Domain Report

  

 

 

 

 

 

 

 

 

 

09/10/2007


Index

Domain: adscribe.com _ 3

Computers _ 3

Organizational units _ 3

Groups _ 3

List of builtin groups _ 3

List of user groups _ 3

Users _ 3

Contacts _ 3

Shared folders _ 3

Printers _ 3

MSMQ queue aliases _ 3

Sites _ 3

Inter-site transports _ 3

Group polices _ 3

About _ 3


Domain: adscribe.com

Object

Name: adscribe.com 
Path: DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 24/09/2007 
Original USN: 4098 
Current USN: 53390 
SID: S-1-5-21-2034109091-298619056-3282043246 
GUID: {81E4BD01-B467-41ED-9CFF-284FA94ED6A2} 

General

Domain name (pre-Windows 2000): adscribe 
Description: domain description 
Domain functional level: Windows 2000 
Forest functional level: Windows 2000 
Managed by: AAA 
Domain controller: ADSCRIBE-SERVER 

Organizational units

NameDescription
 Accounting  
 Domain Controllers Default container for domain controllers 
 Finance  
 subdomain controllers  
 TopFinance Description 
Total: 5 organizational unit(s)

Computers

NameRoleDisabledDescription
 ADSCRIBE-SERVER Domain Controller  domain controller description 
 EXTPC1 Workstation or Server   
 PC1 Workstation or Server  pc1 description 
 PC2 Workstation or Server   
 PC3 Workstation or Server   
 PC4 Workstation or Server   
 PC6 Workstation or Server   
 VirtualDomainServer Workstation or Server  virtual server 
Total: 8 computer(s)

Groups

NameBuiltinScopeTypeE-mail
 Account Operators  Domain Local Group Security  
 Administrators  Domain Local Group Security  
 Backup Operators  Domain Local Group Security  
 Cert Publishers  Domain Local Group Security  
 ddddd  Global Group Security  
 DHCP Administrators  Domain Local Group Security  
 DHCP Users  Domain Local Group Security  
 DnsAdmins  Domain Local Group Security  
 DnsUpdateProxy  Global Group Security  
 Domain Admins  Global Group Security  
 Domain Computers  Global Group Security  
 Domain Controllers  Global Group Security  
 Domain Guests  Global Group Security  
 Domain Users  Global Group Security  
 Enterprise Admins  Global Group Security  
 ExternalGroup  Global Group Security  
 FinanceGroup1  Universal Group Distribution  
 Group  Global Group Security  
 Group Policy Creator Owners  Global Group Security  
 Guests  Domain Local Group Security  
 HelpServicesGroup  Domain Local Group Security  
 IIS_WPG  Domain Local Group Security  
 Incoming Forest Trust Builders  Domain Local Group Security  
 Network Configuration Operators  Domain Local Group Security  
 Performance Log Users  Domain Local Group Security  
 Performance Monitor Users  Domain Local Group Security  
 Pre-Windows 2000 Compatible Access  Domain Local Group Security  
 Print Operators  Domain Local Group Security  
 Programmers  Global Group Security  
 RAS and IAS Servers  Domain Local Group Security  
 Remote Desktop Users  Domain Local Group Security  
 Replicator  Domain Local Group Security  
 Schema Admins  Global Group Security  
 Server Operators  Domain Local Group Security  
 TelnetClients  Domain Local Group Security  
 Terminal Server Computers  Domain Local Group Security  
 Terminal Server License Servers  Domain Local Group Security  
 Users  Domain Local Group Security  
 Windows Authorization Access Group  Domain Local Group Security  
 WINS Users  Domain Local Group Security  
Total: 40 group(s)

Foreign security principals

NameTypeDescription
 Contact Mr. Mc Contact contact description 
 External Mr. External user  
 ExternalGroup group  
 EXTPC1 computer  
 Person Ms. Pirson user  
 Programmers group  
 queue_alias queuealias  
 S-1-5-11 foreign-security-principal  
 S-1-5-18 foreign-security-principal  
 S-1-5-19 foreign-security-principal  
 S-1-5-20 foreign-security-principal  
 S-1-5-4 foreign-security-principal  
 S-1-5-9 foreign-security-principal  
 Share1 folder  
Total: 14 foreign security principal(s)

Users

NameDisabledLockedDescriptionE-mail
 AAA   Decription 1@email.com 
 Administrator   Built-in account for administering the computer/domain administrator@adscribe.com 
 ASPNET   Account used for running the ASP.NET worker process (aspnet_wp.exe)  
 BBB     
 External Mr. External     
 Guest   Built-in account for guest access to the computer/domain  
 IISUser     
 InetOrgPerson Init. Last name     
 IUSR_ADSCRIBE-SERVER   Built-in account for anonymous access to Internet Information Services  
 IWAM_ADSCRIBE-SERVER   Built-in account for Internet Information Services to start out of process applications  
 krbtgt   Key Distribution Center Service Account  
 New Object   new object description  
 oneway.com$     
 Person Ms. Pirson     
 supplier01-int$     
 SUPPORT_388945a0   This is a vendor's account for the Help and Support Service  
 VUSR_ADSCRIBE-SERVER   Cuenta para los componentes de servidor de Visual Studio Analyzer  
 WMUS_ADSCRIBE-SERVER   Default account for anonymous access to Windows Media Services  
Total: 18 user(s)

Contacts

NameDescriptionE-mail
 Contact Mr. Mc Contact description email 
 FinanceContact FirstName Init. Last name   
Total: 2 contact(s)

Shared folders

NameDescription
 folder1 Description 
 Share1  
Total: 2 shared folder(s)

Printers

NameDescription
 Printer display name description 
Total: 1 printer(s)

MSMQ queue aliases

NameDescription
 queue_alias  
 queue_alias Description 
Total: 2 MSMQ queue alias(es)

Sites

NameDescription
 SomeSite Site description 
Total: 1 site(s)

Inter-site transports

NameDescription
 IP ip inter site transport 
 SMTP smtpintersite transport 
Total: 2 inter-site transport(s)

Trusts

DomainTypeDirectionTransitive
 oneway.com Realm Incomming  
 outgoing Realm Outgoing  
 supplier01-int Realm Bidirectional  
Total: 3 trust(s)

Group policies

DisplayName
 Default Domain Controllers Policy 
 Default Domain Policy 
 New Group Policy Object 
 Site Group Policy 
 Site Group Policy 2 
Total: 5 group policy(s)

Security

Owner:  
Group:  
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 Everyone  Read the properties   
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Replicating Directory Changes 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Replication Synchronization 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Extended access rights  Manage Replication Topology 
 BUILTIN\Administrators  Extended access rights  Replicating Directory Changes 
 BUILTIN\Administrators  Extended access rights  Replication Synchronization 
 BUILTIN\Administrators  Extended access rights  Manage Replication Topology 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Domain Password & Lockout Policies 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
Read the properties 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Other Domain Parameters (for use by SAM) 
 NT AUTHORITY\Authenticated Users  Read the properties  Other Domain Parameters (for use by SAM) 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 ADSCRIBE\Domain Controllers  Extended access rights  Replicating Directory Changes All 
 BUILTIN\Administrators  Extended access rights  Replicating Directory Changes All 
 BUILTIN\Incoming Forest Trust Builders  Extended access rights  Create Inbound Forest Trust 
 NT AUTHORITY\Authenticated Users  Extended access rights  Update Password Not Required Bit 
 NT AUTHORITY\Authenticated Users  Extended access rights  Unexpire Password 
 NT AUTHORITY\Authenticated Users  Extended access rights  Enable Per User Reversibly Encrypted Password 
Total: 40 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 BUILTIN\Administrators Extended access rights    
 ADSCRIBE\Domain Users Extended access rights    
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 5 audit permission(s)

Group policy

Block policy inheritance:  

Group policy settings

NameDisabledOverride
 Default Domain Policy   
Total: 1 group policy(s)

Computers


Computer: ADSCRIBE-SERVER

Object

Name: ADSCRIBE-SERVER 
Path: CN=ADSCRIBE-SERVER,OU=Domain Controllers,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 12290 
Current USN: 86619 
SID: S-1-5-21-2034109091-298619056-3282043246-1011 
GUID: {65462E0F-1D5D-42C8-AE5F-960B9BCC0EFD} 

General

Disabled:  
Computer name (pre-Windows 2000): ADSCRIBE-SERVER$ 
DNS name: adscribe-server.adscribe.com 
Role: Domain Controller 
Description: domain controller description 
Location: Location 
Trast computer for delegation:  
Managed by: AAA 

