Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 26, 2007

Keep Tabs on Your Administrative Group Memberships


RSS
View this exclusive article with VIP access -- click here to join | See More Active Directory (AD) Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

Download the Code Here

I wrote a script, SecuritySnapShot.vbs, that takes a daily snapshot of key administrative groups and reports any changes to the membership of those groups. This script is easy to customize and use.

Customizing the Script
SecuritySnapShot.vbs monitors the groups you specify. Listing 1 shows an excerpt from this script. (You can download the entire script by clicking the Download the Code Here button.) As callout B in Listing 1 shows, the script is currently set up to monitor eight administrative groups, including Enterprise Admins, Schema Admins, and Domain Admins. Because the groups are defined within the code (i.e., hard-coded), it’s easy to add or remove groups as needed. You simply need to change the entries in the condit variable. The script then uses this variable in an Active Directory (AD) query, as callout C shows.

To determine whether there have been any changes to the groups' memberships, SecuritySnapShot.vbs looks back up to 31 days for previous snapshot files. You can increase or decrease this time span by simply changing the value of the x variable, which callout A in Listing 1 shows.

Using the Script
Here's an overview of how SecuritySnapShot.vbs works. When you run this script, it iterates through the collection returned by the AD query and writes each group's members to a text file, which I'll refer to as the snapshot file. The script saves this file to the C:\Temp directory, using a filename that consists of the domain's name and the current date (e.g., MyDomain12-4-2006.txt). If C:\Temp doesn’t exist on your PC, you need to either create the C:\Temp folder or change the script so that it points to another folder. Similarly, you can change the script so that it points to another folder if you want to save the snapshot file to a more secure location.

After creating the snapshot file, the script checks to see whether there’s a previous snapshot file. It searches as far back as 31 days, assuming you didn't change this default value. When the script doesn't find a previous snapshot file (i.e., it’s the first time the script is run or the script hasn't been run in the past 31 days), the script creates a Microsoft Excel spreadsheet. In the spreadsheet, the script adds a worksheet for each specified group and lists the group's members in that worksheet. When the script finds a previous snapshot file, it compares the current snapshot file with the previous snapshot file. The script then creates a spreadsheet that not only documents the current and previous membership information for each group but also summarizes the changes that have occurred.

People say that a picture is worth a thousand words, so let's look at some pictures of sample worksheets so that you know how to interpret the script's results. Let's say that you run SecuritySnapShot.vbs for the first time. Figure 1 and Figure 2 show sample output from this run. Figure 1, which contains the results for the Domain Admins group, shows the output in its simplest form. As column A shows, this group has three members: Administrator, Lanier, and Rene. You might be wondering about the purpose of column B. To answer that question, take a look at Figure 2, which shows the results for the Administrators group. Note that the Administrators group contains other groups. The strings in column B clearly identify nested groups by specifying the parent group followed by the child group, as cell B1 in Figure 2 shows. When the member is an account (Administrator or user) in a nested group, the account's name is listed after the parent.child group information, as cell B2 shows. So, with a single glance at column B, you know whether a group member is an account, a nested group, or an account in a nested group.

The worksheet tabs are color coded according to what a group contains. A blue tab indicates there are nested groups within a group. A gray tab tells you that there are only accounts as members. A red tab denotes that there are no members in the group or a group that was previously in the AD query was removed.

Let's say that after you run SecuritySnapShot.vbs, you add a user named Mike Boone (MikeB) to the Administrators group. When you run the script again, the script adds a worksheet named Differences, as Figure 3 shows. In this worksheet, Column A tells you that this account didn't previously exist. The group name (i.e., Administrators) is repeated in column B because you added the user to the parent group. The Administrators group might easily be a member of another group, such as Enterprise Admins. In that case, the entry would read Enterprise Admins~Administrators~MikeB.

Besides highlighting group-membership changes in the Differences worksheet, the script also provides a now and then comparison in the group worksheets. For example, Figure 4 shows the Administrators worksheet after Mike Boone was added to the Administrators group. As you can see, MikeB appears in the Administrators group on December 9 but not on December 7.

Let's now look at what happens when a member of a group is deleted. Let's say that you not only add Mike Boone to the Administrators group but also remove Lanier Collins from the Domain Admins and Administrators groups because he left the company. Figure 5 shows the Differences worksheet. Figure 6 shows the now and then comparison in the Domain Admins worksheet. Figure 7 shows the same type of comparison in the Administrators worksheet.

I wrote SecuritySnapShot.vbs for Windows Server 2003. The machine from which you run the script needs to have Excel 2003 or Excel XP. The script might not work with other versions of Excel because of differences in functionality.

Editor's note: This Reader to Reader item was a winning entry in the Know Your IT Security contest sponsored by Microsoft Learning Paths for Security.

End of Article



Reader Comments
How do I change from the rootdse to another domain? It seems nothing I input works. We have multiple domains. So I would like to run this script from my desk and point it to different domains.

sunbeltcomit June 08, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Microsoft Misses Windows Mobile Sales Target

The warning signs were there. After boldly proclaiming that it would sell "more than" 20 million licenses to its Windows Mobile operating system by the end of its fiscal year on June 30, Microsoft later scaled that prediction back to "nearly" 20 million ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Microsoft: Midori is Not a Future Windows

As I've written previously here and mentioned in the "Windows Weekly" podcast, the oft-hyped-of-late "Midori" project that Microsoft is currently working on is not designed as an update to its current family of Windows operating systems. Midori has been ...


Active Directory (AD) Whitepapers An Introduction to Windows Server 2008 Server Manager

Get More from Active Directory—Easily Audit Changes, and Secure and Restore Objects

User Provisioning: Get the Most Bang for your IT Buck

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 through Aug 29th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Agent-less Remote Backup Service, Free 30 Day Trial
Award winning remote backup service at a competitive price with no min GB/month. Sign up Now!

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing