.com _ 3

Computers _ 3

Organizational units _ 3

Groups _ 3

List of builtin groups _ 3

List of user groups _ 3

Users _ 3

Contacts _ 3

Shared folders _ 3

Printers _ 3

MSMQ queue aliases _ 3

Sites _ 3

Inter-site transports _ 3

Group polices _ 3

About _ 3


 

Domain: adscribe.com

Domain: adscribe.com

Object

Name:adscribe.com 
Path:DC=adscribe,DC=com 
Created:10/10/2006 
Modified:24/09/2007 
Original USN:4098 
Current USN:53390 
SID:S-1-5-21-2034109091-298619056-3282043246 
GUID:{81E4BD01-B467-41ED-9CFF-284FA94ED6A2} 
Domain: adscribe.com

General

Domain name (pre-Windows 2000):adscribe 
Description:domain description 
Domain functional level:Windows 2000 
Forest functional level:Windows 2000 
Managed by:AAA 
Domain controller:ADSCRIBE-SERVER 

Organizational units

NameDescription
Accounting  
Domain Controllers Default container for domain controllers 
Finance  
subdomain controllers  
TopFinance Description 

Computers

NameRoleDisabledDescription
ADSCRIBE-SERVER Domain Controller  domain controller description 
EXTPC1 Workstation or Server   
PC1 Workstation or Server  pc1 description 
PC2 Workstation or Server   
PC3 Workstation or Server   
PC4 Workstation or Server   
PC6 Workstation or Server   
VirtualDomainServer Workstation or Server  virtual server 

Groups

NameBuiltinScopeTypeE-mail
Account Operators  Domain Local Group Security  
Administrators  Domain Local Group Security  
Backup Operators  Domain Local Group Security  
Cert Publishers  Domain Local Group Security  
ddddd  Global Group Security  
DHCP Administrators  Domain Local Group Security  
DHCP Users  Domain Local Group Security  
DnsAdmins  Domain Local Group Security  
DnsUpdateProxy  Global Group Security  
Domain Admins  Global Group Security  
Domain Computers  Global Group Security  
Domain Controllers  Global Group Security  
Domain Guests  Global Group Security  
Domain Users  Global Group Security  
Enterprise Admins  Global Group Security  
ExternalGroup  Global Group Security  
FinanceGroup1  Universal Group Distribution  
Group  Global Group Security  
Group Policy Creator Owners  Global Group Security  
Guests  Domain Local Group Security  
HelpServicesGroup  Domain Local Group Security  
IIS_WPG  Domain Local Group Security  
Incoming Forest Trust Builders  Domain Local Group Security  
Network Configuration Operators  Domain Local Group Security  
Performance Log Users  Domain Local Group Security  
Performance Monitor Users  Domain Local Group Security  
Pre-Windows 2000 Compatible Access  Domain Local Group Security  
Print Operators  Domain Local Group Security  
Programmers  Global Group Security  
RAS and IAS Servers  Domain Local Group Security  
Remote Desktop Users  Domain Local Group Security  
Replicator  Domain Local Group Security  
Schema Admins  Global Group Security  
Server Operators  Domain Local Group Security  
TelnetClients  Domain Local Group Security  
Terminal Server Computers  Domain Local Group Security  
Terminal Server License Servers  Domain Local Group Security  
Users  Domain Local Group Security  
Windows Authorization Access Group  Domain Local Group Security  
WINS Users  Domain Local Group Security  

Foreign security principals

NameTypeDescription
Contact Mr. Mc Contact contact description 
External Mr. External user  
ExternalGroup group  
EXTPC1 computer  
Person Ms. Pirson user  
Programmers group  
queue_alias queuealias  
S-1-5-11 foreign-security-principal  
S-1-5-18 foreign-security-principal  
S-1-5-19 foreign-security-principal  
S-1-5-20 foreign-security-principal  
S-1-5-4 foreign-security-principal  
S-1-5-9 foreign-security-principal  
Share1 folder  

Users

NameDisabledLockedDescriptionE-mail
AAA   Decription 1@email.com 
Administrator   Built-in account for administering the computer/domain administrator@adscribe.com 
ASPNET   Account used for running the ASP.NET worker process (aspnet_wp.exe)  
BBB     
External Mr. External     
Guest   Built-in account for guest access to the computer/domain  
IISUser     
InetOrgPerson Init. Last name     
IUSR_ADSCRIBE-SERVER   Built-in account for anonymous access to Internet Information Services  
IWAM_ADSCRIBE-SERVER   Built-in account for Internet Information Services to start out of process applications  
krbtgt   Key Distribution Center Service Account  
New Object   new object description  
oneway.com$     
Person Ms. Pirson     
supplier01-int$     
SUPPORT_388945a0   This is a vendor's account for the Help and Support Service  
VUSR_ADSCRIBE-SERVER   Cuenta para los componentes de servidor de Visual Studio Analyzer  
WMUS_ADSCRIBE-SERVER   Default account for anonymous access to Windows Media Services  

Contacts

NameDescriptionE-mail
Contact Mr. Mc Contact description email 
FinanceContact FirstName Init. Last name   

Shared folders

NameDescription
folder1 Description 
Share1  

Printers

NameDescription
Printer display name description 

MSMQ queue aliases

NameDescription
queue_alias  
queue_alias Description 

Sites

NameDescription
SomeSite Site description 

Inter-site transports

NameDescription
IP ip inter site transport 
SMTP smtpintersite transport 

Trusts

DomainTypeDirectionTransitive
oneway.com Realm Incomming  
outgoing Realm Outgoing  
supplier01-int Realm Bidirectional  

Group policies

DisplayName
Default Domain Controllers Policy 
Default Domain Policy 
New Group Policy Object 
Site Group Policy 
Site Group Policy 2 
Domain: adscribe.com

Security

Owner: 
Group: 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
Everyone  Read the properties   
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Replicating Directory Changes 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Replication Synchronization 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Manage Replication Topology 
BUILTIN\Administrators  Extended access rights  Replicating Directory Changes 
BUILTIN\Administrators  Extended access rights  Replication Synchronization 
BUILTIN\Administrators  Extended access rights  Manage Replication Topology 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Domain Password & Lockout Policies 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
Read the properties 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Other Domain Parameters (for use by SAM) 
NT AUTHORITY\Authenticated Users  Read the properties  Other Domain Parameters (for use by SAM) 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
ADSCRIBE\Domain Controllers  Extended access rights  Replicating Directory Changes All 
BUILTIN\Administrators  Extended access rights  Replicating Directory Changes All 
BUILTIN\Incoming Forest Trust Builders  Extended access rights  Create Inbound Forest Trust 
NT AUTHORITY\Authenticated Users  Extended access rights  Update Password Not Required Bit 
NT AUTHORITY\Authenticated Users  Extended access rights  Unexpire Password 
NT AUTHORITY\Authenticated Users  Extended access rights  Enable Per User Reversibly Encrypted Password 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
BUILTIN\Administrators Extended access rights    
ADSCRIBE\Domain Users Extended access rights    
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Domain: adscribe.com

Group policy

Block policy inheritance: 

Group policy settings

NameDisabledOverride
Default Domain Policy   

Computers


 

Computer: ADSCRIBE-SERVER

Computer: ADSCRIBE-SERVER

Object

Name:ADSCRIBE-SERVER 
Path:CN=ADSCRIBE-SERVER,OU=Domain Controllers,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:12290 
Current USN:86619 
SID:S-1-5-21-2034109091-298619056-3282043246-1011 
GUID:{65462E0F-1D5D-42C8-AE5F-960B9BCC0EFD} 
Computer: ADSCRIBE-SERVER

General

Disabled: 
Computer name (pre-Windows 2000):ADSCRIBE-SERVER$ 
DNS name:adscribe-server.adscribe.com 
Role:Domain Controller 
Description:domain controller description 
Location:Location 
Trast computer for delegation: 
Managed by:AAA 
Computer: ADSCRIBE-SERVER

Operating System

Name:Windows Server 2003 
Version:5.2 (3790) 
Service pack: 
Computer: ADSCRIBE-SERVER

Member of

Primary Group:Domain Controllers 
Member Of:Domain Computers, Administrators, DHCP Administrators 
Computer: ADSCRIBE-SERVER

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties    
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: EXTPC1

Computer: EXTPC1

Object

Name:EXTPC1 
Path:CN=EXTPC1,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13984 
Current USN:13988 
SID:S-1-5-21-2034109091-298619056-3282043246-1128 
GUID:{A5258F31-0293-4B61-8BE5-FAA8F2834DC9} 
Computer: EXTPC1

General

Disabled: 
Computer name (pre-Windows 2000):EXTPC1$ 
DNS name: 
Role:Workstation or Server 
Description: 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: EXTPC1

Operating System

Name: 
Version: 
Service pack: 
Computer: EXTPC1

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: EXTPC1

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: PC1

Computer: PC1

Object

Name:PC1 
Path:CN=PC1,CN=Computers,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:16/09/2007 
Original USN:13899 
Current USN:36943 
SID:S-1-5-21-2034109091-298619056-3282043246-1115 
GUID:{F5E7ADB6-4747-4532-8841-8EFB0296ED02} 
Computer: PC1

General

Disabled: 
Computer name (pre-Windows 2000):PC1$ 
DNS name: 
Role:Workstation or Server 
Description:pc1 description 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: PC1

Operating System

Name: 
Version: 
Service pack: 
Computer: PC1

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: PC1

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: PC2

Computer: PC2

Object

Name:PC2 
Path:CN=PC2,CN=Computers,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13905 
Current USN:13909 
SID:S-1-5-21-2034109091-298619056-3282043246-1116 
GUID:{4C23671F-FAE1-4FCD-A732-92910029D26A} 
Computer: PC2

General

Disabled: 
Computer name (pre-Windows 2000):PC2$ 
DNS name: 
Role:Workstation or Server 
Description: 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: PC2

Operating System

Name: 
Version: 
Service pack: 
Computer: PC2

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: PC2

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: PC3

Computer: PC3

Object

Name:PC3 
Path:CN=PC3,CN=Computers,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13911 
Current USN:13915 
SID:S-1-5-21-2034109091-298619056-3282043246-1117 
GUID:{D2E851B8-2224-4B6C-945A-1C3BD1725107} 
Computer: PC3