Operating System

Name: Windows Server 2003 
Version: 5.2 (3790) 
Service pack:  

Member of

Primary Group: Domain Controllers 
Member Of: Domain Computers, Administrators, DHCP Administrators 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties    
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 4 audit permission(s)

See Also

List of computers


Computer: EXTPC1

Object

Name: EXTPC1 
Path: CN=EXTPC1,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13984 
Current USN: 13988 
SID: S-1-5-21-2034109091-298619056-3282043246-1128 
GUID: {A5258F31-0293-4B61-8BE5-FAA8F2834DC9} 

General

Disabled:  
Computer name (pre-Windows 2000): EXTPC1$ 
DNS name:  
Role: Workstation or Server 
Description:  
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: PC1

Object

Name: PC1 
Path: CN=PC1,CN=Computers,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 16/09/2007 
Original USN: 13899 
Current USN: 36943 
SID: S-1-5-21-2034109091-298619056-3282043246-1115 
GUID: {F5E7ADB6-4747-4532-8841-8EFB0296ED02} 

General

Disabled:  
Computer name (pre-Windows 2000): PC1$ 
DNS name:  
Role: Workstation or Server 
Description: pc1 description 
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: PC2

Object

Name: PC2 
Path: CN=PC2,CN=Computers,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13905 
Current USN: 13909 
SID: S-1-5-21-2034109091-298619056-3282043246-1116 
GUID: {4C23671F-FAE1-4FCD-A732-92910029D26A} 

General

Disabled:  
Computer name (pre-Windows 2000): PC2$ 
DNS name:  
Role: Workstation or Server 
Description:  
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: PC3

Object

Name: PC3 
Path: CN=PC3,CN=Computers,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13911 
Current USN: 13915 
SID: S-1-5-21-2034109091-298619056-3282043246-1117 
GUID: {D2E851B8-2224-4B6C-945A-1C3BD1725107} 

General

Disabled:  
Computer name (pre-Windows 2000): PC3PREWIN2000$ 
DNS name:  
Role: Workstation or Server 
Description:  
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: PC4

Object

Name: PC4 
Path: CN=PC4,OU=Accounting,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 14010 
Current USN: 86206 
SID: S-1-5-21-2034109091-298619056-3282043246-1131 
GUID: {D6D82021-F8A4-4386-9577-F22A817F2806} 

General

Disabled:  
Computer name (pre-Windows 2000): PC4$ 
DNS name:  
Role: Workstation or Server 
Description:  
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: PC6

Object

Name: PC6 
Path: CN=PC6,OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 12/10/2005 
Original USN: 28724 
Current USN: 28728 
SID: S-1-5-21-2034109091-298619056-3282043246-1135 
GUID: {B41AAD7D-E64A-4F1C-943D-258AF9EEB95C} 

General

Disabled:  
Computer name (pre-Windows 2000): PC6$ 
DNS name:  
Role: Workstation or Server 
Description:  
Location:  
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Computers 
Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of computers


Computer: VirtualDomainServer

Object

Name: VirtualDomainServer 
Path: CN=VirtualDomainServer,OU=subdomain controllers,OU=Domain Controllers,DC=adscribe,DC=com 
Created: 23/09/2007 
Modified: 07/10/2007 
Original USN: 53289 
Current USN: 87020 
SID: S-1-5-21-2034109091-298619056-3282043246-1143 
GUID: {96BB9188-534E-44C1-A8EB-720C3A424A7B} 

General

Disabled:  
Computer name (pre-Windows 2000): VirtualDomain 
DNS name: virtual-server.adscribe2.com 
Role: Workstation or Server 
Description: virtual server 
Location: alabama 
Trast computer for delegation:  
Managed by:  

Operating System

Name:  
Version:  
Service pack:  

Member of

Primary Group: Domain Users 
Member Of: Schema Admins 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties    
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 4 audit permission(s)

See Also

List of computers


Organizational units


Organizational unit: Accounting

Object

Name: Accounting 
Path: OU=Accounting,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 01/10/2007 
Original USN: 14008 
Current USN: 76866 
GUID: {1AB97C26-DD41-45AB-A1B2-1EE883A22D77} 

General

Description:  
Street:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  
Managed by:  

Members

NameTypeDescription
 Finance unit  
 PC4 computer  
Total: 2 member(s)

COM+

Partition set: Current provider does not support returning multiple recordsets from a single execution. 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
 BUILTIN\Account Operators  Delete child object
Create child object 
 User 
 BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 28 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

Group policy

Block policy inheritance:  

Group policy settings

NameDisabledOverride
 Default Domain Controllers Policy   
 Site Group Policy 2   
Total: 2 group policy(s)

See Also

List of organizational units


Organizational unit: Domain Controllers

Object

Name: Domain Controllers 
Path: OU=Domain Controllers,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 4411 
Current USN: 4411 
GUID: {96828BC9-46A8-44F0-9CCB-4163CB9A1591} 

General

Description: Default container for domain controllers 
Street:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  
Managed by:  

Members

NameTypeDescription
 ADSCRIBE-SERVER computer domain controller description 
 subdomain controllers unit  
Total: 2 member(s)

COM+

Partition set:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 23 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Write the properties    
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 4 audit permission(s)

Group policy

Block policy inheritance:  

Group policy settings

NameDisabledOverride
 Default Domain Controllers Policy   
Total: 1 group policy(s)

See Also

List of organizational units


Organizational unit: Finance

Object

Name: Finance 
Path: OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 12/10/2005 
Original USN: 28715 
Current USN: 28715 
GUID: {6E183DB3-0AAC-4BC4-8B02-6EF90B960C1D} 

General

Description:  
Street:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  
Managed by:  

Members

NameTypeDescription
 AAA user Decription 
 FinanceContact FirstName Init. Last name contact  
 FinanceGroup1 group  
 folder1 folder Description 
 InetOrgPerson Init. Last name user  
 Printer display name printer description 
 queue_alias queuealias Description 
 TopFinance unit Description 
Total: 8 member(s)

COM+

Partition set:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
 BUILTIN\Account Operators  Delete child object
Create child object 
 User 
 BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 28 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

Group policy

Block policy inheritance:  

See Also

List of organizational units


Organizational unit: subdomain controllers

Object

Name: subdomain controllers 
Path: OU=subdomain controllers,OU=Domain Controllers,DC=adscribe,DC=com 
Created: 23/09/2007 
Modified: 23/09/2007 
Original USN: 53330 
Current USN: 53330 
GUID: {4EB59D4E-5E45-4102-9553-4E9DF21AB256} 

General

Description:  
Street:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  
Managed by:  

Members

NameTypeDescription
 VirtualDomainServer computer virtual server 
Total: 1 member(s)

COM+

Partition set:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
 BUILTIN\Account Operators  Delete child object
Create child object 
 User 
 BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 28 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties    
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

Group policy

Block policy inheritance:  

See Also

List of organizational units


Organizational unit: TopFinance

Object

Name: TopFinance 
Path: OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 16/09/2007 
Original USN: 28722 
Current USN: 36967 
GUID: {2F7883A7-68FF-47AF-98E2-A6583D1C28FF} 

General

Description: Description 
Street: Street 
City: City 
State/Province: State/Province 
Zip/PostalCode: zip 
Country/Region: Albania 
Managed by: BBB 

Members

NameTypeDescription
 New Object user new object description 
 PC6 computer  
Total: 2 member(s)

COM+

Partition set:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 Computer 
 BUILTIN\Account Operators  Delete child object
Create child object 
 User 
 BUILTIN\Account Operators  Delete child object
Create child object 
 Group 
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Delete child object
Create child object 
 InetOrgPerson 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 28 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

Group policy

Block policy inheritance:  

Group policy settings

NameDisabledOverride
 New Group Policy Object   
Total: 1 group policy(s)

See Also

List of organizational units


Groups


Group: Account Operators

Object

Name: Account Operators 
Path: CN=Account Operators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 12359 
Current USN: 86811 
SID: S-1-5-32-548 
GUID: {162BA1B7-B4D5-4522-B644-99FBDC64F1F7} 

General

Name (pre-Windows 2000): Account Operators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 AAA user Decription 
 Schema Admins group Designated administrators of the schema 
Total: 2 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Administrators

Object

Name: Administrators 
Path: CN=Administrators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 8213 
Current USN: 86240 
SID: S-1-5-32-544 
GUID: {27D1018C-CBDD-4912-957E-11099ED06948} 

