Queried Domain Admins

Copper Contributor

I was looking at a computer and on the logs, it shows a name of a person who is not a Domain Admin but has queried Domain Admins Queried next to his name.


What does this mean?

2 Replies


It means a process running as the user ran a query against the domain admins group to enumerate the members of this group.  Some apps do this.  Is this something you would expect apps on your network to do?  if so, its likely normal.  if not its worth looking in to.


  Thank you for the replay.  This is not normal on our network.  What type of steps could you recommend to help look into this?