1

Some tools that draw links between objects in a Active Directory architecture, show that if we have an user who is administrator of an OU on which a domain administrator is also present, so he can take control of the domain.

Is that true?

How is it possible if so?

Duke Nukem
  • 687
  • 3
  • 9
  • 20

1 Answers1

1

Should be straightforward enough;

  1. As OU administrator, reset the domain administrator's password (as he is in your OU)
  2. Now you can log in as the domain administrator (you know the password now)
  3. Configure your account to be a domain administrator (as you're currently authenticated as a domain admin).
James
  • 161
  • 3