General

Name (pre-Windows 2000): Administrators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 IISUser user  
 queue_alias queuealias Description 
 FinanceGroup1 group  
 FinanceContact FirstName Init. Last name contact  
 Contact Mr. Mc Contact contact description 
 Domain Admins group Designated administrators of the domain 
 Enterprise Admins group Designated administrators of the enterprise 
 ADSCRIBE-SERVER computer domain controller description 
 IUSR_ADSCRIBE-SERVER user Built-in account for anonymous access to Internet Information Services 
 Administrator user Built-in account for administering the computer/domain 
Total: 10 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Backup Operators

Object

Name: Backup Operators 
Path: CN=Backup Operators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 8222 
Current USN: 86813 
SID: S-1-5-32-551 
GUID: {5A92BAB2-2DFA-483D-B860-C0C9FF78142E} 

General

Name (pre-Windows 2000): Backup Operators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 FinanceContact FirstName Init. Last name contact  
 BBB user  
 AAA user Decription 
 ExternalGroup group  
 Schema Admins group Designated administrators of the schema 
Total: 5 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Cert Publishers

Object

Name: Cert Publishers 
Path: CN=Cert Publishers,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 02/10/2007 
Original USN: 12338 
Current USN: 79415 
SID: S-1-5-21-2034109091-298619056-3282043246-517 
GUID: {03374580-3F7C-44EA-845D-BE163217E337} 

General

Name (pre-Windows 2000): Cert Publishers 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 FinanceGroup1 group  
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: ddddd

Object

Name: ddddd 
Path: CN=ddddd,CN=Computers,DC=adscribe,DC=com 
Created: 23/09/2007 
Modified: 23/09/2007 
Original USN: 53327 
Current USN: 53327 
SID: S-1-5-21-2034109091-298619056-3282043246-1144 
GUID: {99881626-DF9D-4E38-9D37-FC1CB367744B} 

General

Name (pre-Windows 2000): ddddd 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: DHCP Administrators

Object

Name: DHCP Administrators 
Path: CN=DHCP Administrators,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 8210 
Current USN: 86242 
SID: S-1-5-21-2034109091-298619056-3282043246-1009 
GUID: {61577D09-54D6-4DB1-A1A6-1464E31B7315} 

General

Name (pre-Windows 2000): DHCP Administrators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 ADSCRIBE-SERVER computer domain controller description 
Total: 1 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: DHCP Users

Object

Name: DHCP Users 
Path: CN=DHCP Users,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8209 
Current USN: 8209 
SID: S-1-5-21-2034109091-298619056-3282043246-1008 
GUID: {9B55639E-720F-4680-AB70-0E6618F1BA80} 

General

Name (pre-Windows 2000): DHCP Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: DnsAdmins

Object

Name: DnsAdmins 
Path: CN=DnsAdmins,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 16/09/2007 
Original USN: 12399 
Current USN: 36956 
SID: S-1-5-21-2034109091-298619056-3282043246-1112 
GUID: {4EB722E8-F1AA-4BBA-98C5-FA707C3B9966} 

General

Name (pre-Windows 2000): DnsAdmins 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by: Administrator 
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 BBB user  
Total: 1 member(s)

Security

Owner: NT AUTHORITY\SYSTEM 
Group: NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: DnsUpdateProxy

Object

Name: DnsUpdateProxy 
Path: CN=DnsUpdateProxy,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12404 
Current USN: 12404 
SID: S-1-5-21-2034109091-298619056-3282043246-1113 
GUID: {4F2FA6E6-65EF-4738-BEAC-EA6B11B2238F} 

General

Name (pre-Windows 2000): DnsUpdateProxy 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: NT AUTHORITY\SYSTEM 
Group: NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Domain Admins

Object

Name: Domain Admins 
Path: CN=Domain Admins,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 12341 
Current USN: 87387 
SID: S-1-5-21-2034109091-298619056-3282043246-512 
GUID: {4BC305CA-1BA4-4BD4-B9EB-3A36C57D9972} 

General

Name (pre-Windows 2000): Domain Admins 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of: Administrators 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Domain Computers

Object

Name: Domain Computers 
Path: CN=Domain Computers,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 16/09/2007 
Original USN: 12326 
Current USN: 36945 
SID: S-1-5-21-2034109091-298619056-3282043246-515 
GUID: {FBA3EE65-F645-49E8-8EEB-E8EA2D4E5723} 

General

Name (pre-Windows 2000): Domain Computers 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 ADSCRIBE-SERVER computer domain controller description 
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Domain Controllers

Object

Name: Domain Controllers 
Path: CN=Domain Controllers,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12329 
Current USN: 13975 
SID: S-1-5-21-2034109091-298619056-3282043246-516 
GUID: {3DD979D6-AC27-4E58-A18F-61B0C6C9A5F2} 

General

Name (pre-Windows 2000): Domain Controllers 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Domain Guests

Object

Name: Domain Guests 
Path: CN=Domain Guests,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12347 
Current USN: 12349 
SID: S-1-5-21-2034109091-298619056-3282043246-514 
GUID: {1A93A3F1-7FD2-4986-AFBF-3FD4E0CDB9C1} 

General

Name (pre-Windows 2000): Domain Guests 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of: Guests 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Domain Users

Object

Name: Domain Users 
Path: CN=Domain Users,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 12344 
Current USN: 87388 
SID: S-1-5-21-2034109091-298619056-3282043246-513 
GUID: {0347C861-8993-4C0A-AB5B-972E8053B804} 

General

Name (pre-Windows 2000): Domain Users 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of: Users 

Members

NameTypeDescription
 Administrator user Built-in account for administering the computer/domain 
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Enterprise Admins

Object

Name: Enterprise Admins 
Path: CN=Enterprise Admins,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12335 
Current USN: 13965 
SID: S-1-5-21-2034109091-298619056-3282043246-519 
GUID: {E1D75174-6F1E-4A28-A25C-1BCD09A007C1} 

General

Name (pre-Windows 2000): Enterprise Admins 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of: Administrators 

Members

NameTypeDescription
 Administrator user Built-in account for administering the computer/domain 
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: ExternalGroup

Object

Name: ExternalGroup 
Path: CN=ExternalGroup,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 13961 
Current USN: 87390 
SID: S-1-5-21-2034109091-298619056-3282043246-1127 
GUID: {32FC0F4E-D133-49E8-AC22-009FF93C6709} 

General

Name (pre-Windows 2000): ExternalGroup 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by: Administrator 
Notes:  

Member of

Member Of: Backup Operators 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: FinanceGroup1

Object

Name: FinanceGroup1 
Path: CN=FinanceGroup1,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 07/10/2007 
Original USN: 36985 
Current USN: 86922 
SID: S-1-5-21-2034109091-298619056-3282043246-1140 
GUID: {2357016C-3A54-440A-A9A7-D69C8FDE8CCC} 

General

Name (pre-Windows 2000): FinanceGroup1 
Builtin:  
E-mail:  
Scope: Universal Group 
Type: Distribution 
Managed by: BBB 
Notes: 1200
hour=60 min=
day=24 hours=60*24

days=x/60*24
x=x-60*24*day
hours=x/60
x=x-60*hours 

Member of

Member Of: Cert Publishers, Administrators 

Members

NameTypeDescription
 queue_alias queuealias Description 
 BBB user  
 queue_alias queuealias  
Total: 3 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Group

Object

Name: Group 
Path: CN=Group,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 23/09/2007 
Original USN: 14002 
Current USN: 53349 
SID: S-1-5-21-2034109091-298619056-3282043246-1130 
GUID: {34862615-F4BD-4624-850B-07DFF6B12291} 

General

Name (pre-Windows 2000): Group 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 BBB user  
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Group Policy Creator Owners

Object

Name: Group Policy Creator Owners 
Path: CN=Group Policy Creator Owners,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12350 
Current USN: 12380 
SID: S-1-5-21-2034109091-298619056-3282043246-520 
GUID: {1BA8D93E-F548-4B9B-A7EF-78ADA28AF671} 

General

Name (pre-Windows 2000): Group Policy Creator Owners 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 Administrator user Built-in account for administering the computer/domain 
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Guests

Object

Name: Guests 
Path: CN=Guests,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 20/09/2007 
Original USN: 8219 
Current USN: 45085 
SID: S-1-5-32-546 
GUID: {AFD06032-CBF5-4672-B29E-288E6D8FEA1D} 

