19.07.2013 Views

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

ACTIVE DIRECTORY SECURITY CHECKLIST ... - Leet Upload

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Active Directory Checklist, V1R1.2 Field Security Operations<br />

22 September 2006 Defense Information Systems Agency<br />

DS15.0110 ADAM Service Account<br />

STIG ID \ V-Key DS15.0110 \ V0008344<br />

Severity Cat II<br />

Short Name ADAM Service Account<br />

IA Controls ECLP-1<br />

MAC /Conf 1-CSP, 2-CSP, 3-CSP<br />

References AD STIG 2.3.3.6<br />

Long Name: An ADAM service account is a member of a Windows built-in administrative<br />

group.<br />

Checks:<br />

A. Determine ADAM service accounts<br />

• Start the Services console (“Start”, “Run…”, “services.msc”)<br />

• Identify the individual services for ADAM instances.<br />

These names are usually of the form “ADAM_instance”, where instance is the<br />

name chosen during installation.<br />

• For *each* ADAM instance service:<br />

- Note the entry in the LogOnAs field.<br />

• If the service account used for all ADAM instances is the Network Service<br />

account, then there is *no* Finding.<br />

B. Check ADAM service accounts group membership<br />

• For *each* ADAM service account that is a local (*not* domain) user account,<br />

- At a command line prompt enter: “net user account”<br />

where account is the ADAM service account.<br />

- Note the Group Membership information.<br />

• For *each* ADAM service account that is a domain user account,<br />

- At a command line prompt enter: “net user account /domain”<br />

where account is the ADAM service account.<br />

- Note the Group Membership information.<br />

• If any ADAM service account is a member of the Administrators, Domain<br />

Admins, Enterprise Admins, or Schema Admins groups, then this is a finding.<br />

UNCLASSIFIED<br />

5-44

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!