General

Disabled: 
Computer name (pre-Windows 2000):PC3PREWIN2000$ 
DNS name: 
Role:Workstation or Server 
Description: 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: PC3

Operating System

Name: 
Version: 
Service pack: 
Computer: PC3

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: PC3

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: PC4

Computer: PC4

Object

Name:PC4 
Path:CN=PC4,OU=Accounting,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:14010 
Current USN:86206 
SID:S-1-5-21-2034109091-298619056-3282043246-1131 
GUID:{D6D82021-F8A4-4386-9577-F22A817F2806} 
Computer: PC4

General

Disabled: 
Computer name (pre-Windows 2000):PC4$ 
DNS name: 
Role:Workstation or Server 
Description: 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: PC4

Operating System

Name: 
Version: 
Service pack: 
Computer: PC4

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: PC4

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: PC6

Computer: PC6

Object

Name:PC6 
Path:CN=PC6,OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:12/10/2005 
Modified:12/10/2005 
Original USN:28724 
Current USN:28728 
SID:S-1-5-21-2034109091-298619056-3282043246-1135 
GUID:{B41AAD7D-E64A-4F1C-943D-258AF9EEB95C} 
Computer: PC6

General

Disabled: 
Computer name (pre-Windows 2000):PC6$ 
DNS name: 
Role:Workstation or Server 
Description: 
Location: 
Trast computer for delegation: 
Managed by: 
Computer: PC6

Operating System

Name: 
Version: 
Service pack: 
Computer: PC6

Member of

Primary Group:Domain Computers 
Member Of: 
Computer: PC6

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

 

Computer: VirtualDomainServer

Computer: VirtualDomainServer

Object

Name:VirtualDomainServer 
Path:CN=VirtualDomainServer,OU=subdomain controllers,OU=Domain Controllers,DC=adscribe,DC=com 
Created:23/09/2007 
Modified:07/10/2007 
Original USN:53289 
Current USN:87020 
SID:S-1-5-21-2034109091-298619056-3282043246-1143 
GUID:{96BB9188-534E-44C1-A8EB-720C3A424A7B} 
Computer: VirtualDomainServer

General

Disabled: 
Computer name (pre-Windows 2000):VirtualDomain 
DNS name:virtual-server.adscribe2.com 
Role:Workstation or Server 
Description:virtual server 
Location:alabama 
Trast computer for delegation: 
Managed by: 
Computer: VirtualDomainServer

Operating System

Name: 
Version: 
Service pack: 
Computer: VirtualDomainServer

Member of

Primary Group:Domain Users 
Member Of:Schema Admins 
Computer: VirtualDomainServer

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties    
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of computers

Organizational units


 

Organizational unit: Accounting

Organizational unit: Accounting

Object

Name:Accounting 
Path:OU=Accounting,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:01/10/2007 
Original USN:14008 
Current USN:76866 
GUID:{1AB97C26-DD41-45AB-A1B2-1EE883A22D77} 
Organizational unit: Accounting

General

Description: 
Street: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
Managed by: 

Members

NameTypeDescription
Finance unit  
PC4 computer  
Organizational unit: Accounting

COM+

Partition set:Current provider does not support returning multiple recordsets from a single execution. 
Organizational unit: Accounting

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
BUILTIN\Account Operators  Delete child object
Create child object 
 User 
BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Organizational unit: Accounting

Group policy

Block policy inheritance: 

Group policy settings

NameDisabledOverride
Default Domain Controllers Policy   
Site Group Policy 2   

See Also

List of organizational units

 

Organizational unit: Domain Controllers

Organizational unit: Domain Controllers

Object

Name:Domain Controllers 
Path:OU=Domain Controllers,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:4411 
Current USN:4411 
GUID:{96828BC9-46A8-44F0-9CCB-4163CB9A1591} 
Organizational unit: Domain Controllers

General

Description:Default container for domain controllers 
Street: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
Managed by: 

Members

NameTypeDescription
ADSCRIBE-SERVER computer domain controller description 
subdomain controllers unit  
Organizational unit: Domain Controllers

COM+

Partition set: 
Organizational unit: Domain Controllers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Write the properties    
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Organizational unit: Domain Controllers

Group policy

Block policy inheritance: 

Group policy settings

NameDisabledOverride
Default Domain Controllers Policy   

See Also

List of organizational units

 

Organizational unit: Finance

Organizational unit: Finance

Object

Name:Finance 
Path:OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:12/10/2005 
Modified:12/10/2005 
Original USN:28715 
Current USN:28715 
GUID:{6E183DB3-0AAC-4BC4-8B02-6EF90B960C1D} 
Organizational unit: Finance

General

Description: 
Street: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
Managed by: 

Members

NameTypeDescription
AAA user Decription 
FinanceContact FirstName Init. Last name contact  
FinanceGroup1 group  
folder1 folder Description 
InetOrgPerson Init. Last name user  
Printer display name printer description 
queue_alias queuealias Description 
TopFinance unit Description 
Organizational unit: Finance

COM+

Partition set: 
Organizational unit: Finance

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
BUILTIN\Account Operators  Delete child object
Create child object 
 User 
BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Organizational unit: Finance

Group policy

Block policy inheritance: 

See Also

List of organizational units

 

Organizational unit: subdomain controllers

Organizational unit: subdomain controllers

Object

Name:subdomain controllers 
Path:OU=subdomain controllers,OU=Domain Controllers,DC=adscribe,DC=com 
Created:23/09/2007 
Modified:23/09/2007 
Original USN:53330 
Current USN:53330 
GUID:{4EB59D4E-5E45-4102-9553-4E9DF21AB256} 
Organizational unit: subdomain controllers

General

Description: 
Street: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
Managed by: 

Members

NameTypeDescription
VirtualDomainServer computer virtual server 
Organizational unit: subdomain controllers

COM+

Partition set: 
Organizational unit: subdomain controllers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
BUILTIN\Account Operators  Delete child object
Create child object 
 User 
BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties    
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Organizational unit: subdomain controllers

Group policy

Block policy inheritance: 

See Also

List of organizational units

 

Organizational unit: TopFinance

Organizational unit: TopFinance

Object

Name:TopFinance 
Path:OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:12/10/2005 
Modified:16/09/2007 
Original USN:28722 
Current USN:36967 
GUID:{2F7883A7-68FF-47AF-98E2-A6583D1C28FF} 
Organizational unit: TopFinance

General

Description:Description 
Street:Street 
City:City 
State/Province:State/Province 
Zip/PostalCode:zip 
Country/Region:Albania 
Managed by:BBB 

Members

NameTypeDescription
New Object user new object description 
PC6 computer  
Organizational unit: TopFinance

COM+

Partition set: 
Organizational unit: TopFinance

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
BUILTIN\Account Operators  Delete child object
Create child object 
 User 
BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 
Organizational unit: TopFinance

Group policy

Block policy inheritance: 

Group policy settings

NameDisabledOverride
New Group Policy Object   

See Also

List of organizational units

Groups


 

Group: Account Operators

Group: Account Operators

Object

Name:Account Operators 
Path:CN=Account Operators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:12359 
Current USN:86811 
SID:S-1-5-32-548 
GUID:{162BA1B7-B4D5-4522-B644-99FBDC64F1F7} 
Group: Account Operators

General

Name (pre-Windows 2000):Account Operators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Account Operators

Member of

Member Of: 

Members

NameTypeDescription
AAA user Decription 
Schema Admins group Designated administrators of the schema 
Group: Account Operators

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Administrators

Group: Administrators

Object

Name:Administrators 
Path:CN=Administrators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:8213 
Current USN:86240 
SID:S-1-5-32-544 
GUID:{27D1018C-CBDD-4912-957E-11099ED06948} 
Group: Administrators

General

Name (pre-Windows 2000):Administrators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Administrators

Member of

Member Of: 

Members

NameTypeDescription
IISUser user  
queue_alias queuealias Description 
FinanceGroup1 group  
FinanceContact FirstName Init. Last name contact  
Contact Mr. Mc Contact contact description 
Domain Admins group Designated administrators of the domain 
Enterprise Admins group Designated administrators of the enterprise 
ADSCRIBE-SERVER computer domain controller description 
IUSR_ADSCRIBE-SERVER user Built-in account for anonymous access to Internet Information Services 
Administrator user Built-in account for administering the computer/domain 
Group: Administrators

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Backup Operators

Group: Backup Operators

Object

Name:Backup Operators 
Path:CN=Backup Operators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:8222 
Current USN:86813 
SID:S-1-5-32-551 
GUID:{5A92BAB2-2DFA-483D-B860-C0C9FF78142E} 
Group: Backup Operators

General

Name (pre-Windows 2000):Backup Operators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Backup Operators

Member of

Member Of: 

Members

NameTypeDescription
FinanceContact FirstName Init. Last name contact  
BBB user  
AAA user Decription 
ExternalGroup group  
Schema Admins group Designated administrators of the schema 
Group: Backup Operators

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Cert Publishers

Group: Cert Publishers

Object

Name:Cert Publishers 
Path:CN=Cert Publishers,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:02/10/2007 
Original USN:12338 
Current USN:79415 
SID:S-1-5-21-2034109091-298619056-3282043246-517 
GUID:{03374580-3F7C-44EA-845D-BE163217E337} 
Group: Cert Publishers

General

Name (pre-Windows 2000):Cert Publishers 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Cert Publishers

Member of

Member Of: 

Members

NameTypeDescription
FinanceGroup1 group  
Group: Cert Publishers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: ddddd

Group: ddddd

Object

Name:ddddd 
Path:CN=ddddd,CN=Computers,DC=adscribe,DC=com 
Created:23/09/2007 
Modified:23/09/2007 
Original USN:53327 
Current USN:53327 
SID:S-1-5-21-2034109091-298619056-3282043246-1144 
GUID:{99881626-DF9D-4E38-9D37-FC1CB367744B} 
Group: ddddd

General

Name (pre-Windows 2000):ddddd 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: ddddd