General

Name (pre-Windows 2000): Guests 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 Domain Guests group All domain guests 
 WMUS_ADSCRIBE-SERVER user Default account for anonymous access to Windows Media Services 
 Guest user Built-in account for guest access to the computer/domain 
Total: 3 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: HelpServicesGroup

Object

Name: HelpServicesGroup 
Path: CN=HelpServicesGroup,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8201 
Current USN: 8202 
SID: S-1-5-21-2034109091-298619056-3282043246-1000 
GUID: {81F07DBF-7CCE-448A-9EF3-C56108299ABE} 

General

Name (pre-Windows 2000): HelpServicesGroup 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 SUPPORT_388945a0 user This is a vendor's account for the Help and Support Service 
Total: 1 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: IIS_WPG

Object

Name: IIS_WPG 
Path: CN=IIS_WPG,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8204 
Current USN: 8208 
SID: S-1-5-21-2034109091-298619056-3282043246-1005 
GUID: {AD592C46-7ADA-4F50-8DB3-B1D7409EC0A0} 

General

Name (pre-Windows 2000): IIS_WPG 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 S-1-5-20 foreign-security-principal  
 S-1-5-19 foreign-security-principal  
 S-1-5-18 foreign-security-principal  
 IWAM_ADSCRIBE-SERVER user Built-in account for Internet Information Services to start out of process applications 
Total: 4 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Incoming Forest Trust Builders

Object

Name: Incoming Forest Trust Builders 
Path: CN=Incoming Forest Trust Builders,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12365 
Current USN: 12367 
SID: S-1-5-32-557 
GUID: {420E00E4-6BFB-4227-BD0B-3C8AB20AED78} 

General

Name (pre-Windows 2000): Incoming Forest Trust Builders 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Network Configuration Operators

Object

Name: Network Configuration Operators 
Path: CN=Network Configuration Operators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8225 
Current USN: 8225 
SID: S-1-5-32-556 
GUID: {4DEF0985-16C0-4B67-83BD-AB3A90D905A3} 

General

Name (pre-Windows 2000): Network Configuration Operators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Performance Log Users

Object

Name: Performance Log Users 
Path: CN=Performance Log Users,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8227 
Current USN: 8228 
SID: S-1-5-32-559 
GUID: {FBC50DEB-1417-4CFC-B7DA-6F8ABF4E3DE1} 

General

Name (pre-Windows 2000): Performance Log Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 S-1-5-20 foreign-security-principal  
Total: 1 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Performance Monitor Users

Object

Name: Performance Monitor Users 
Path: CN=Performance Monitor Users,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8226 
Current USN: 8226 
SID: S-1-5-32-558 
GUID: {CEF28F66-CEE3-4B98-8485-CC0F09CEED12} 

General

Name (pre-Windows 2000): Performance Monitor Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Pre-Windows 2000 Compatible Access

Object

Name: Pre-Windows 2000 Compatible Access 
Path: CN=Pre-Windows 2000 Compatible Access,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12362 
Current USN: 12381 
SID: S-1-5-32-554 
GUID: {3D17BBD8-ADD7-4805-862D-4BC1AF05F094} 

General

Name (pre-Windows 2000): Pre-Windows 2000 Compatible Access 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 S-1-5-11 foreign-security-principal  
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Print Operators

Object

Name: Print Operators 
Path: CN=Print Operators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8221 
Current USN: 13972 
SID: S-1-5-32-550 
GUID: {12F699B4-A5B4-4FFC-A7F5-F477C076F06A} 

General

Name (pre-Windows 2000): Print Operators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Programmers

Object

Name: Programmers 
Path: CN=Programmers,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13919 
Current USN: 13919 
SID: S-1-5-21-2034109091-298619056-3282043246-1118 
GUID: {CF7479DD-FA9D-4AAE-B755-8C9AD1679E2A} 

General

Name (pre-Windows 2000): Programmers 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: RAS and IAS Servers

Object

Name: RAS and IAS Servers 
Path: CN=RAS and IAS Servers,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12353 
Current USN: 12355 
SID: S-1-5-21-2034109091-298619056-3282043246-553 
GUID: {8ED22436-5532-4667-857F-BA43E1A1DE0F} 

General

Name (pre-Windows 2000): RAS and IAS Servers 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Remote Desktop Users

Object

Name: Remote Desktop Users 
Path: CN=Remote Desktop Users,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8224 
Current USN: 8224 
SID: S-1-5-32-555 
GUID: {E8F93FB0-B717-4A3A-A64C-0F77F35822A3} 

General

Name (pre-Windows 2000): Remote Desktop Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Replicator

Object

Name: Replicator 
Path: CN=Replicator,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8223 
Current USN: 13969 
SID: S-1-5-32-552 
GUID: {2F00A977-A1D0-4F4F-9471-13634320E4AF} 

General

Name (pre-Windows 2000): Replicator 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Schema Admins

Object

Name: Schema Admins 
Path: CN=Schema Admins,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 12332 
Current USN: 86823 
SID: S-1-5-21-2034109091-298619056-3282043246-518 
GUID: {6BFC40E7-ADE2-42E5-AB31-A816EF2ED3EC} 

General

Name (pre-Windows 2000): Schema Admins 
Builtin:  
E-mail:  
Scope: Global Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of: Account Operators, Backup Operators 

Members

NameTypeDescription
 VirtualDomainServer computer virtual server 
 BBB user  
 Contact Mr. Mc Contact contact description 
 Administrator user Built-in account for administering the computer/domain 
Total: 4 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: Server Operators

Object

Name: Server Operators 
Path: CN=Server Operators,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12356 
Current USN: 13968 
SID: S-1-5-32-549 
GUID: {1F377D06-5B6D-42D1-A7E0-8CC31325A4B3} 

General

Name (pre-Windows 2000): Server Operators 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of groups


Group: TelnetClients

Object

Name: TelnetClients 
Path: CN=TelnetClients,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8203 
Current USN: 8203 
SID: S-1-5-21-2034109091-298619056-3282043246-1002 
GUID: {93F955A9-5B89-4C9D-A63B-52E56A3D4A39} 

General

Name (pre-Windows 2000): TelnetClients 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Terminal Server Computers

Object

Name: Terminal Server Computers 
Path: CN=Terminal Server Computers,CN=Users,DC=adscribe,DC=com 
Created: 11/10/2005 
Modified: 11/10/2005 
Original USN: 16390 
Current USN: 16392 
SID: S-1-5-21-2034109091-298619056-3282043246-1132 
GUID: {9627B3D2-0CFA-43B5-BAB3-D742F7EFB633} 

General

Name (pre-Windows 2000): Terminal Server Computers 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: NT AUTHORITY\SYSTEM 
Group: NT AUTHORITY\SYSTEM 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Terminal Server License Servers

Object

Name: Terminal Server License Servers 
Path: CN=Terminal Server License Servers,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12371 
Current USN: 12373 
SID: S-1-5-32-561 
GUID: {A4F54DCB-BC5E-4D6F-BA63-A78F0E18BACB} 

General

Name (pre-Windows 2000): Terminal Server License Servers 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Users

Object

Name: Users 
Path: CN=Users,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8215 
Current USN: 12375 
SID: S-1-5-32-545 
GUID: {5A5FD169-DD71-4FF2-B656-01039AC7C09C} 

General

Name (pre-Windows 2000): Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 Domain Users group All domain users 
 S-1-5-11 foreign-security-principal  
 S-1-5-4 foreign-security-principal  
 ASPNET user Account used for running the ASP.NET worker process (aspnet_wp.exe) 
Total: 4 member(s)

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: Windows Authorization Access Group

Object

Name: Windows Authorization Access Group 
Path: CN=Windows Authorization Access Group,CN=Builtin,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12368 
Current USN: 12383 
SID: S-1-5-32-560 
GUID: {3FC72A7A-7CF4-42F4-B571-8E9D365E74B6} 

General

Name (pre-Windows 2000): Windows Authorization Access Group 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Members

NameTypeDescription
 S-1-5-9 foreign-security-principal  
Total: 1 member(s)

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


Group: WINS Users

Object

Name: WINS Users 
Path: CN=WINS Users,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8211 
Current USN: 8211 
SID: S-1-5-21-2034109091-298619056-3282043246-1010 
GUID: {36791DC7-3833-4B81-A979-FF7A7B31F35A} 

General

Name (pre-Windows 2000): WINS Users 
Builtin:  
E-mail:  
Scope: Domain Local Group 
Type: Security 
Managed by:  
Notes:  

Member of

Member Of:  

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Send To 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 26 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of groups


