Back to all recipes
Level: JuniorLast updated:
Recursive report: who really is in Domain Admins
Get-ADGroupMember -Identity "Domain Admins" -Recursive |
Get-ADUser -Properties LastLogonDate,Enabled |
Select-Object Name,SamAccountName,Enabled,LastLogonDate | Sort-Object NameWhy it works this way
Nested groups hide members. -Recursive reveals those who got in through a group inside a group.
Watch out
- In a healthy org the list is short — up to 5 dedicated accounts.
- A service account in Domain Admins is a finding to fix, not to document.