Member of

Member Of: 
Group: ddddd

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: DHCP Administrators

Group: DHCP Administrators

Object

Name:DHCP Administrators 
Path:CN=DHCP Administrators,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:8210 
Current USN:86242 
SID:S-1-5-21-2034109091-298619056-3282043246-1009 
GUID:{61577D09-54D6-4DB1-A1A6-1464E31B7315} 
Group: DHCP Administrators

General

Name (pre-Windows 2000):DHCP Administrators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: DHCP Administrators

Member of

Member Of: 

Members

NameTypeDescription
ADSCRIBE-SERVER computer domain controller description 
Group: DHCP Administrators

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: DHCP Users

Group: DHCP Users

Object

Name:DHCP Users 
Path:CN=DHCP Users,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8209 
Current USN:8209 
SID:S-1-5-21-2034109091-298619056-3282043246-1008 
GUID:{9B55639E-720F-4680-AB70-0E6618F1BA80} 
Group: DHCP Users

General

Name (pre-Windows 2000):DHCP Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: DHCP Users

Member of

Member Of: 
Group: DHCP Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: DnsAdmins

Group: DnsAdmins

Object

Name:DnsAdmins 
Path:CN=DnsAdmins,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:16/09/2007 
Original USN:12399 
Current USN:36956 
SID:S-1-5-21-2034109091-298619056-3282043246-1112 
GUID:{4EB722E8-F1AA-4BBA-98C5-FA707C3B9966} 
Group: DnsAdmins

General

Name (pre-Windows 2000):DnsAdmins 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by:Administrator 
Notes: 
Group: DnsAdmins

Member of

Member Of: 

Members

NameTypeDescription
BBB user  
Group: DnsAdmins

Security

Owner:NT AUTHORITY\SYSTEM 
Group:NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: DnsUpdateProxy

Group: DnsUpdateProxy

Object

Name:DnsUpdateProxy 
Path:CN=DnsUpdateProxy,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12404 
Current USN:12404 
SID:S-1-5-21-2034109091-298619056-3282043246-1113 
GUID:{4F2FA6E6-65EF-4738-BEAC-EA6B11B2238F} 
Group: DnsUpdateProxy

General

Name (pre-Windows 2000):DnsUpdateProxy 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: DnsUpdateProxy

Member of

Member Of: 
Group: DnsUpdateProxy

Security

Owner:NT AUTHORITY\SYSTEM 
Group:NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Domain Admins

Group: Domain Admins

Object

Name:Domain Admins 
Path:CN=Domain Admins,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:12341 
Current USN:87387 
SID:S-1-5-21-2034109091-298619056-3282043246-512 
GUID:{4BC305CA-1BA4-4BD4-B9EB-3A36C57D9972} 
Group: Domain Admins

General

Name (pre-Windows 2000):Domain Admins 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Domain Admins

Member of

Member Of:Administrators 
Group: Domain Admins

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Domain Computers

Group: Domain Computers

Object

Name:Domain Computers 
Path:CN=Domain Computers,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:16/09/2007 
Original USN:12326 
Current USN:36945 
SID:S-1-5-21-2034109091-298619056-3282043246-515 
GUID:{FBA3EE65-F645-49E8-8EEB-E8EA2D4E5723} 
Group: Domain Computers

General

Name (pre-Windows 2000):Domain Computers 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Domain Computers

Member of

Member Of: 

Members

NameTypeDescription
ADSCRIBE-SERVER computer domain controller description 
Group: Domain Computers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Domain Controllers

Group: Domain Controllers

Object

Name:Domain Controllers 
Path:CN=Domain Controllers,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12329 
Current USN:13975 
SID:S-1-5-21-2034109091-298619056-3282043246-516 
GUID:{3DD979D6-AC27-4E58-A18F-61B0C6C9A5F2} 
Group: Domain Controllers

General

Name (pre-Windows 2000):Domain Controllers 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Domain Controllers

Member of

Member Of: 
Group: Domain Controllers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Domain Guests

Group: Domain Guests

Object

Name:Domain Guests 
Path:CN=Domain Guests,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12347 
Current USN:12349 
SID:S-1-5-21-2034109091-298619056-3282043246-514 
GUID:{1A93A3F1-7FD2-4986-AFBF-3FD4E0CDB9C1} 
Group: Domain Guests

General

Name (pre-Windows 2000):Domain Guests 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Domain Guests

Member of

Member Of:Guests 
Group: Domain Guests

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Domain Users

Group: Domain Users

Object

Name:Domain Users 
Path:CN=Domain Users,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:12344 
Current USN:87388 
SID:S-1-5-21-2034109091-298619056-3282043246-513 
GUID:{0347C861-8993-4C0A-AB5B-972E8053B804} 
Group: Domain Users

General

Name (pre-Windows 2000):Domain Users 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Domain Users

Member of

Member Of:Users 

Members

NameTypeDescription
Administrator user Built-in account for administering the computer/domain 
Group: Domain Users

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Enterprise Admins

Group: Enterprise Admins

Object

Name:Enterprise Admins 
Path:CN=Enterprise Admins,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12335 
Current USN:13965 
SID:S-1-5-21-2034109091-298619056-3282043246-519 
GUID:{E1D75174-6F1E-4A28-A25C-1BCD09A007C1} 
Group: Enterprise Admins

General

Name (pre-Windows 2000):Enterprise Admins 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Enterprise Admins

Member of

Member Of:Administrators 

Members

NameTypeDescription
Administrator user Built-in account for administering the computer/domain 
Group: Enterprise Admins

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: ExternalGroup

Group: ExternalGroup

Object

Name:ExternalGroup 
Path:CN=ExternalGroup,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:13961 
Current USN:87390 
SID:S-1-5-21-2034109091-298619056-3282043246-1127 
GUID:{32FC0F4E-D133-49E8-AC22-009FF93C6709} 
Group: ExternalGroup

General

Name (pre-Windows 2000):ExternalGroup 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by:Administrator 
Notes: 
Group: ExternalGroup

Member of

Member Of:Backup Operators 
Group: ExternalGroup

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: FinanceGroup1

Group: FinanceGroup1

Object

Name:FinanceGroup1 
Path:CN=FinanceGroup1,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:07/10/2007 
Original USN:36985 
Current USN:86922 
SID:S-1-5-21-2034109091-298619056-3282043246-1140 
GUID:{2357016C-3A54-440A-A9A7-D69C8FDE8CCC} 
Group: FinanceGroup1

General

Name (pre-Windows 2000):FinanceGroup1 
Builtin: 
E-mail: 
Scope:Universal Group 
Type:Distribution 
Managed by:BBB 
Notes:1200
hour=60 min=
day=24 hours=60*24

days=x/60*24
x=x-60*24*day
hours=x/60
x=x-60*hours 
Group: FinanceGroup1

Member of

Member Of:Cert Publishers, Administrators 

Members

NameTypeDescription
queue_alias queuealias Description 
BBB user  
queue_alias queuealias  
Group: FinanceGroup1

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Group

Group: Group

Object

Name:Group 
Path:CN=Group,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:23/09/2007 
Original USN:14002 
Current USN:53349 
SID:S-1-5-21-2034109091-298619056-3282043246-1130 
GUID:{34862615-F4BD-4624-850B-07DFF6B12291} 
Group: Group

General

Name (pre-Windows 2000):Group 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Group

Member of

Member Of: 

Members

NameTypeDescription
BBB user  
Group: Group

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Group Policy Creator Owners

Group: Group Policy Creator Owners

Object

Name:Group Policy Creator Owners 
Path:CN=Group Policy Creator Owners,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12350 
Current USN:12380 
SID:S-1-5-21-2034109091-298619056-3282043246-520 
GUID:{1BA8D93E-F548-4B9B-A7EF-78ADA28AF671} 
Group: Group Policy Creator Owners

General

Name (pre-Windows 2000):Group Policy Creator Owners 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Group Policy Creator Owners

Member of

Member Of: 

Members

NameTypeDescription
Administrator user Built-in account for administering the computer/domain 
Group: Group Policy Creator Owners

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Guests

Group: Guests

Object

Name:Guests 
Path:CN=Guests,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:20/09/2007 
Original USN:8219 
Current USN:45085 
SID:S-1-5-32-546 
GUID:{AFD06032-CBF5-4672-B29E-288E6D8FEA1D} 
Group: Guests

General

Name (pre-Windows 2000):Guests 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Guests

Member of

Member Of: 

Members

NameTypeDescription
Domain Guests group All domain guests 
WMUS_ADSCRIBE-SERVER user Default account for anonymous access to Windows Media Services 
Guest user Built-in account for guest access to the computer/domain 
Group: Guests

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: HelpServicesGroup

Group: HelpServicesGroup

Object

Name:HelpServicesGroup 
Path:CN=HelpServicesGroup,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8201 
Current USN:8202 
SID:S-1-5-21-2034109091-298619056-3282043246-1000 
GUID:{81F07DBF-7CCE-448A-9EF3-C56108299ABE} 
Group: HelpServicesGroup

General

Name (pre-Windows 2000):HelpServicesGroup 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: HelpServicesGroup

Member of

Member Of: 

Members

NameTypeDescription
SUPPORT_388945a0 user This is a vendor's account for the Help and Support Service 
Group: HelpServicesGroup

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: IIS_WPG

Group: IIS_WPG

Object

Name:IIS_WPG 
Path:CN=IIS_WPG,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8204 
Current USN:8208 
SID:S-1-5-21-2034109091-298619056-3282043246-1005 
GUID:{AD592C46-7ADA-4F50-8DB3-B1D7409EC0A0} 
Group: IIS_WPG

General

Name (pre-Windows 2000):IIS_WPG 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: IIS_WPG

Member of

Member Of: 

Members

NameTypeDescription
S-1-5-20 foreign-security-principal  
S-1-5-19 foreign-security-principal  
S-1-5-18 foreign-security-principal  
IWAM_ADSCRIBE-SERVER user Built-in account for Internet Information Services to start out of process applications 
Group: IIS_WPG

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Incoming Forest Trust Builders