List of builtin groups

Builtin groups

NameScopeTypeE-mail
 Account Operators Domain Local Group Security  
 Administrators Domain Local Group Security  
 Backup Operators Domain Local Group Security  
 Group Global Group Security  
 Guests Domain Local Group Security  
 Incoming Forest Trust Builders Domain Local Group Security  
 Network Configuration Operators Domain Local Group Security  
 Performance Log Users Domain Local Group Security  
 Performance Monitor Users Domain Local Group Security  
 Pre-Windows 2000 Compatible Access Domain Local Group Security  
 Print Operators Domain Local Group Security  
 Remote Desktop Users Domain Local Group Security  
 Replicator Domain Local Group Security  
 Server Operators Domain Local Group Security  
 Terminal Server License Servers Domain Local Group Security  
 Users Domain Local Group Security  
 Windows Authorization Access Group Domain Local Group Security  
Total: 17 builtin group(s)

See Also

Active Directory overview


List of user groups

User groups

NameScopeTypeE-mail
 Cert Publishers Domain Local Group Security  
 ddddd Global Group Security  
 DHCP Administrators Domain Local Group Security  
 DHCP Users Domain Local Group Security  
 DnsAdmins Domain Local Group Security  
 DnsUpdateProxy Global Group Security  
 Domain Admins Global Group Security  
 Domain Computers Global Group Security  
 Domain Controllers Global Group Security  
 Domain Guests Global Group Security  
 Domain Users Global Group Security  
 Enterprise Admins Global Group Security  
 ExternalGroup Global Group Security  
 FinanceGroup1 Universal Group Distribution  
 Group Policy Creator Owners Global Group Security  
 HelpServicesGroup Domain Local Group Security  
 IIS_WPG Domain Local Group Security  
 Programmers Global Group Security  
 RAS and IAS Servers Domain Local Group Security  
 Schema Admins Global Group Security  
 TelnetClients Domain Local Group Security  
 Terminal Server Computers Domain Local Group Security  
 WINS Users Domain Local Group Security  
Total: 23 user group(s)

See Also

Active Directory overview


Users


User: AAA

Object

Name: AAA 
Path: CN=AAA,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 02/10/2007 
Original USN: 28748 
Current USN: 79365 
SID: S-1-5-21-2034109091-298619056-3282043246-1137 
GUID: {88B8FCB1-AE3E-4EB1-89FF-6CB86A6F9DBF} 

General

Disabled:  
Type: Normal 
Display name: DisplayName 
First name: FirstName 
Last name: LastName 
Initials: Init 
Description: Decription 
Office: Office 
Telephone:
Telephone(other): telefonnumber2, telefonnumber1 
E-mail: 1@email.com 
Web-page: www.webpage.com 
Web-page(other): www.otherwebpage2.com, www.otherwebpage.com 

Address

StreetAddress: Street 
P.O.Box: BOX 
City: Cyty 
State/Province: State/province 
Zip/PostalCode: zip/postalcode 
Country/Region: Afghanistan 

Account

User logon name: AAA@adscribe.com 
User logon name (pre-Windows 2000): PRE2000 
Primary Group: Domain Users 
Member Of: Account Operators, Backup Operators 
Log on to: pcq,pc1 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date: 29/09/2007 

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number: 123 
Static ip address: 0.13.222.209 
Static route: qwqqw, wqwqw, 1111 

Profile

Profile path: profilepath 
Script Path: logonscript 
Local path: \\pc1\conecttofolder 
Connect to: W: 

Telephones

Home: home 
Home(other): home2, home1 
Mobile: mobile 
Mobile(other): mobile2, mobile1 
Fax: fax 
Fax(other): fax2, fax1 
IP phone: ipfone 
IP phone(other): ipfone2, ipfone1 
Notes: st: State/province
title: Organization tittle
description: Decription
postalCode: zip/postalcode
postOfficeBox: BOX
physicalDeliveryOfficeName: Office
telephoneNumber: 1
facsimileTelephoneNumber: fax
givenName: FirstName
initials: Init
distinguishedName: CN=AAA,CN=Users,DC=adscribe,DC=com
instanceType: 4
whenCreated: 10/12/2005 23:15:49
whenChanged: 10/13/2005 07:53:08 

Organisation

Title: Organization tittle 
Department: ord department 
Company: org company 
Manager: Administrator 
Direct reports: Administrator 

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path: c:/terminal service user profile 
Home drive: Z: 
Home directory: //pc1/terminalservicepath 

COM+

Partition set: Current provider does not support returning multiple recordsets from a single execution. 

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session: 10 minutes 
Active session limit: 20 hours  
Idle session limit: 1 day 6 hours 30 minutes 
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from originating client only 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: Administrator

Object

Name: Administrator 
Path: CN=Administrator,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 07/10/2007 
Original USN: 8194 
Current USN: 87389 
SID: S-1-5-21-2034109091-298619056-3282043246-500 
GUID: {49167A66-00E0-45B7-8304-164A2EEF5AA5} 

General

Disabled:  
Type: Normal 
Display name:  
First name:  
Last name:  
Initials:  
Description: Built-in account for administering the computer/domain 
Office:  
Telephone:  
Telephone(other):  
E-mail: administrator@adscribe.com 
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name: administrator_logon@adscribe.com 
User logon name (pre-Windows 2000): Administrator 
Primary Group: Domain Admins 
Member Of: Group Policy Creator Owners, Domain Users, Enterprise Admins, Schema Admins, Administrators 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number: 9189819891891 
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:
Home(other):  
Mobile:
Mobile(other):  
Fax: 34343434334 
Fax(other): 4, 3, 2, 1 
IP phone:
IP phone(other):  
Notes:  

Organisation

Title: Test Engineer 
Department: Testing 
Company: Leadum Software 
Manager: AAA 
Direct reports: FinanceContact FirstName Init. Last name, AAA, Contact Mr. Mc Contact 

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: ASPNET

Object

Name: ASPNET 
Path: CN=ASPNET,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8200 
Current USN: 8200 
SID: S-1-5-21-2034109091-298619056-3282043246-1007 
GUID: {3A2470CD-6F15-4F15-B65E-0A3D1C6534B8} 

General

Disabled:  
Type: Normal 
Display name: ASP.NET Machine Account 
First name:  
Last name:  
Initials:  
Description: Account used for running the ASP.NET worker process (aspnet_wp.exe) 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): ASPNET 
Primary Group: Domain Users 
Member Of: Users 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\Authenticated Users  Read the properties   
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read the properties   
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 27 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: BBB

Object

Name: BBB 
Path: CN=BBB,CN=Users,DC=adscribe,DC=com 
Created: 12/10/2005 
Modified: 29/09/2007 
Original USN: 28791 
Current USN: 65593 
SID: S-1-5-21-2034109091-298619056-3282043246-1138 
GUID: {3A65DB55-0DF9-4A39-9F13-253BFA4AD17F} 

General

Disabled:  
Type: Normal 
Display name: BBB 
First name: BBB 
Last name:  
Initials:  
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region: Albania 

Account

User logon name: BBB@adscribe.com 
User logon name (pre-Windows 2000): BBB 
Primary Group: Domain Users 
Member Of: FinanceGroup1, Group, DnsAdmins, Schema Admins, Backup Operators 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path: C:\terminalServiceProfile 
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program: notepad 
Start in: C:\xxxxx 
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session: 1 minute 
Active session limit: 30 minutes 
Idle session limit: 1 day  
When a session limit is reached or conection is broken: end session 
Allow reconnection: from originating client only 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: External Mr. External

Object

Name: External Mr. External 
Path: CN=External Mr. External,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13955 
Current USN: 13959 
SID: S-1-5-21-2034109091-298619056-3282043246-1126 
GUID: {2F137CF2-A76F-4901-B140-190098AA1E2A} 

General

Disabled:  
Type: Normal 
Display name: External Mr. External 
First name: External 
Last name: External 
Initials: Mr 
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name: external@adscribe.com 
User logon name (pre-Windows 2000): external 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Send As 
 NT AUTHORITY\SELF  Extended access rights  Receive As 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
 NT AUTHORITY\Authenticated Users  Read permissions   
 NT AUTHORITY\Authenticated Users  Read the properties  General Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 42 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: Guest

Object

Name: Guest 
Path: CN=Guest,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8195 
Current USN: 8195 
SID: S-1-5-21-2034109091-298619056-3282043246-501 
GUID: {B647CF73-D833-40A1-8C62-D542049C5268} 

