Occasional Contributor

I was looking at a computer and on the logs, it shows a name of a person who is not a Domain Admin but has queried Domain Admins Queried next to his name.


What does this mean?


It means a process running as the user ran a query against the domain admins group to enumerate the members of this group.  Some apps do this.  Is this something you would expect apps on your network to do?  if so, its likely normal.  if not its worth looking in to.


  Thank you for the replay.  This is not normal on our network.  What type of steps could you recommend to help look into this?

We support Ukraine and condemn war. Push Russian government to act against war. Be brave, vocal and show your support to Ukraine. Follow the latest news HERE