Group: Incoming Forest Trust Builders

Object

Name:Incoming Forest Trust Builders 
Path:CN=Incoming Forest Trust Builders,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12365 
Current USN:12367 
SID:S-1-5-32-557 
GUID:{420E00E4-6BFB-4227-BD0B-3C8AB20AED78} 
Group: Incoming Forest Trust Builders

General

Name (pre-Windows 2000):Incoming Forest Trust Builders 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Incoming Forest Trust Builders

Member of

Member Of: 
Group: Incoming Forest Trust Builders

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Network Configuration Operators

Group: Network Configuration Operators

Object

Name:Network Configuration Operators 
Path:CN=Network Configuration Operators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8225 
Current USN:8225 
SID:S-1-5-32-556 
GUID:{4DEF0985-16C0-4B67-83BD-AB3A90D905A3} 
Group: Network Configuration Operators

General

Name (pre-Windows 2000):Network Configuration Operators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Network Configuration Operators

Member of

Member Of: 
Group: Network Configuration Operators

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Performance Log Users

Group: Performance Log Users

Object

Name:Performance Log Users 
Path:CN=Performance Log Users,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8227 
Current USN:8228 
SID:S-1-5-32-559 
GUID:{FBC50DEB-1417-4CFC-B7DA-6F8ABF4E3DE1} 
Group: Performance Log Users

General

Name (pre-Windows 2000):Performance Log Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Performance Log Users

Member of

Member Of: 

Members

NameTypeDescription
S-1-5-20 foreign-security-principal  
Group: Performance Log Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Performance Monitor Users

Group: Performance Monitor Users

Object

Name:Performance Monitor Users 
Path:CN=Performance Monitor Users,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8226 
Current USN:8226 
SID:S-1-5-32-558 
GUID:{CEF28F66-CEE3-4B98-8485-CC0F09CEED12} 
Group: Performance Monitor Users

General

Name (pre-Windows 2000):Performance Monitor Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Performance Monitor Users

Member of

Member Of: 
Group: Performance Monitor Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Pre-Windows 2000 Compatible Access

Group: Pre-Windows 2000 Compatible Access

Object

Name:Pre-Windows 2000 Compatible Access 
Path:CN=Pre-Windows 2000 Compatible Access,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12362 
Current USN:12381 
SID:S-1-5-32-554 
GUID:{3D17BBD8-ADD7-4805-862D-4BC1AF05F094} 
Group: Pre-Windows 2000 Compatible Access

General

Name (pre-Windows 2000):Pre-Windows 2000 Compatible Access 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Pre-Windows 2000 Compatible Access

Member of

Member Of: 

Members

NameTypeDescription
S-1-5-11 foreign-security-principal  
Group: Pre-Windows 2000 Compatible Access

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Print Operators

Group: Print Operators

Object

Name:Print Operators 
Path:CN=Print Operators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8221 
Current USN:13972 
SID:S-1-5-32-550 
GUID:{12F699B4-A5B4-4FFC-A7F5-F477C076F06A} 
Group: Print Operators

General

Name (pre-Windows 2000):Print Operators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Print Operators

Member of

Member Of: 
Group: Print Operators

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Programmers

Group: Programmers

Object

Name:Programmers 
Path:CN=Programmers,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13919 
Current USN:13919 
SID:S-1-5-21-2034109091-298619056-3282043246-1118 
GUID:{CF7479DD-FA9D-4AAE-B755-8C9AD1679E2A} 
Group: Programmers

General

Name (pre-Windows 2000):Programmers 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Programmers

Member of

Member Of: 
Group: Programmers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: RAS and IAS Servers

Group: RAS and IAS Servers

Object

Name:RAS and IAS Servers 
Path:CN=RAS and IAS Servers,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12353 
Current USN:12355 
SID:S-1-5-21-2034109091-298619056-3282043246-553 
GUID:{8ED22436-5532-4667-857F-BA43E1A1DE0F} 
Group: RAS and IAS Servers

General

Name (pre-Windows 2000):RAS and IAS Servers 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: RAS and IAS Servers

Member of

Member Of: 
Group: RAS and IAS Servers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Remote Desktop Users

Group: Remote Desktop Users

Object

Name:Remote Desktop Users 
Path:CN=Remote Desktop Users,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8224 
Current USN:8224 
SID:S-1-5-32-555 
GUID:{E8F93FB0-B717-4A3A-A64C-0F77F35822A3} 
Group: Remote Desktop Users

General

Name (pre-Windows 2000):Remote Desktop Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Remote Desktop Users

Member of

Member Of: 
Group: Remote Desktop Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Replicator

Group: Replicator

Object

Name:Replicator 
Path:CN=Replicator,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8223 
Current USN:13969 
SID:S-1-5-32-552 
GUID:{2F00A977-A1D0-4F4F-9471-13634320E4AF} 
Group: Replicator

General

Name (pre-Windows 2000):Replicator 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Replicator

Member of

Member Of: 
Group: Replicator

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Schema Admins

Group: Schema Admins

Object

Name:Schema Admins 
Path:CN=Schema Admins,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:12332 
Current USN:86823 
SID:S-1-5-21-2034109091-298619056-3282043246-518 
GUID:{6BFC40E7-ADE2-42E5-AB31-A816EF2ED3EC} 
Group: Schema Admins

General

Name (pre-Windows 2000):Schema Admins 
Builtin: 
E-mail: 
Scope:Global Group 
Type:Security 
Managed by: 
Notes: 
Group: Schema Admins

Member of

Member Of:Account Operators, Backup Operators 

Members

NameTypeDescription
VirtualDomainServer computer virtual server 
BBB user  
Contact Mr. Mc Contact contact description 
Administrator user Built-in account for administering the computer/domain 
Group: Schema Admins

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Server Operators

Group: Server Operators

Object

Name:Server Operators 
Path:CN=Server Operators,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12356 
Current USN:13968 
SID:S-1-5-32-549 
GUID:{1F377D06-5B6D-42D1-A7E0-8CC31325A4B3} 
Group: Server Operators

General

Name (pre-Windows 2000):Server Operators 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Server Operators

Member of

Member Of: 
Group: Server Operators

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: TelnetClients

Group: TelnetClients

Object

Name:TelnetClients 
Path:CN=TelnetClients,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8203 
Current USN:8203 
SID:S-1-5-21-2034109091-298619056-3282043246-1002 
GUID:{93F955A9-5B89-4C9D-A63B-52E56A3D4A39} 
Group: TelnetClients

General

Name (pre-Windows 2000):TelnetClients 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: TelnetClients

Member of

Member Of: 
Group: TelnetClients

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Terminal Server Computers

Group: Terminal Server Computers

Object

Name:Terminal Server Computers 
Path:CN=Terminal Server Computers,CN=Users,DC=adscribe,DC=com 
Created:11/10/2005 
Modified:11/10/2005 
Original USN:16390 
Current USN:16392 
SID:S-1-5-21-2034109091-298619056-3282043246-1132 
GUID:{9627B3D2-0CFA-43B5-BAB3-D742F7EFB633} 
Group: Terminal Server Computers

General

Name (pre-Windows 2000):Terminal Server Computers 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Terminal Server Computers

Member of

Member Of: 
Group: Terminal Server Computers

Security

Owner:NT AUTHORITY\SYSTEM 
Group:NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Terminal Server License Servers

Group: Terminal Server License Servers

Object

Name:Terminal Server License Servers 
Path:CN=Terminal Server License Servers,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12371 
Current USN:12373 
SID:S-1-5-32-561 
GUID:{A4F54DCB-BC5E-4D6F-BA63-A78F0E18BACB} 
Group: Terminal Server License Servers

General

Name (pre-Windows 2000):Terminal Server License Servers 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Terminal Server License Servers

Member of

Member Of: 
Group: Terminal Server License Servers

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Users

Group: Users

Object

Name:Users 
Path:CN=Users,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8215 
Current USN:12375 
SID:S-1-5-32-545 
GUID:{5A5FD169-DD71-4FF2-B656-01039AC7C09C} 
Group: Users

General

Name (pre-Windows 2000):Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Users

Member of

Member Of: 

Members

NameTypeDescription
Domain Users group All domain users 
S-1-5-11 foreign-security-principal  
S-1-5-4 foreign-security-principal  
ASPNET user Account used for running the ASP.NET worker process (aspnet_wp.exe) 
Group: Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: Windows Authorization Access Group

Group: Windows Authorization Access Group

Object

Name:Windows Authorization Access Group 
Path:CN=Windows Authorization Access Group,CN=Builtin,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12368 
Current USN:12383 
SID:S-1-5-32-560 
GUID:{3FC72A7A-7CF4-42F4-B571-8E9D365E74B6} 
Group: Windows Authorization Access Group

General

Name (pre-Windows 2000):Windows Authorization Access Group 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: Windows Authorization Access Group

Member of

Member Of: 

Members

NameTypeDescription
S-1-5-9 foreign-security-principal  
Group: Windows Authorization Access Group

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

Group: WINS Users

Group: WINS Users

Object

Name:WINS Users 
Path:CN=WINS Users,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8211 
Current USN:8211 
SID:S-1-5-21-2034109091-298619056-3282043246-1010 
GUID:{36791DC7-3833-4B81-A979-FF7A7B31F35A} 
Group: WINS Users

General

Name (pre-Windows 2000):WINS Users 
Builtin: 
E-mail: 
Scope:Domain Local Group 
Type:Security 
Managed by: 
Notes: 
Group: WINS Users

Member of

Member Of: 
Group: WINS Users

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of groups

 

List of builtin groups

Builtin groups

NameScopeTypeE-mail
Account Operators Domain Local Group Security  
Administrators Domain Local Group Security  
Backup Operators Domain Local Group Security  
Group Global Group Security  
Guests Domain Local Group Security  
Incoming Forest Trust Builders Domain Local Group Security  
Network Configuration Operators Domain Local Group Security  
Performance Log Users Domain Local Group Security  
Performance Monitor Users Domain Local Group Security  
Pre-Windows 2000 Compatible Access Domain Local Group Security  
Print Operators Domain Local Group Security  
Remote Desktop Users Domain Local Group Security  
Replicator Domain Local Group Security  
Server Operators Domain Local Group Security  
Terminal Server License Servers Domain Local Group Security  
Users Domain Local Group Security  
Windows Authorization Access Group Domain Local Group Security  