General

Disabled:  
Type: Normal 
Display name:  
First name:  
Last name:  
Initials:  
Description: Built-in account for guest access to the computer/domain 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): Guest 
Primary Group: Domain Guests 
Member Of: Guests 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\Authenticated Users  Read the properties   
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read the properties   
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 27 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: IISUser

Object

Name: IISUser 
Path: CN=IISUser,CN=Users,DC=adscribe,DC=com 
Created: 20/09/2007 
Modified: 20/09/2007 
Original USN: 45088 
Current USN: 45101 
SID: S-1-5-21-2034109091-298619056-3282043246-1142 
GUID: {8AE476C2-32B9-44F9-89B9-F12B312256B4} 

General

Disabled:  
Type: Normal 
Display name: IISUser 
First name: IISUser 
Last name:  
Initials:  
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name: iisuser@adscribe.com 
User logon name (pre-Windows 2000): iisuser 
Primary Group: Domain Users 
Member Of: Administrators 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: InetOrgPerson Init. Last name

Object

Name: InetOrgPerson Init. Last name 
Path: CN=InetOrgPerson Init. Last name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 36990 
Current USN: 36996 
SID: S-1-5-21-2034109091-298619056-3282043246-1141 
GUID: {C850FD52-C3E3-436E-8769-AB38D74AC786} 

General

Disabled:  
Type: Normal 
Display name: InetOrgPerson Init. Last name 
First name: InetOrgPerson 
Last name: Last name 
Initials: Init 
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name: inetorgperson@adscribe.com 
User logon name (pre-Windows 2000): inetorgperson 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Send As 
 NT AUTHORITY\SELF  Extended access rights  Receive As 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
 NT AUTHORITY\Authenticated Users  Read permissions   
 NT AUTHORITY\Authenticated Users  Read the properties  General Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 44 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: IUSR_ADSCRIBE-SERVER

Object

Name: IUSR_ADSCRIBE-SERVER 
Path: CN=IUSR_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 20/09/2007 
Original USN: 8197 
Current USN: 45100 
SID: S-1-5-21-2034109091-298619056-3282043246-1003 
GUID: {B994739D-6CE1-4DF5-AB68-907E13ADF72B} 

General

Disabled:  
Type: Normal 
Display name: Internet Guest Account 
First name:  
Last name:  
Initials:  
Description: Built-in account for anonymous access to Internet Information Services 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): IUSR_ADSCRIBE-SERVER 
Primary Group: Domain Users 
Member Of: Administrators 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: IWAM_ADSCRIBE-SERVER

Object

Name: IWAM_ADSCRIBE-SERVER 
Path: CN=IWAM_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8198 
Current USN: 8198 
SID: S-1-5-21-2034109091-298619056-3282043246-1004 
GUID: {351F292D-6B05-4FC4-ABC2-3B7BBECAEE2F} 

General

Disabled:  
Type: Normal 
Display name: Launch IIS Process Account 
First name:  
Last name:  
Initials:  
Description: Built-in account for Internet Information Services to start out of process applications 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): IWAM_ADSCRIBE-SERVER 
Primary Group: Domain Users 
Member Of: IIS_WPG 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\Authenticated Users  Read the properties   
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read the properties   
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 27 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: krbtgt

Object

Name: krbtgt 
Path: CN=krbtgt,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 12320 
Current USN: 13974 
SID: S-1-5-21-2034109091-298619056-3282043246-502 
GUID: {257C4FA3-6869-4367-890D-4D74CD6CCA22} 

General

Disabled:  
Type: Normal 
Display name:  
First name:  
Last name:  
Initials:  
Description: Key Distribution Center Service Account 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): krbtgt 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Modify owner
Write permissions
Write the properties 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: New Object

Object

Name: New Object 
Path: CN=New Object,OU=TopFinance,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 36939 
Current USN: 36970 
SID: S-1-5-21-2034109091-298619056-3282043246-1139 
GUID: {61B8947A-4A5D-4EC6-944C-BAC475681854} 

General

Disabled:  
Type: Normal 
Display name:  
First name: Pippo 
Last name:  
Initials:  
Description: new object description 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): Pippo 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Send As 
 NT AUTHORITY\SELF  Extended access rights  Receive As 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
 NT AUTHORITY\Authenticated Users  Read permissions   
 NT AUTHORITY\Authenticated Users  Read the properties  General Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 42 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: oneway.com$

Object

Name: oneway.com$ 
Path: CN=oneway.com$,CN=Users,DC=adscribe,DC=com 
Created: 25/09/2007 
Modified: 25/09/2007 
Original USN: 57351 
Current USN: 57354 
SID: S-1-5-21-2034109091-298619056-3282043246-1149 
GUID: {CE826597-299E-42CB-8C4D-4DA15EAB82DD} 

General

Disabled:  
Type: Inter-domain trust 
Display name:  
First name:  
Last name:  
Initials:  
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): oneway.com$ 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: Person Ms. Pirson

Object

Name: Person Ms. Pirson 
Path: CN=Person Ms. Pirson,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13992 
Current USN: 13998 
SID: S-1-5-21-2034109091-298619056-3282043246-1129 
GUID: {F60E6934-EF59-4147-97CE-11AA9DEB10FA} 

General

Disabled:  
Type: Normal 
Display name: Person Ms. Pirson 
First name: Person 
Last name: Pirson 
Initials: Ms 
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name: pirson@adscribe.com 
User logon name (pre-Windows 2000): pirson 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Send As 
 NT AUTHORITY\SELF  Extended access rights  Receive As 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
 NT AUTHORITY\Authenticated Users  Read permissions   
 NT AUTHORITY\Authenticated Users  Read the properties  General Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 42 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: supplier01-int$

Object

Name: supplier01-int$ 
Path: CN=supplier01-int$,CN=Users,DC=adscribe,DC=com 
Created: 25/09/2007 
Modified: 25/09/2007 
Original USN: 57346 
Current USN: 57349 
SID: S-1-5-21-2034109091-298619056-3282043246-1148 
GUID: {36A5639C-0E66-4134-ADCC-01E19799D65B} 

General

Disabled:  
Type: Inter-domain trust 
Display name:  
First name:  
Last name:  
Initials:  
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): supplier01-int$ 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Domain Admins  Write the properties  Account Restrictions 
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Delete child object
Create child object 
  
 BUILTIN\Print Operators  Delete child object
Create child object 
 PrintQueue 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 NT AUTHORITY\SELF  Validate property  ServicePrincipalName 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  DNSHostName 
 ADSCRIBE\Domain Admins  Validate property  ServicePrincipalName 
 ADSCRIBE\Domain Admins  Write the properties  SAMAccountName 
 ADSCRIBE\Domain Admins  Write the properties  Logon Information 
 ADSCRIBE\Domain Admins  Write the properties  Description 
 ADSCRIBE\Domain Admins  Write the properties  DisplayName 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 39 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: SUPPORT_388945a0

Object

Name: SUPPORT_388945a0 
Path: CN=SUPPORT_388945a0,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8196 
Current USN: 8196 
SID: S-1-5-21-2034109091-298619056-3282043246-1001 
GUID: {62C83D6A-444F-49F1-9AF7-F52E13349BC0} 

General

Disabled:  
Type: Normal 
Display name: CN=Microsoft Corporation,L=Redmond,S=Washington,C=US 
First name:  
Last name:  
Initials:  
Description: This is a vendor's account for the Help and Support Service 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): SUPPORT_388945a0 
Primary Group: Domain Users 
Member Of: HelpServicesGroup 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\Authenticated Users  Read the properties   
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read the properties   
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 27 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


User: VUSR_ADSCRIBE-SERVER

Object

Name: VUSR_ADSCRIBE-SERVER 
Path: CN=VUSR_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created: 11/10/2005 
Modified: 11/10/2005 
Original USN: 20498 
Current USN: 20501 
SID: S-1-5-21-2034109091-298619056-3282043246-1133 
GUID: {2BEDDF1D-F34A-438A-89DE-FC550A3C6F57} 

