Showing posts with label LIZA. Show all posts
Showing posts with label LIZA. Show all posts

March 6, 2013

How to View Active Directory Permissions

Active Directory permissions store and protect Active Directory objects from unauthorized access, and enable IT administrators to precisely control who has access to what in Active Directory.

Active Directory permissions are specified in Active Directory ACLs and IT admins often have a need to be able to view, analyze and export Active Directory permissions, whether to analyze access grants, or to lock down Active Directory access or to control access to Active Directory content.

How to View Active Directory Permissions

The default view to view Active Directory permissions is via the Security Tab that can be accessed by right-clicking on objects in Active Directory Users and Computers Snap-In or in the Active Directory Administrative Center Console.

However, it can be a challenge to view and analyze Active Directory permissions using the Security Tab, because it unfortunately does not provide a complete and easily analyzable view of the ACL of the Active Directory object -

Active Directory Advanced Permissions

For example, the most common problem with it is that it is very difficult to find out exactly which security permissions are granted by which access control entries (ACEs) in the ACL, and that makes it very difficult to analyze Active Directory permissions, especially when you are trying to find out who is delegated what access on an Active Directory object, or when performing an Active Directory delegation audit.

This information can also be obtained using other Microsoft security tools such as dsacls, but even with dsacls, it is not easy to get an easily sortable breakdown of all the permissions granted by each ACE in an object's Active Directory object's ACL. There are also some 3rd party tools like LIZA that provide an advanced view, but they do not provide a break down of all the individually possible permissions in an Active Directory object's ACL.

How to Easily View Active Directory Permissions

With our Gold Finger Microsoft Active Directory Audit Tool, IT administrators can now instantly view, analyze and export ACLs with unmatched ease and clarity, as well as obtain detailed views of the individual permissions granted in Active Directory ACLs -

Active Directory ACL / Permissions Viewer

The ability to view the ACL in its entirety makes it much easier to analyze ACLs and permissions, and the availability of the detailed view makes it very easy to identify which ACEs in the ACL end up granting a specific permission type, such as Extended Rights permissions, or Write Property permissions.

This information is also often needed when performing an Active Directory delegation audit, or when relying on an Active Directory Audit Checklist to perform an Active Directory Audit.

Armed with this information, IT admins can easily and instantly analyze Active Directory ACLs and make accurate and well-informed decisions based on clear and detailed insight into all aspects of access rights granted in an Active Directory object's ACL.

For more information on the Active Directory ACL Viewer capabilities of our Gold Finger audit tool for Active Directory, including a free 21-day trial, please visit - http://www.paramountdefenses.com/products/active-directory-audit-tool/capabilities/acl-viewer-and-exporter.html.

September 17, 2012

How to View and Analyze Active Directory (AD) Object ACLs Using Gold Finger

In this blog, as we begin coverage of how to view and analyze Active Directory security permissions, ACLs and SACLs, we will make extensive use of the Gold Finger Active Directory Security/ACL/SACL Viewer Tool. It would thus be helpful to have a basic understanding of how to use Gold Finger's automated Active Directory security permissions/ACL/SACL viewing and analysis capabilities.

How to View and Analyze Active Directory (AD) Object ACLs Using Gold Finger

The following is thus a brief demo that shows how to use Gold Finger to view and analyze Active Directory security permissions, ACLs and SACLs.







In addition to being able to view and analyze Active Directory security permissions/rights, ACLs and SACLs, Gold Finger can also generate Active Directory delegated access reports that show you who is delegated what access where and how.

Once you have gained familiarity with how to use Gold Finger to view and analyze Active Directory security rights/permissions, ACLs and SACLs, it will be much easier to follow various examples that we shall share as we cover this subject.


The WikiLeaks Security Incident and the lastest Anonymous Cyber-Attacks on Israel all demonstrate the importance of cyber security and IT security today. When it comes to the security of the IT infatructures of organization, Active Directory is at the foundation of their security and thus is mission-critical to global security today. In fact, the most the Most Powerful and Expensive Weapon in the World is related to Active Directory security as well.

August 31, 2012

How to View and Analyze Active Directory ACLs and SACLs

Active Directory stores and protects critical IT resources like user and computer accounts, passwords, security groups and security policies, which are stored in the form of Active Directory objects.



Each Active Directory object is secured by the means of a security descriptor, which is comprised of a discretionary access control list (ACL) an System Access Control List (SACL), a Group field and an Owner field. Each ACL in turn contains many access control entries (ACEs). Each ACE specifies some security permissions for some security principal (e.g. user, computer, group, well-known principals.)

In order to maintain security, IT personnel often need to be able to analyze Active Directory ACLs such as to find out and lock down who is granted what access on individual Active Directory objects.

ACL Editor in Active Directory Users and Computers

The default way to view Active Directory ACLs is via the ACL Editor/Viewer that is built into the Microsoft Active Directory Users and Computers tool -



 
Unfortunately, the view available in the ACL Editor is substantially insufficient to perform any kind of Active Directory ACL analysis because one is unable to view the individual elements of the access control entires (ACEs) that comprise the ACL of the Active Directory object.


DSACLs to Analyze Active Directory ACLs
 
The Microsoft command-line tool DSACLS provide some additional detail that is somewhat useful in performing Active Directory ACL analysis, but it is still cumbersome because you need to export the contents to perform any useful analysis and even then, it does not break down the individual permissions contained in the access mask field, so you have to do that manually, which can be time consuming, and prone to error.
 
 

Scripts to Analyze Active Directory ACLs
 
It is also not very easy to write scripts to try and analyze Active Directory ACLs, because detailed ACL analysis involves looking into the security mask of all ACEs, analyzing analyzing flags, resolving SIDs, etc. In addition, because there can be multiple permissions specified in a single ACE, determining which ACEs grant which permissions can be complicated.

Performing all of these steps can take a very long time, involve a lot of effort and knowledge. As a result, analyzing Active Directory ACLs in detail can be difficult for most IT personnel.

 
A Dedicated and Automated ACL Analysis Tool
 
In this blog, we will take a look at how to use a dedicated and automated, advanced Active Directory ACL Viewer and ACL Analysis Tool to easily and efficiently analyze Active Directory ACLs.





A dedicated ACL Analysis Tool can help easily analyze Active Directory ACLs. and look into every field of an object's ACL, including the individual permissions specified in every ACE.



With a dedicated Active Directory ACL Analysis Tool, IT personnel have the ability to instantly analyze the ACL of any Active Directory object in any partition, and use this information to identify security vulnerabilities, as well as lock down and maintain secure access to Active Directory content.

- Andrew