See Also

Active Directory overview

 

List of user groups

User groups

NameScopeTypeE-mail
Cert Publishers Domain Local Group Security  
ddddd Global Group Security  
DHCP Administrators Domain Local Group Security  
DHCP Users Domain Local Group Security  
DnsAdmins Domain Local Group Security  
DnsUpdateProxy Global Group Security  
Domain Admins Global Group Security  
Domain Computers Global Group Security  
Domain Controllers Global Group Security  
Domain Guests Global Group Security  
Domain Users Global Group Security  
Enterprise Admins Global Group Security  
ExternalGroup Global Group Security  
FinanceGroup1 Universal Group Distribution  
Group Policy Creator Owners Global Group Security  
HelpServicesGroup Domain Local Group Security  
IIS_WPG Domain Local Group Security  
Programmers Global Group Security  
RAS and IAS Servers Domain Local Group Security  
Schema Admins Global Group Security  
TelnetClients Domain Local Group Security  
Terminal Server Computers Domain Local Group Security  
WINS Users Domain Local Group Security  

See Also

Active Directory overview

Users


 

User: AAA

User: AAA

Object

Name:AAA 
Path:CN=AAA,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:12/10/2005 
Modified:02/10/2007 
Original USN:28748 
Current USN:79365 
SID:S-1-5-21-2034109091-298619056-3282043246-1137 
GUID:{88B8FCB1-AE3E-4EB1-89FF-6CB86A6F9DBF} 
User: AAA

General

Disabled: 
Type:Normal 
Display name:DisplayName 
First name:FirstName 
Last name:LastName 
Initials:Init 
Description:Decription 
Office:Office 
Telephone:
Telephone(other):telefonnumber2, telefonnumber1 
E-mail:1@email.com 
Web-page:www.webpage.com 
Web-page(other):www.otherwebpage2.com, www.otherwebpage.com 
User: AAA

Address

StreetAddress:Street 
P.O.Box:BOX 
City:Cyty 
State/Province:State/province 
Zip/PostalCode:zip/postalcode 
Country/Region:Afghanistan 
User: AAA

Account

User logon name:AAA@adscribe.com 
User logon name (pre-Windows 2000):PRE2000 
Primary Group:Domain Users 
Member Of:Account Operators, Backup Operators 
Log on to:pcq,pc1 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date:29/09/2007 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: AAA

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number:123 
Static ip address:0.13.222.209 
Static route:qwqqw, wqwqw, 1111 
User: AAA

Profile

Profile path:profilepath 
Script Path:logonscript 
Local path:\\pc1\conecttofolder 
Connect to:W: 
User: AAA

Telephones

Home:home 
Home(other):home2, home1 
Mobile:mobile 
Mobile(other):mobile2, mobile1 
Fax:fax 
Fax(other):fax2, fax1 
IP phone:ipfone 
IP phone(other):ipfone2, ipfone1 
Notes:st: State/province
title: Organization tittle
description: Decription
postalCode: zip/postalcode
postOfficeBox: BOX
physicalDeliveryOfficeName: Office
telephoneNumber: 1
facsimileTelephoneNumber: fax
givenName: FirstName
initials: Init
distinguishedName: CN=AAA,CN=Users,DC=adscribe,DC=com
instanceType: 4
whenCreated: 10/12/2005 23:15:49
whenChanged: 10/13/2005 07:53:08 
User: AAA

Organisation

Title:Organization tittle 
Department:ord department 
Company:org company 
Manager:Administrator 
Direct reports:Administrator 
User: AAA

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: AAA

Terminal service

Logon allowed: 
Profile path:c:/terminal service user profile 
Home drive:Z: 
Home directory://pc1/terminalservicepath 
User: AAA

COM+

Partition set:Current provider does not support returning multiple recordsets from a single execution. 
User: AAA

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: AAA

Session

End a disconnected session:10 minutes 
Active session limit:20 hours  
Idle session limit:1 day 6 hours 30 minutes 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from originating client only 
User: AAA

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: Administrator

User: Administrator

Object

Name:Administrator 
Path:CN=Administrator,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:07/10/2007 
Original USN:8194 
Current USN:87389 
SID:S-1-5-21-2034109091-298619056-3282043246-500 
GUID:{49167A66-00E0-45B7-8304-164A2EEF5AA5} 
User: Administrator

General

Disabled: 
Type:Normal 
Display name: 
First name: 
Last name: 
Initials: 
Description:Built-in account for administering the computer/domain 
Office: 
Telephone: 
Telephone(other): 
E-mail:administrator@adscribe.com 
Web-page: 
Web-page(other): 
User: Administrator

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: Administrator

Account

User logon name:administrator_logon@adscribe.com 
User logon name (pre-Windows 2000):Administrator 
Primary Group:Domain Admins 
Member Of:Group Policy Creator Owners, Domain Users, Enterprise Admins, Schema Admins, Administrators 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: Administrator

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number:9189819891891 
Static ip address: 
Static route: 
User: Administrator

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: Administrator

Telephones

Home:
Home(other): 
Mobile:
Mobile(other): 
Fax:34343434334 
Fax(other):4, 3, 2, 1 
IP phone:
IP phone(other): 
Notes: 
User: Administrator

Organisation

Title:Test Engineer 
Department:Testing 
Company:Leadum Software 
Manager:AAA 
Direct reports:FinanceContact FirstName Init. Last name, AAA, Contact Mr. Mc Contact 
User: Administrator

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: Administrator

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: Administrator

COM+

Partition set: 
User: Administrator

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: Administrator

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: Administrator

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: ASPNET

User: ASPNET

Object

Name:ASPNET 
Path:CN=ASPNET,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8200 
Current USN:8200 
SID:S-1-5-21-2034109091-298619056-3282043246-1007 
GUID:{3A2470CD-6F15-4F15-B65E-0A3D1C6534B8} 
User: ASPNET

General

Disabled: 
Type:Normal 
Display name:ASP.NET Machine Account 
First name: 
Last name: 
Initials: 
Description:Account used for running the ASP.NET worker process (aspnet_wp.exe) 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: ASPNET

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: ASPNET

Account

User logon name: 
User logon name (pre-Windows 2000):ASPNET 
Primary Group:Domain Users 
Member Of:Users 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: ASPNET

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: ASPNET

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: ASPNET

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: ASPNET

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: ASPNET

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: ASPNET

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: ASPNET

COM+

Partition set: 
User: ASPNET

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: ASPNET

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: ASPNET

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\Authenticated Users  Read the properties   
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read the properties   
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: BBB

User: BBB

Object

Name:BBB 
Path:CN=BBB,CN=Users,DC=adscribe,DC=com 
Created:12/10/2005 
Modified:29/09/2007 
Original USN:28791 
Current USN:65593 
SID:S-1-5-21-2034109091-298619056-3282043246-1138 
GUID:{3A65DB55-0DF9-4A39-9F13-253BFA4AD17F} 
User: BBB

General

Disabled: 
Type:Normal 
Display name:BBB 
First name:BBB 
Last name: 
Initials: 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: BBB

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region:Albania 
User: BBB

Account

User logon name:BBB@adscribe.com 
User logon name (pre-Windows 2000):BBB 
Primary Group:Domain Users 
Member Of:FinanceGroup1, Group, DnsAdmins, Schema Admins, Backup Operators 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: BBB

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: BBB

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: BBB

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: BBB

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: BBB

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: BBB

Terminal service

Logon allowed: 
Profile path:C:\terminalServiceProfile 
Home drive: 
Home directory: 
User: BBB

COM+

Partition set: 
User: BBB

Enviroment

Initial program:notepad 
Start in:C:\xxxxx 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: BBB

Session

End a disconnected session:1 minute 
Active session limit:30 minutes 
Idle session limit:1 day  
When a session limit is reached or conection is broken:end session 
Allow reconnection:from originating client only 
User: BBB

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: External Mr. External

User: External Mr. External

Object

Name:External Mr. External 
Path:CN=External Mr. External,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13955 
Current USN:13959 
SID:S-1-5-21-2034109091-298619056-3282043246-1126 
GUID:{2F137CF2-A76F-4901-B140-190098AA1E2A} 
User: External Mr. External

General

Disabled: 
Type:Normal 
Display name:External Mr. External 
First name:External 
Last name:External 
Initials:Mr 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: External Mr. External

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: External Mr. External

Account

User logon name:external@adscribe.com 
User logon name (pre-Windows 2000):external 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: External Mr. External

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: External Mr. External

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: External Mr. External

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: External Mr. External

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: External Mr. External

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: External Mr. External

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: External Mr. External

COM+

Partition set: 
User: External Mr. External

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: External Mr. External

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: External Mr. External

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SELF  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Send As 
NT AUTHORITY\SELF  Extended access rights  Receive As 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
NT AUTHORITY\Authenticated Users  Read permissions   
NT AUTHORITY\Authenticated Users  Read the properties  General Information 
NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
Everyone  Extended access rights  Change Password 
ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: Guest

User: Guest

Object

Name:Guest 
Path:CN=Guest,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8195 
Current USN:8195 
SID:S-1-5-21-2034109091-298619056-3282043246-501 
GUID:{B647CF73-D833-40A1-8C62-D542049C5268} 
User: Guest

General

Disabled: 
Type:Normal 
Display name: 
First name: 
Last name: 
Initials: 
Description:Built-in account for guest access to the computer/domain 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: Guest

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: Guest

Account

User logon name: 
User logon name (pre-Windows 2000):Guest 
Primary Group:Domain Guests 
Member Of:Guests 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: Guest

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: Guest

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: Guest

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: Guest

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: Guest

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: Guest

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: Guest

COM+

Partition set: 
User: Guest

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: Guest

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: Guest

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\Authenticated Users  Read the properties   
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read the properties   
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: IISUser

User: IISUser

Object

Name:IISUser 
Path:CN=IISUser,CN=Users,DC=adscribe,DC=com 
Created:20/09/2007 
Modified:20/09/2007 
Original USN:45088 
Current USN:45101 
SID:S-1-5-21-2034109091-298619056-3282043246-1142 
GUID:{8AE476C2-32B9-44F9-89B9-F12B312256B4} 
User: IISUser

