Skip to main content

Admin Account Management

Purpose

This document outlines multiple solutions that can be used to manage local and domain admins.

Associated Content

Windows Local Admin Process

ContentTypeFunction
Windows Local Admin ProcessSolutionThis solution aims to establish a centralized local admin user for each client or computer
Windows Local Admin Account ProcessInternal MonitorDetects the machine with missing or outdated credentials.
Windows - Admin Account - Create/UpdateScriptCreate/Update the user.
△ CUSTOM - Execute Script - Windows - Admin Account - Create/UpdateAlert TemplateExecute the script against the machines detected by the internal monitor.
Windows - Admin Account Password Rotation NotificationClient ScriptThis script sets the Ticket Creation or email sent for the password update made by the script 'Windows - Admin Account - Create/Update'

Windows Domain Admin Process

ContentTypeFunction
Windows Domain Admin ProcessSolutionThis solution aims to establish a centralized domain admin for each domain.
Windows Domain Admin Account ProcessInternal MonitorDetects the domain controller with missing or outdated credentials.
Windows - Admin Account - Create/UpdateScriptCreate/Update the user.
△ CUSTOM - Execute Script - Windows - Admin Account - Create/UpdateAlert TemplateExecute the script against the machines detected by the internal monitor.

Local Admin Group Cleanup

ContentTypeFunction
Local Admin Group CleanupSolutionThe purpose of the solution is to manage the members in the local admin group for the Windows machines.
Local Admin Group Cleanup - Add/RemoveScriptManage the addition and removal of members from the local admin group.
Local Admin Group CleanupInternal MonitorDetects Windows computers where the local admin group cleanup process is enabled, but the script has not been executed in the past 7 days.
△ Custom - Local Admin Group CleanupAlert TemplateRun the script against the computers detected by the internal monitor.

New Local Admin Monitor

ContentTypeFunction
New Local Admin Monitor - CreateScriptThe script generates remote monitors that trigger an alert when a user or group of users are promoted as local administrators on the endpoint machine.

New Domain Admin Monitor

ContentTypeFunction
New Domain Admin Monitor - CreateScriptThe script generates remote monitors that trigger an alert when a user or group of users are promoted as domain administrators on a Windows domain controller.

Implementation

  1. Please carefully review the solution documents for importation before implementation.