General

Disabled:  
Type: Normal 
Display name: VSA Server Account 
First name:  
Last name:  
Initials:  
Description: Cuenta para los componentes de servidor de Visual Studio Analyzer 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): VUSR_ADSCRIBE-SERVER 
Primary Group: Domain Users 
Member Of:  
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Send As 
 NT AUTHORITY\SELF  Extended access rights  Receive As 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Personal Information 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Phone and Mail Options 
 NT AUTHORITY\SELF  Write the properties
Read the properties 
 Web Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Remote Access Information 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Account Restrictions 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Group Membership 
 NT AUTHORITY\Authenticated Users  Read permissions   
 NT AUTHORITY\Authenticated Users  Read the properties  General Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Personal Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Web Information 
 NT AUTHORITY\Authenticated Users  Read the properties  Public Information 
 Everyone  Extended access rights  Change Password 
 ADSCRIBE\RAS and IAS Servers  Read the properties  Logon Information 
 ADSCRIBE\Cert Publishers  Write the properties
Read the properties 
 UserCertificate 
 BUILTIN\Windows Authorization Access Group  Read the properties  TokenGroupsGlobalAndUniversal 
 BUILTIN\Terminal Server License Servers  Write the properties
Read the properties 
 TerminalServer 
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 42 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of users


User: WMUS_ADSCRIBE-SERVER

Object

Name: WMUS_ADSCRIBE-SERVER 
Path: CN=WMUS_ADSCRIBE-SERVER,CN=Users,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 8199 
Current USN: 8199 
SID: S-1-5-21-2034109091-298619056-3282043246-1006 
GUID: {8C692548-3019-495B-BA5C-03F4FE22D4EE} 

General

Disabled:  
Type: Normal 
Display name: Windows Media Services Guest Account 
First name:  
Last name:  
Initials:  
Description: Default account for anonymous access to Windows Media Services 
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Account

User logon name:  
User logon name (pre-Windows 2000): WMUS_ADSCRIBE-SERVER 
Primary Group: Domain Users 
Member Of: Guests 
Log on to: All computers 
Account is locked out:  
User must change password at next logon??:  
User cannot change password:  
Password never expired:  
Store password using reversible encryption:  
Account is disabled:  
Smart card is required for interactive logon:  
Account is trusted for delegation:  
Account is sensitive and cannot be delegated:  
Use DES encryption types for this account:  
Do not require Kerberos preauthentication:  
Account expires:  
Account expiration date:  

Logon hours

Day123456789101112131415161718192021222324
Sun                         
Mon                         
Tue                         
Wed                         
Thu                         
Fri                         
Sat                         

Dial-in

Allowed:  
Verify caller ID:  
Calling station ID(s):  
Callback number:  
Static ip address:  
Static route:  

Profile

Profile path:  
Script Path:  
Local path:  
Connect to:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title:  
Department:  
Company:  
Manager:  
Direct reports:  

Remote control

Enabled:  
Require user permission:  
View user session:  
Interract user session:  

Terminal service

Logon allowed:  
Profile path:  
Home drive:  
Home directory:  

COM+

Partition set:  

Enviroment

Initial program:  
Start in:  
Connect client drives at logon:  
Connect client printers at logon:  
Default to main printer:  

Session

End a disconnected session:  
Active session limit:  
Idle session limit:  
When a session limit is reached or conection is broken: disconnect from session 
Allow reconnection: from any client 

Security

Owner: BUILTIN\Administrators 
Group: BUILTIN\Administrators 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\SELF  Extended access rights  Change Password 
 Everyone  Extended access rights  Change Password 
 NT AUTHORITY\Authenticated Users  Read the properties   
 BUILTIN\Account Operators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Administrators  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SELF  Read the properties   
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 27 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone ADS_RIGHT_ACCESS_SYSTEM_SECURITY
Write permissions
Read permissions
Delete an object 
   
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of users


Contacts


Contact: Contact Mr. Mc Contact

Object

Name: Contact Mr. Mc Contact 
Path: CN=Contact Mr. Mc Contact,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 16/09/2007 
Original USN: 13990 
Current USN: 36978 
GUID: {CCA799E3-04CB-46A8-AC71-32CD9BA0C7E6} 

General

Display name: display name 
First name: FirstName 
Last name: Lastname 
Initials: Init 
Description: description 
Office: ofice 
Telephone: Telephone 
Telephone(other): telephone2, telephone1 
E-mail: email 
Web-page: webpage 
Web-page(other): webpage2, webpage1 

Address

StreetAddress: Stret dsdsdsds 
P.O.Box: pobox 
City: city 
State/Province: state/province 
Zip/PostalCode: zip 
Country/Region: American Samoa 

Telephones

Home: home phone 
Home(other): home phone2, home phone1 
Mobile: mobile 
Mobile(other): mobile2, mobile1 
Fax: fax 
Fax(other): fax2, fax1 
IP phone: ipphone 
IP phone(other): ipphone2, ipphone1 
Notes: select case (Host.ContextObject.Properties("DEPENDENTTYPE").Value)
case "V" :strName="VIEW"
case "T" :strName="TABLE"
case "P" :strName="PROCEDURE"
case "PG" :strName="PACKAGE"
case "IX" :strName="INDEX"
case "F" :strName="FUNCTION"
case "TR" :strName="TRIGGERr"
case "S" :strName="MATERIALISED VIEW"
case "I" :strName="INDEX"
case "N" :strName="NICKNAME"
case "A" :strName="ALIAS"
case "SH" :strName="SCHEMA"
case "SQ" :strName="SEQUENCE"
case "TBS" :strName="TABLESPACE"
case "DB" :strName="DATABASE"
end select
Host.returnValue=strName 

Organisation

Title: Tittle 
Department: department 
Company: company 
Manager: Administrator 
Direct reports:  

Member of

Member Of: Schema Admins, Administrators 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of contacts


Contact: FinanceContact FirstName Init. Last name

Object

Name: FinanceContact FirstName Init. Last name 
Path: CN=FinanceContact FirstName Init. Last name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 03/10/2007 
Original USN: 36982 
Current USN: 79677 
GUID: {64B5C1DA-383D-495D-8000-56170E12A9C5} 

General

Display name: Display name 
First name: FinanceContact FirstName 
Last name: Last name 
Initials: Init 
Description:  
Office:  
Telephone:  
Telephone(other):  
E-mail:  
Web-page:  
Web-page(other):  

Address

StreetAddress:  
P.O.Box:  
City:  
State/Province:  
Zip/PostalCode:  
Country/Region:  

Telephones

Home:  
Home(other):  
Mobile:  
Mobile(other):  
Fax:  
Fax(other):  
IP phone:  
IP phone(other):  
Notes:  

Organisation

Title: title 
Department:  
Company:  
Manager: Administrator 
Direct reports:  

Member of

Member Of: Backup Operators, Administrators 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Administrators  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Enumerate an object   
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Remote Access Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  General Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Group Membership 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Account Restrictions 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read the properties  Logon Information 
 BUILTIN\Pre-Windows 2000 Compatible Access  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read the properties  TokenGroups 
Total: 22 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 2 audit permission(s)

See Also

List of contacts


Shared folders


Shared folder: folder1

Object

Name: folder1 
Path: CN=folder1,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 36983 
Current USN: 37009 
GUID: {D24D0179-79A7-4868-8954-36E764BB8D35} 

General

Description: Description 
UNC name: \\server\path 
Managed by: Administrator 
Keywords: keyword3, keyword2, keywrord1 

See Also

List of folders


Shared folder: Share1

Object

Name: Share1 
Path: CN=Share1,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 14000 
Current USN: 14000 
GUID: {EAA66918-3132-4EAF-B34B-DE282247629B} 

General

Description:  
UNC name: \\pdcn\share 
Managed by:  
Keywords:  

See Also

List of folders


Printers


Printer: Printer display name

Object

Name: Printer display name 
Path: CN=Printer display name,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 37017 
Current USN: 37023 
GUID: {E345D4A2-B53E-4AFE-AE89-381E38904B48} 

General

Printer name: printer 
Location: printer location 
Model: HPLaserJet 
Color:  
Staple:  
Double-sided:  
Printing speed: 20 
Maximim resoltion: 600 
Managed by: Administrator 

See Also

List of printers


MSMQ queue aliases


MSMQ queue alias: queue_alias

Object

Name: queue_alias 
Path: CN=queue_alias,CN=ForeignSecurityPrincipals,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 13999 
Current USN: 13999 
GUID: {6079A97B-E4EF-4E87-8465-96D56B29E3D0} 

General

Description:  
Format name: DIRECT=os:comp\private$\q3 
Member Of: FinanceGroup1 

See Also

List of MSMQ queue aliases


MSMQ queue alias: queue_alias

Object

Name: queue_alias 
Path: CN=queue_alias,OU=Finance,OU=Accounting,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 36999 
Current USN: 37013 
GUID: {4725028E-9A47-40D8-852B-7A60180CBC4F} 

General

Description: Description 
Format name: DIRECT=os:comp1\private$\q1 
Member Of: FinanceGroup1, Administrators 