General

Disabled: 
Type:Normal 
Display name:IISUser 
First name:IISUser 
Last name: 
Initials: 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: IISUser

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: IISUser

Account

User logon name:iisuser@adscribe.com 
User logon name (pre-Windows 2000):iisuser 
Primary Group:Domain Users 
Member Of:Administrators 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: IISUser

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: IISUser

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: IISUser

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: IISUser

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: IISUser

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: IISUser

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: IISUser

COM+

Partition set: 
User: IISUser

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: IISUser

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: IISUser

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: InetOrgPerson Init. Last name

User: InetOrgPerson Init. Last name

Object

Name:InetOrgPerson Init. Last name 
Path:CN=InetOrgPerson Init. Last name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:36990 
Current USN:36996 
SID:S-1-5-21-2034109091-298619056-3282043246-1141 
GUID:{C850FD52-C3E3-436E-8769-AB38D74AC786} 
User: InetOrgPerson Init. Last name

General

Disabled: 
Type:Normal 
Display name:InetOrgPerson Init. Last name 
First name:InetOrgPerson 
Last name:Last name 
Initials:Init 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: InetOrgPerson Init. Last name

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: InetOrgPerson Init. Last name

Account

User logon name:inetorgperson@adscribe.com 
User logon name (pre-Windows 2000):inetorgperson 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: InetOrgPerson Init. Last name

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: InetOrgPerson Init. Last name

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: InetOrgPerson Init. Last name

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: InetOrgPerson Init. Last name

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: InetOrgPerson Init. Last name

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: InetOrgPerson Init. Last name

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: InetOrgPerson Init. Last name

COM+

Partition set: 
User: InetOrgPerson Init. Last name

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: InetOrgPerson Init. Last name

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: InetOrgPerson Init. Last name

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SELF  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Send As 
NT AUTHORITY\SELF  Extended access rights  Receive As 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
NT AUTHORITY\Authenticated Users  Read permissions   
NT AUTHORITY\Authenticated Users  Read the properties  General Information 
NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
Everyone  Extended access rights  Change Password 
ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: IUSR_ADSCRIBE-SERVER

User: IUSR_ADSCRIBE-SERVER

Object

Name:IUSR_ADSCRIBE-SERVER 
Path:CN=IUSR_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:20/09/2007 
Original USN:8197 
Current USN:45100 
SID:S-1-5-21-2034109091-298619056-3282043246-1003 
GUID:{B994739D-6CE1-4DF5-AB68-907E13ADF72B} 
User: IUSR_ADSCRIBE-SERVER

General

Disabled: 
Type:Normal 
Display name:Internet Guest Account 
First name: 
Last name: 
Initials: 
Description:Built-in account for anonymous access to Internet Information Services 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: IUSR_ADSCRIBE-SERVER

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: IUSR_ADSCRIBE-SERVER

Account

User logon name: 
User logon name (pre-Windows 2000):IUSR_ADSCRIBE-SERVER 
Primary Group:Domain Users 
Member Of:Administrators 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: IUSR_ADSCRIBE-SERVER

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: IUSR_ADSCRIBE-SERVER

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: IUSR_ADSCRIBE-SERVER

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: IUSR_ADSCRIBE-SERVER

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: IUSR_ADSCRIBE-SERVER

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: IUSR_ADSCRIBE-SERVER

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: IUSR_ADSCRIBE-SERVER

COM+

Partition set: 
User: IUSR_ADSCRIBE-SERVER

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: IUSR_ADSCRIBE-SERVER

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: IUSR_ADSCRIBE-SERVER

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: IWAM_ADSCRIBE-SERVER

User: IWAM_ADSCRIBE-SERVER

Object

Name:IWAM_ADSCRIBE-SERVER 
Path:CN=IWAM_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8198 
Current USN:8198 
SID:S-1-5-21-2034109091-298619056-3282043246-1004 
GUID:{351F292D-6B05-4FC4-ABC2-3B7BBECAEE2F} 
User: IWAM_ADSCRIBE-SERVER

General

Disabled: 
Type:Normal 
Display name:Launch IIS Process Account 
First name: 
Last name: 
Initials: 
Description:Built-in account for Internet Information Services to start out of process applications 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: IWAM_ADSCRIBE-SERVER

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: IWAM_ADSCRIBE-SERVER

Account

User logon name: 
User logon name (pre-Windows 2000):IWAM_ADSCRIBE-SERVER 
Primary Group:Domain Users 
Member Of:IIS_WPG 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: IWAM_ADSCRIBE-SERVER

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: IWAM_ADSCRIBE-SERVER

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: IWAM_ADSCRIBE-SERVER

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: IWAM_ADSCRIBE-SERVER

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: IWAM_ADSCRIBE-SERVER

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: IWAM_ADSCRIBE-SERVER

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: IWAM_ADSCRIBE-SERVER

COM+

Partition set: 
User: IWAM_ADSCRIBE-SERVER

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: IWAM_ADSCRIBE-SERVER

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: IWAM_ADSCRIBE-SERVER

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\Authenticated Users  Read the properties   
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read the properties   
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: krbtgt

User: krbtgt

Object

Name:krbtgt 
Path:CN=krbtgt,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:12320 
Current USN:13974 
SID:S-1-5-21-2034109091-298619056-3282043246-502 
GUID:{257C4FA3-6869-4367-890D-4D74CD6CCA22} 
User: krbtgt

General

Disabled: 
Type:Normal 
Display name: 
First name: 
Last name: 
Initials: 
Description:Key Distribution Center Service Account 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: krbtgt

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: krbtgt

Account

User logon name: 
User logon name (pre-Windows 2000):krbtgt 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: krbtgt

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: krbtgt

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: krbtgt

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: krbtgt

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: krbtgt

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: krbtgt

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: krbtgt

COM+

Partition set: 
User: krbtgt

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: krbtgt

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: krbtgt

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Modify owner
Write permissions
Write the properties 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: New Object

User: New Object

Object

Name:New Object 
Path:CN=New Object,OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:36939 
Current USN:36970 
SID:S-1-5-21-2034109091-298619056-3282043246-1139 
GUID:{61B8947A-4A5D-4EC6-944C-BAC475681854} 
User: New Object

General

Disabled: 
Type:Normal 
Display name: 
First name:Pippo 
Last name: 
Initials: 
Description:new object description 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: New Object

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: New Object

Account

User logon name: 
User logon name (pre-Windows 2000):Pippo 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: New Object

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: New Object

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: New Object

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: New Object

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: New Object

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: New Object

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: New Object

COM+

Partition set: 
User: New Object

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: New Object

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: New Object

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SELF  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Send As 
NT AUTHORITY\SELF  Extended access rights  Receive As 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
NT AUTHORITY\Authenticated Users  Read permissions   
NT AUTHORITY\Authenticated Users  Read the properties  General Information 
NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
Everyone  Extended access rights  Change Password 
ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: oneway.com$

User: oneway.com$

Object

Name:oneway.com$ 
Path:CN=oneway.com$,CN=Users,DC=adscribe,DC=com 
Created:25/09/2007 
Modified:25/09/2007 
Original USN:57351 
Current USN:57354 
SID:S-1-5-21-2034109091-298619056-3282043246-1149 
GUID:{CE826597-299E-42CB-8C4D-4DA15EAB82DD} 
User: oneway.com$

General

Disabled: 
Type:Inter-domain trust 
Display name: 
First name: 
Last name: 
Initials: 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: oneway.com$

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: oneway.com$

Account

User logon name: 
User logon name (pre-Windows 2000):oneway.com$ 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: oneway.com$

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: oneway.com$

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: oneway.com$

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: oneway.com$

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: oneway.com$

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: oneway.com$

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: oneway.com$

COM+

Partition set: 
User: oneway.com$

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: oneway.com$

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: oneway.com$

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: Person Ms. Pirson

User: Person Ms. Pirson

Object

Name:Person Ms. Pirson 
Path:CN=Person Ms. Pirson,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13992 
Current USN:13998 
SID:S-1-5-21-2034109091-298619056-3282043246-1129 
GUID:{F60E6934-EF59-4147-97CE-11AA9DEB10FA} 
User: Person Ms. Pirson

General

Disabled: 
Type:Normal 
Display name:Person Ms. Pirson 
First name:Person 
Last name:Pirson 
Initials:Ms 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: Person Ms. Pirson

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: Person Ms. Pirson

Account

User logon name:pirson@adscribe.com 
User logon name (pre-Windows 2000):pirson 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: Person Ms. Pirson

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: Person Ms. Pirson

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: Person Ms. Pirson

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: Person Ms. Pirson

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: Person Ms. Pirson

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: Person Ms. Pirson

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: Person Ms. Pirson

COM+

Partition set: 
User: Person Ms. Pirson

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: Person Ms. Pirson

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: Person Ms. Pirson

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SELF  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Send As 
NT AUTHORITY\SELF  Extended access rights  Receive As 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
NT AUTHORITY\Authenticated Users  Read permissions   
NT AUTHORITY\Authenticated Users  Read the properties  General Information 
NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
Everyone  Extended access rights  Change Password 
ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: supplier01-int$

User: supplier01-int$

Object

Name:supplier01-int$ 
Path:CN=supplier01-int$,CN=Users,DC=adscribe,DC=com 
Created:25/09/2007 
Modified:25/09/2007 
Original USN:57346 
Current USN:57349 
SID:S-1-5-21-2034109091-298619056-3282043246-1148 
GUID:{36A5639C-0E66-4134-ADCC-01E19799D65B} 
User: supplier01-int$

General

Disabled: 
Type:Inter-domain trust 
Display name: 
First name: 
Last name: 
Initials: 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: supplier01-int$

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: supplier01-int$

Account

User logon name: 
User logon name (pre-Windows 2000):supplier01-int$ 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: supplier01-int$

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: supplier01-int$

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: supplier01-int$

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: supplier01-int$

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: supplier01-int$

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: supplier01-int$

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: supplier01-int$

COM+

Partition set: 
User: supplier01-int$

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: supplier01-int$

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: supplier01-int$

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Delete child object
Create child object 
  
BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  DNSHostName 
ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
ADSCRIBE\Domain Admins  Write the properties  Logon Information 
ADSCRIBE\Domain Admins  Write the properties  Description 
ADSCRIBE\Domain Admins  Write the properties  DisplayName 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: SUPPORT_388945a0

User: SUPPORT_388945a0

Object

Name:SUPPORT_388945a0 
Path:CN=SUPPORT_388945a0,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8196 
Current USN:8196 
SID:S-1-5-21-2034109091-298619056-3282043246-1001 
GUID:{62C83D6A-444F-49F1-9AF7-F52E13349BC0} 
User: SUPPORT_388945a0

General

Disabled: 
Type:Normal 
Display name:CN=Microsoft Corporation,L=Redmond,S=Washington,C=US 
First name: 
Last name: 
Initials: 
Description:This is a vendor's account for the Help and Support Service 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: SUPPORT_388945a0

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: SUPPORT_388945a0

Account

User logon name: 
User logon name (pre-Windows 2000):SUPPORT_388945a0 
Primary Group:Domain Users 
Member Of:HelpServicesGroup 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: SUPPORT_388945a0

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: SUPPORT_388945a0

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: SUPPORT_388945a0

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: SUPPORT_388945a0

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: SUPPORT_388945a0

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: SUPPORT_388945a0

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: SUPPORT_388945a0

COM+

Partition set: 
User: SUPPORT_388945a0

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: SUPPORT_388945a0

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: SUPPORT_388945a0

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\Authenticated Users  Read the properties   
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read the properties   
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: VUSR_ADSCRIBE-SERVER

User: VUSR_ADSCRIBE-SERVER

Object

Name:VUSR_ADSCRIBE-SERVER 
Path:CN=VUSR_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created:11/10/2005 
Modified:11/10/2005 
Original USN:20498 
Current USN:20501 
SID:S-1-5-21-2034109091-298619056-3282043246-1133 
GUID:{2BEDDF1D-F34A-438A-89DE-FC550A3C6F57} 
User: VUSR_ADSCRIBE-SERVER

General

Disabled: 
Type:Normal 
Display name:VSA Server Account 
First name: 
Last name: 
Initials: 
Description:Cuenta para los componentes de servidor de Visual Studio Analyzer 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: VUSR_ADSCRIBE-SERVER

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: VUSR_ADSCRIBE-SERVER

Account

User logon name: 
User logon name (pre-Windows 2000):VUSR_ADSCRIBE-SERVER 
Primary Group:Domain Users 
Member Of: 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: VUSR_ADSCRIBE-SERVER

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: VUSR_ADSCRIBE-SERVER

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: VUSR_ADSCRIBE-SERVER

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: VUSR_ADSCRIBE-SERVER

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: VUSR_ADSCRIBE-SERVER

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: VUSR_ADSCRIBE-SERVER

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: VUSR_ADSCRIBE-SERVER

COM+

Partition set: 
User: VUSR_ADSCRIBE-SERVER

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: VUSR_ADSCRIBE-SERVER

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: VUSR_ADSCRIBE-SERVER

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SELF  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Send As 
NT AUTHORITY\SELF  Extended access rights  Receive As 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
NT AUTHORITY\Authenticated Users  Read permissions   
NT AUTHORITY\Authenticated Users  Read the properties  General Information 
NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
Everyone  Extended access rights  Change Password 
ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

 

User: WMUS_ADSCRIBE-SERVER

User: WMUS_ADSCRIBE-SERVER

Object

Name:WMUS_ADSCRIBE-SERVER 
Path:CN=WMUS_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:8199 
Current USN:8199 
SID:S-1-5-21-2034109091-298619056-3282043246-1006 
GUID:{8C692548-3019-495B-BA5C-03F4FE22D4EE} 
User: WMUS_ADSCRIBE-SERVER

General

Disabled: 
Type:Normal 
Display name:Windows Media Services Guest Account 
First name: 
Last name: 
Initials: 
Description:Default account for anonymous access to Windows Media Services 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
User: WMUS_ADSCRIBE-SERVER

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
User: WMUS_ADSCRIBE-SERVER

Account

User logon name: 
User logon name (pre-Windows 2000):WMUS_ADSCRIBE-SERVER 
Primary Group:Domain Users 
Member Of:Guests 
Log on to:All computers 
Account is locked out: 
User must change password at next logon??: 
User cannot change password: 
Password never expired: 
Store password using reversible encryption: 
Account is disabled: 
Smart card is required for interactive logon: 
Account is trusted for delegation: 
Account is sensitive and cannot be delegated: 
Use DES encryption types for this account: 
Do not require Kerberos preauthentication: 
Account expires: 
Account expiration date: 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         
User: WMUS_ADSCRIBE-SERVER

Dial-in

Allowed: 
Verify caller ID: 
Calling station ID(s): 
Callback number: 
Static ip address: 
Static route: 
User: WMUS_ADSCRIBE-SERVER

Profile

Profile path: 
Script Path: 
Local path: 
Connect to: 
User: WMUS_ADSCRIBE-SERVER

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
User: WMUS_ADSCRIBE-SERVER

Organisation

Title: 
Department: 
Company: 
Manager: 
Direct reports: 
User: WMUS_ADSCRIBE-SERVER

Remote control

Enabled: 
Require user permission: 
View user session: 
Interract user session: 
User: WMUS_ADSCRIBE-SERVER

Terminal service

Logon allowed: 
Profile path: 
Home drive: 
Home directory: 
User: WMUS_ADSCRIBE-SERVER

COM+

Partition set: 
User: WMUS_ADSCRIBE-SERVER

Enviroment

Initial program: 
Start in: 
Connect client drives at logon: 
Connect client printers at logon: 
Default to main printer: 
User: WMUS_ADSCRIBE-SERVER

Session

End a disconnected session: 
Active session limit: 
Idle session limit: 
When a session limit is reached or conection is broken:disconnect from session 
Allow reconnection:from any client 
User: WMUS_ADSCRIBE-SERVER

Security

Owner:BUILTIN\Administrators 
Group:BUILTIN\Administrators 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\SELF  Extended access rights  Change Password 
Everyone  Extended access rights  Change Password 
NT AUTHORITY\Authenticated Users  Read the properties   
BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SELF  Read the properties   
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of users

Contacts


 

Contact: Contact Mr. Mc Contact

Contact: Contact Mr. Mc Contact

Object

Name:Contact Mr. Mc Contact 
Path:CN=Contact Mr. Mc Contact,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:16/09/2007 
Original USN:13990 
Current USN:36978 
GUID:{CCA799E3-04CB-46A8-AC71-32CD9BA0C7E6} 
Contact: Contact Mr. Mc Contact

General

Display name:display name 
First name:FirstName 
Last name:Lastname 
Initials:Init 
Description:description 
Office:ofice 
Telephone:Telephone 
Telephone(other):telephone2, telephone1 
E-mail:email 
Web-page:webpage 
Web-page(other):webpage2, webpage1 
Contact: Contact Mr. Mc Contact

Address

StreetAddress:Stret dsdsdsds 
P.O.Box:pobox 
City:city 
State/Province:state/province 
Zip/PostalCode:zip 
Country/Region:American Samoa 
Contact: Contact Mr. Mc Contact

Telephones

Home:home phone 
Home(other):home phone2, home phone1 
Mobile:mobile 
Mobile(other):mobile2, mobile1 
Fax:fax 
Fax(other):fax2, fax1 
IP phone:ipphone 
IP phone(other):ipphone2, ipphone1 
Notes:select case (Host.ContextObject.Properties("DEPENDENTTYPE").Value)
case "V" :strName="VIEW"
case "T" :strName="TABLE"
case "P" :strName="PROCEDURE"
case "PG" :strName="PACKAGE"
case "IX" :strName="INDEX"
case "F" :strName="FUNCTION"
case "TR" :strName="TRIGGERr"
case "S" :strName="MATERIALISED VIEW"
case "I" :strName="INDEX"
case "N" :strName="NICKNAME"
case "A" :strName="ALIAS"
case "SH" :strName="SCHEMA"
case "SQ" :strName="SEQUENCE"
case "TBS" :strName="TABLESPACE"
case "DB" :strName="DATABASE"
end select
Host.returnValue=strName 
Contact: Contact Mr. Mc Contact

Organisation

Title:Tittle 
Department:department 
Company:company 
Manager:Administrator 
Direct reports: 
Contact: Contact Mr. Mc Contact

Member of

Member Of:Schema Admins, Administrators 
Contact: Contact Mr. Mc Contact

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of contacts

 

Contact: FinanceContact FirstName Init. Last name

Contact: FinanceContact FirstName Init. Last name

Object

Name:FinanceContact FirstName Init. Last name 
Path:CN=FinanceContact FirstName Init. Last name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:03/10/2007 
Original USN:36982 
Current USN:79677 
GUID:{64B5C1DA-383D-495D-8000-56170E12A9C5} 
Contact: FinanceContact FirstName Init. Last name

General

Display name:Display name 
First name:FinanceContact FirstName 
Last name:Last name 
Initials:Init 
Description: 
Office: 
Telephone: 
Telephone(other): 
E-mail: 
Web-page: 
Web-page(other): 
Contact: FinanceContact FirstName Init. Last name

Address

StreetAddress: 
P.O.Box: 
City: 
State/Province: 
Zip/PostalCode: 
Country/Region: 
Contact: FinanceContact FirstName Init. Last name

Telephones

Home: 
Home(other): 
Mobile: 
Mobile(other): 
Fax: 
Fax(other): 
IP phone: 
IP phone(other): 
Notes: 
Contact: FinanceContact FirstName Init. Last name

Organisation

Title:title 
Department: 
Company: 
Manager:Administrator 
Direct reports: 
Contact: FinanceContact FirstName Init. Last name

Member of

Member Of:Backup Operators, Administrators 
Contact: FinanceContact FirstName Init. Last name

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of contacts

Shared folders


 

Shared folder: folder1

Shared folder: folder1

Object

Name:folder1 
Path:CN=folder1,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:36983 
Current USN:37009 
GUID:{D24D0179-79A7-4868-8954-36E764BB8D35} 
Shared folder: folder1

