Forum Discussion

charles burch's avatar
charles burch
Copper Contributor
Sep 17, 2018

Queried Domain Admins

I was looking at a computer and on the logs, it shows a name of a person who is not a Domain Admin but has queried Domain Admins Queried next to his name.

 

What does this mean?

2 Replies

  • Hi

    It means a process running as the user ran a query against the domain admins group to enumerate the members of this group.  Some apps do this.  Is this something you would expect apps on your network to do?  if so, its likely normal.  if not its worth looking in to.

    • charles burch's avatar
      charles burch
      Copper Contributor

      Nicholas,

        Thank you for the replay.  This is not normal on our network.  What type of steps could you recommend to help look into this?

Resources