Aloha,
I regularly view and export NTFS permissions from various server and NetApp shared folders using Hyena so that we can audit shared folder access, and it works fine using a Domain Admin account. However, I am not a Domain Admin, and I normally have to borrow the account temporarily, which is very risky since I could also use the DA account to make changes to Active Directory and servers.
I am wondering what type of account Hyena needs to use to just view and export NTFS permissions from a domain, and if there is a lesser type of account I could use to runas Hyena from my PC, such as a shared local admin server account, or something similar.
Once I hear back, I will work with my server team to see if they can implement a lesser account on the servers, so that I don't have to use the DA account anymore going forward.
thank you,
Mike Howard
Information Security
I regularly view and export NTFS permissions from various server and NetApp shared folders using Hyena so that we can audit shared folder access, and it works fine using a Domain Admin account. However, I am not a Domain Admin, and I normally have to borrow the account temporarily, which is very risky since I could also use the DA account to make changes to Active Directory and servers.
I am wondering what type of account Hyena needs to use to just view and export NTFS permissions from a domain, and if there is a lesser type of account I could use to runas Hyena from my PC, such as a shared local admin server account, or something similar.
Once I hear back, I will work with my server team to see if they can implement a lesser account on the servers, so that I don't have to use the DA account anymore going forward.
thank you,
Mike Howard
Information Security
Comment