General

Description:Description 
UNC name:\\server\path 
Managed by:Administrator 
Keywords:keyword3, keyword2, keywrord1 

See Also

List of folders

 

Shared folder: Share1

Shared folder: Share1

Object

Name:Share1 
Path:CN=Share1,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:14000 
Current USN:14000 
GUID:{EAA66918-3132-4EAF-B34B-DE282247629B} 
Shared folder: Share1

General

Description: 
UNC name:\\pdcn\share 
Managed by: 
Keywords: 

See Also

List of folders

Printers


 

Printer: Printer display name

Printer: Printer display name

Object

Name:Printer display name 
Path:CN=Printer display name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:37017 
Current USN:37023 
GUID:{E345D4A2-B53E-4AFE-AE89-381E38904B48} 
Printer: Printer display name

General

Printer name:printer 
Location:printer location 
Model:HPLaserJet 
Color: 
Staple: 
Double-sided: 
Printing speed:20 
Maximim resoltion:600 
Managed by:Administrator 

See Also

List of printers

MSMQ queue aliases


 

MSMQ queue alias: queue_alias

MSMQ queue alias: queue_alias

Object

Name:queue_alias 
Path:CN=queue_alias,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:13999 
Current USN:13999 
GUID:{6079A97B-E4EF-4E87-8465-96D56B29E3D0} 
MSMQ queue alias: queue_alias

General

Description: 
Format name:DIRECT=os:comp\private$\q3 
Member Of:FinanceGroup1 

See Also

List of MSMQ queue aliases

 

MSMQ queue alias: queue_alias

MSMQ queue alias: queue_alias

Object

Name:queue_alias 
Path:CN=queue_alias,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:36999 
Current USN:37013 
GUID:{4725028E-9A47-40D8-852B-7A60180CBC4F} 
MSMQ queue alias: queue_alias

General

Description:Description 
Format name:DIRECT=os:comp1\private$\q1 
Member Of:FinanceGroup1, Administrators 

See Also

List of MSMQ queue aliases

Sites


 

Site: SomeSite

Site: SomeSite

Object

Name:SomeSite 
Path:CN=SomeSite,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:17/09/2007 
Original USN:4112 
Current USN:37058 
GUID:{C82F38B8-CD26-4E22-8327-4649B560762B} 
Site: SomeSite

General

Description:Site description 
Location:site location 

Servers

NameDescription
ADSCRIBE-SERVER site server description 

Subnets

NameDescriptionLocation
10.14.208.0/20 Subne1 New York 
Site: SomeSite

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 
Site: SomeSite

Group policy

Block policy inheritance: 

Group policy settings

NameDisabledOverride
Site Group Policy   
Site Group Policy 2   

See Also

List of sites

Servers


 

Server: ADSCRIBE-SERVER

Server: ADSCRIBE-SERVER

Object

Name:ADSCRIBE-SERVER 
Path:CN=ADSCRIBE-SERVER,CN=Servers,CN=SomeSite,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:25/09/2007 
Original USN:4417 
Current USN:57372 
GUID:{62135401-DA8E-4C3B-A8EE-74D066504D83} 
Server: ADSCRIBE-SERVER

General

Description:site server description 
Inter-site data transfer transports:SMTP, IP 
Server reference:ADSCRIBE-SERVER 
DNS hostname:adscribe-server.adscribe.com 

See Also

List of servers

Subnets


 

Subnet: 10.14.208.0/20

Subnet: 10.14.208.0/20

Object

Name:10.14.208.0/20 
Path:CN=10.14.208.0/20,CN=Subnets,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:20/09/2007 
Original USN:13989 
Current USN:49167 
GUID:{D986E11C-307C-4CE7-9939-4DD49E1F0095} 
Subnet: 10.14.208.0/20

General

Description:Subne1 
Location:New York 

See Also

List of subnets

Inter-site transports


 

Inter-site transport: IP

Inter-site transport: IP

Object

Name:IP 
Path:CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:23/09/2007 
Original USN:4109 
Current USN:53311 
GUID:{0E308A99-144B-434D-A010-DF9DE492A3E7} 
Inter-site transport: IP

General

Description:ip inter site transport 
Ignore schedules:?????? 
Bridge all site links:?????? 

Site links

NameDescriptionCostReplication interval
DEFAULTIPSITELINK default site link 100 180 
SITELINK2 site link 2 100 180 

Site link bridges

NameDescription
SiteLinkBridge site link bridge 
Inter-site transport: IP

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 

See Also

List of inter-site transports

Site links


 

Site link: DEFAULTIPSITELINK

Site link: DEFAULTIPSITELINK

Object

Name:DEFAULTIPSITELINK 
Path:CN=DEFAULTIPSITELINK,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:23/09/2007 
Original USN:4110 
Current USN:53318 
GUID:{10608ADC-3DD4-471D-B143-A57A5657584B} 
Site link: DEFAULTIPSITELINK

General

Description:default site link 
Ignore schedules: 
Bridge all site links: 
Site link: DEFAULTIPSITELINK

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 

See Also

List of site links

 

Site link: SITELINK2

Site link: SITELINK2

Object

Name:SITELINK2 
Path:CN=SITELINK2,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:23/09/2007 
Modified:23/09/2007 
Original USN:53314 
Current USN:53317 
GUID:{4E97D919-7160-42CE-AF63-92E6268853EA} 
Site link: SITELINK2

General

Description:site link 2 
Ignore schedules: 
Bridge all site links: 
Site link: SITELINK2

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 

See Also

List of site links

Site link bridges


 

Site link bridge: SiteLinkBridge

Site link bridge: SiteLinkBridge

Object

Name:SiteLinkBridge 
Path:CN=SiteLinkBridge,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:23/09/2007 
Modified:23/09/2007 
Original USN:53315 
Current USN:53316 
GUID:{E8087405-11F8-4B12-8A4B-A361C9829708} 
Site link bridge: SiteLinkBridge

General

Description:site link bridge 
Site links:SITELINK2, DEFAULTIPSITELINK 
Site link bridge: SiteLinkBridge

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 

 

Inter-site transport: SMTP

Inter-site transport: SMTP

Object

Name:SMTP 
Path:CN=SMTP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:23/09/2007 
Original USN:4111 
Current USN:53313 
GUID:{5388369E-9BB7-4FB5-824A-5B8FB423C4DF} 
Inter-site transport: SMTP

General

Description:smtpintersite transport 
Ignore schedules:?????? 
Bridge all site links:?????? 
Inter-site transport: SMTP

Security

Owner:ADSCRIBE\Enterprise Admins 
Group:ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
Everyone Extended access rights  NTDSDSA  
Everyone Write the properties  Site GPLink 
Everyone Write the properties  Site GPOptions 
Everyone Write the properties  Subnet SiteObject 

See Also

List of inter-site transports

Group polices


 

Group policy: Default Domain Controllers Policy

Group policy: Default Domain Controllers Policy

Object

Name:{6AC1786C-016F-11D2-945F-00C04fB984F9} 
Path:CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:22/09/2007 
Original USN:4319 
Current USN:53268 
GUID:{10B4A858-48E6-4202-8B6B-9B90731743E0} 
Group policy: Default Domain Controllers Policy

General

Display name:Default Domain Controllers Policy 
Group policy: Default Domain Controllers Policy

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of group polices

 

Group policy: Default Domain Policy

Group policy: Default Domain Policy

Object

Name:{31B2F340-016D-11D2-945F-00C04FB984F9} 
Path:CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=adscribe,DC=com 
Created:10/10/2006 
Modified:10/10/2006 
Original USN:4316 
Current USN:12513 
GUID:{4E7F1770-CC3D-4689-85A2-E262013B78A2} 
Group policy: Default Domain Policy

General

Display name:Default Domain Policy 
Group policy: Default Domain Policy

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of group polices

 

Group policy: New Group Policy Object

Group policy: New Group Policy Object

Object

Name:{389837ED-E82B-430A-BD5D-B63650F65943} 
Path:CN={389837ED-E82B-430A-BD5D-B63650F65943},CN=Policies,CN=System,DC=adscribe,DC=com 
Created:16/09/2007 
Modified:16/09/2007 
Original USN:36958 
Current USN:36964 
GUID:{C5C1CC02-994B-4396-8414-AB12A0728D40} 
Group policy: New Group Policy Object

General

Display name:New Group Policy Object 
Group policy: New Group Policy Object

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of group polices

 

Group policy: Site Group Policy

Group policy: Site Group Policy

Object

Name:{971DBFF7-DD86-46DE-BAB4-8792539BC315} 
Path:CN={971DBFF7-DD86-46DE-BAB4-8792539BC315},CN=Policies,CN=System,DC=adscribe,DC=com 
Created:17/09/2007 
Modified:17/09/2007 
Original USN:37035 
Current USN:37043 
GUID:{E3A5F827-0868-4211-9A1A-ACC024A3DED6} 
Group policy: Site Group Policy

General

Display name:Site Group Policy 
Group policy: Site Group Policy

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of group polices

 

Group policy: Site Group Policy 2

Group policy: Site Group Policy 2

Object

Name:{5DC08DC4-8E46-438E-BEE2-E09BC30A03A7} 
Path:CN={5DC08DC4-8E46-438E-BEE2-E09BC30A03A7},CN=Policies,CN=System,DC=adscribe,DC=com 
Created:17/09/2007 
Modified:17/09/2007 
Original USN:37051 
Current USN:37057 
GUID:{50A25424-CE3B-48E7-B03B-D6AA2F5E8E7E} 
Group policy: Site Group Policy 2

General

Display name:Site Group Policy 2 
Group policy: Site Group Policy 2

Security

Owner:ADSCRIBE\Domain Admins 
Group:ADSCRIBE\Domain Users 
Allow inheritable permissions from parent: 

Security permissions

TrusteeAllowAccessInheretedChildren
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  

Audit permissions

TrusteeAccessInheretedChildrenAttribute
Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
Everyone Write the properties  OrganizationalUnit GPLink 
Everyone Write the properties  OrganizationalUnit GPOptions 

See Also

List of group polices

 

About

About

Documentation details

Customer: 
Project: 
Created:09/10/2007 
Generator:DBScribe 1.1 for PosgreSQL