See Also

List of MSMQ queue aliases


Sites


Site: SomeSite

Object

Name: SomeSite 
Path: CN=SomeSite,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 17/09/2007 
Original USN: 4112 
Current USN: 37058 
GUID: {C82F38B8-CD26-4E22-8327-4649B560762B} 

General

Description: Site description 
Location: site location 

Servers

NameDescription
 ADSCRIBE-SERVER site server description 
Total: 1 server(s)

Subnets

NameDescriptionLocation
 10.14.208.0/20 Subne1 New York 
Total: 1 subnet(s)

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)

Group policy

Block policy inheritance:  

Group policy settings

NameDisabledOverride
 Site Group Policy   
 Site Group Policy 2   
Total: 2 group policy(s)

See Also

List of sites

Servers


Server: ADSCRIBE-SERVER

Object

Name: ADSCRIBE-SERVER 
Path: CN=ADSCRIBE-SERVER,CN=Servers,CN=SomeSite,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 25/09/2007 
Original USN: 4417 
Current USN: 57372 
GUID: {62135401-DA8E-4C3B-A8EE-74D066504D83} 

General

Description: site server description 
Inter-site data transfer transports: SMTP, IP 
Server reference: ADSCRIBE-SERVER 
DNS hostname: adscribe-server.adscribe.com 

See Also

List of servers


Subnets


Subnet: 10.14.208.0/20

Object

Name: 10.14.208.0/20 
Path: CN=10.14.208.0/20,CN=Subnets,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 20/09/2007 
Original USN: 13989 
Current USN: 49167 
GUID: {D986E11C-307C-4CE7-9939-4DD49E1F0095} 

General

Description: Subne1 
Location: New York 

See Also

List of subnets



Inter-site transports


Inter-site transport: IP

Object

Name: IP 
Path: CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 23/09/2007 
Original USN: 4109 
Current USN: 53311 
GUID: {0E308A99-144B-434D-A010-DF9DE492A3E7} 

General

Description: ip inter site transport 
Ignore schedules: ?????? 
Bridge all site links: ?????? 

Site links

NameDescriptionCostReplication interval
 DEFAULTIPSITELINK default site link 100 180 
 SITELINK2 site link 2 100 180 
Total: 2 site link(s)

Site link bridges

NameDescription
 SiteLinkBridge site link bridge 
Total: 1 site link bridge(s)

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)

See Also

List of inter-site transports

Site links


Site link: DEFAULTIPSITELINK

Object

Name: DEFAULTIPSITELINK 
Path: CN=DEFAULTIPSITELINK,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 23/09/2007 
Original USN: 4110 
Current USN: 53318 
GUID: {10608ADC-3DD4-471D-B143-A57A5657584B} 

General

Description: default site link 
Ignore schedules:  
Bridge all site links:  

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)

See Also

List of site links


Site link: SITELINK2

Object

Name: SITELINK2 
Path: CN=SITELINK2,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 23/09/2007 
Modified: 23/09/2007 
Original USN: 53314 
Current USN: 53317 
GUID: {4E97D919-7160-42CE-AF63-92E6268853EA} 

General

Description: site link 2 
Ignore schedules:  
Bridge all site links:  

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)

See Also

List of site links


Site link bridges


Site link bridge: SiteLinkBridge

Object

Name: SiteLinkBridge 
Path: CN=SiteLinkBridge,CN=IP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 23/09/2007 
Modified: 23/09/2007 
Original USN: 53315 
Current USN: 53316 
GUID: {E8087405-11F8-4B12-8A4B-A361C9829708} 

General

Description: site link bridge 
Site links: SITELINK2, DEFAULTIPSITELINK 

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)


Inter-site transport: SMTP

Object

Name: SMTP 
Path: CN=SMTP,CN=Inter-Site Transports,CN=Sites,CN=Configuration,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 23/09/2007 
Original USN: 4111 
Current USN: 53313 
GUID: {5388369E-9BB7-4FB5-824A-5B8FB423C4DF} 

General

Description: smtpintersite transport 
Ignore schedules: ?????? 
Bridge all site links: ?????? 

Security

Owner: ADSCRIBE\Enterprise Admins 
Group: ADSCRIBE\Enterprise Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
 NT AUTHORITY\SYSTEM  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Full control
Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
Extended access rights
List a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Create child object 
  
Total: 5 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Delete an object
Delete a tree of objects
Delete child object
Create child object 
   
 Everyone Extended access rights  NTDSDSA  
 Everyone Write the properties  Site GPLink 
 Everyone Write the properties  Site GPOptions 
 Everyone Write the properties  Subnet SiteObject 
Total: 5 audit permission(s)

See Also

List of inter-site transports


Group polices


Group policy: Default Domain Controllers Policy

Object

Name: {6AC1786C-016F-11D2-945F-00C04fB984F9} 
Path: CN={6AC1786C-016F-11D2-945F-00C04fB984F9},CN=Policies,CN=System,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 22/09/2007 
Original USN: 4319 
Current USN: 53268 
GUID: {10B4A858-48E6-4202-8B6B-9B90731743E0} 

General

Display name: Default Domain Controllers Policy 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Total: 8 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of group polices


Group policy: Default Domain Policy

Object

Name: {31B2F340-016D-11D2-945F-00C04FB984F9} 
Path: CN={31B2F340-016D-11D2-945F-00C04FB984F9},CN=Policies,CN=System,DC=adscribe,DC=com 
Created: 10/10/2006 
Modified: 10/10/2006 
Original USN: 4316 
Current USN: 12513 
GUID: {4E7F1770-CC3D-4689-85A2-E262013B78A2} 

General

Display name: Default Domain Policy 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Admins 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Total: 8 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of group polices


Group policy: New Group Policy Object

Object

Name: {389837ED-E82B-430A-BD5D-B63650F65943} 
Path: CN={389837ED-E82B-430A-BD5D-B63650F65943},CN=Policies,CN=System,DC=adscribe,DC=com 
Created: 16/09/2007 
Modified: 16/09/2007 
Original USN: 36958 
Current USN: 36964 
GUID: {C5C1CC02-994B-4396-8414-AB12A0728D40} 

General

Display name: New Group Policy Object 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Total: 8 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of group polices


Group policy: Site Group Policy

Object

Name: {971DBFF7-DD86-46DE-BAB4-8792539BC315} 
Path: CN={971DBFF7-DD86-46DE-BAB4-8792539BC315},CN=Policies,CN=System,DC=adscribe,DC=com 
Created: 17/09/2007 
Modified: 17/09/2007 
Original USN: 37035 
Current USN: 37043 
GUID: {E3A5F827-0868-4211-9A1A-ACC024A3DED6} 

General

Display name: Site Group Policy 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Total: 8 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of group polices


Group policy: Site Group Policy 2

Object

Name: {5DC08DC4-8E46-438E-BEE2-E09BC30A03A7} 
Path: CN={5DC08DC4-8E46-438E-BEE2-E09BC30A03A7},CN=Policies,CN=System,DC=adscribe,DC=com 
Created: 17/09/2007 
Modified: 17/09/2007 
Original USN: 37051 
Current USN: 37057 
GUID: {50A25424-CE3B-48E7-B03B-D6AA2F5E8E7E} 

General

Display name: Site Group Policy 2 

Security

Owner: ADSCRIBE\Domain Admins 
Group: ADSCRIBE\Domain Users 
Allow inheritable permissions from parent:  

Security permissions

TrusteeAllowAccessInheretedChildren
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Enterprise Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 ADSCRIBE\Domain Admins  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 CREATOR OWNER  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\SYSTEM  Modify owner
Write permissions
Read permissions
Delete an object
List a tree of objects
Delete a tree of objects
Write the properties
Read the properties
Validate property
Enumerate an object
Delete child object
Create child object 
  
 NT AUTHORITY\Authenticated Users  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
 NT AUTHORITY\Authenticated Users  Extended access rights  Apply Group Policy 
 NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS  Read permissions
List a tree of objects
Read the properties
Enumerate an object 
  
Total: 8 security permission(s)

Audit permissions

TrusteeAccessInheretedChildrenAttribute
 Everyone Write permissions
Write the properties 
 GroupPolicyContainer  
 Everyone Write the properties  OrganizationalUnit GPLink 
 Everyone Write the properties  OrganizationalUnit GPOptions 
Total: 3 audit permission(s)

See Also

List of group polices



About

Documentation details

Customer:  
Project:  
Created: 09/10/2007 
Generator: ADScribe