How Many Angels Can Dance on the Head of a Pin?

PS AD:\> (Get-Acl (Get-ADObject -Filter *)).Access.Count
PS AD:\> (Get-ADGroupMember -Identity “Domain Admins”).Count
PS AD:\> (Get-ADGroupMember -Identity “Domain Admins” -Recursive).Count
((Get-ACL ‘cn=domain admins,cn=users,dc=corp,dc=local’).Access | Where {($_.ActiveDirectoryRights -like “*WriteProperty*”) -and (($_.ObjectType -eq “bf9679c0–0de6–11d0-a285–00aa003049e2”) -or ($_.ObjectType -eq “00000000–0000–0000–0000–000000000000”)) -or ($_.ActiveDirectoryRights -like “*GenericWrite*”) -or ($_.ActiveDirectoryRights -like “*GenericAll*”)}).count
((Get-ACL $DN).Access | Where {((($_.ActiveDirectoryRights -like "*WriteProperty*") -and (($_.ObjectType -eq "bf9679c0-0de6-11d0-a285-00aa003049e2") -or ($_.ObjectType -eq "00000000-0000-0000-0000-000000000000"))) -or ($_.ActiveDirectoryRights -like "*GenericWrite*") -or ($_.ActiveDirectoryRights -like "*GenericAll*") -or ($_.ActiveDirectoryRights -like "*WriteDACL*") -or ($_.ActiveDirectoryRights -like "*WriteOwner*") -or (($_.ActiveDirectoryRights -like "*Self*") -and (($_.ObjectType -eq "bf9679c0-0de6-11d0-a285-00aa003049e2") -or ($_.ObjectType -eq "00000000-0000-0000-0000-000000000000"))))}).Count
(Get-ADUser -Filter * -SearchBase “ou=suborg,dc=corp,dc=local”).Count
(Get-Acl (Get-ADObject -Filter *)).Access.Count
PS C:\> Import-Module ActiveDirectoryPS C:\> Set-Location AD:

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Rich

Rich

15 Followers

I work various IT jobs & like Windows domain security as a hobby. Most of what’s here is my notes from work or the lab.