Notification

Icon
Error

Windows: Unauthorized Administrators (Built-in)

Posted: Thursday, November 20, 2014 12:53:12 PM(UTC)
Daniel.B

Daniel.B

Member Original PosterPosts: 1,150
1
Like
Old name: Computer: Unauthorized Administrators (Built-in)

The report below lists unauthorized members of your Windows computers' local administrator group, users that have not been marked as authorized under Configuration\User Pages in the web console. More info on the admin authorization feature can be found in this knowledge base article.

The report will only list assets that meet all of the following criteria:
  • The asset state is set to "active".
  • The asset has been successfully scanned at least once.
  • The asset is a Windows computer.
  • The Windows computer has an admin who is not built-in and who is not on the list of authorized admins under Configuration\User Pages.

Code:

SELECT Top 1000000 tblAssets.AssetID,  
 tblAssets.AssetName,  
tblAssets.Domain,
 tblAssets.Username,
 tblAssets.Userdomain,
 Coalesce(tsysOS.Image, tsysAssetTypes.AssetTypeIcon10) As icon,
 tblAssets.IPAddress,
 tsysIPLocations.IPLocation,
 tblAssetCustom.Manufacturer,
 tblAssetCustom.Model,
 tsysOS.OSname As OS,
 tblAssets.SP,
 tblAssets.Lastseen,
 tblAssets.Lasttried,
 tblUsersInGroup.Domainname as unauthorizedDomain, 
 tblUsersInGroup.Username as unauthorizedUser,
 tblUsersInGroup.Lastchanged
FROM tblAssets 
 Inner Join tblUsersInGroup ON tblUsersInGroup.AssetID = tblAssets.AssetID 
 Inner Join tblAssetCustom On tblAssets.AssetID = tblAssetCustom.AssetID
 Inner Join tsysAssetTypes On tsysAssetTypes.AssetType = tblAssets.Assettype
 Inner Join tsysIPLocations On tsysIPLocations.LocationID = tblAssets.LocationID 
 Inner Join tblState On tblState.State = tblAssetCustom.State
 Left Join tsysOS On tsysOS.OScode = tblAssets.OScode
WHERE
 (NOT EXISTS ( SELECT tblAssets.AssetName AS Domain, tblUsers.Name AS Username FROM tblAssets INNER JOIN tblUsers ON tblAssets.AssetID = tblUsers.AssetID
        WHERE (Case tblUsers.BuildInAdmin when 1 then 'Yes' else 'No' end) = 'Yes' AND (tblUsersInGroup.Domainname = tblAssets.AssetName) AND (tblUsersInGroup.Username = tblUsers.Name))
 AND NOT EXISTS( SELECT Domain, AdminName AS username FROM tsysadmins WHERE (tblUsersInGroup.Domainname LIKE Domain) AND (tblUsersInGroup.Username LIKE  AdminName)))
 AND (Case tblUsersInGroup.Admingroup when 1 then 'Yes' else 'No' end) = 'Yes' 
 AND tblState.Statename = 'Active' 
Order By tblAssets.Domain, tblAssets.AssetName
Lancreeper
#1Lancreeper Member Posts: 2  
posted: 7/29/2019 9:32:17 PM(UTC)
The KB article states "Authorizing a domain user for a specific computer is not currently possible." Is this possible using a different query?
bnishan
#2bnishan Member Posts: 3  
posted: 8/12/2019 8:13:15 PM(UTC)
We need the ability to authorize a domain user for a specific computer. This report has very limited usefulness without that.
Lancreeper
#3Lancreeper Member Posts: 2  
posted: 8/12/2019 8:56:54 PM(UTC)
Originally Posted by: bnishan Go to Quoted Post
We need the ability to authorize a domain user for a specific computer. This report has very limited usefulness without that.


This is what I came up with. Just replace %DOMAIN% with your domain.

Select Top 1000000 tblAssets.AssetID,
tblAssets.AssetName,
tblUsersInGroup.Username,
tblUsersInGroup.Domainname,
tblUsersInGroup.Groupname
From tblAssets
Inner Join tblUsersInGroup On tblAssets.AssetID = tblUsersInGroup.AssetID
Where tblUsersInGroup.Username != 'Administrator' And
tblUsersInGroup.Groupname = 'Administrators' And
Not Exists(Select tsysadmins.Domain,
tsysadmins.AdminName From tsysadmins
Where (tblAssets.AssetName Like tsysadmins.Domain Or
tsysadmins.Domain Like '%DOMAIN%') And tblUsersInGroup.Username Like
tsysadmins.AdminName)
Order By tblAssets.AssetName
bnishan
#4bnishan Member Posts: 3  
posted: 8/12/2019 9:02:30 PM(UTC)
Originally Posted by: Lancreeper Go to Quoted Post
Originally Posted by: bnishan Go to Quoted Post
We need the ability to authorize a domain user for a specific computer. This report has very limited usefulness without that.


This is what I came up with. Just replace %DOMAIN% with your domain.

Select Top 1000000 tblAssets.AssetID,
tblAssets.AssetName,
tblUsersInGroup.Username,
tblUsersInGroup.Domainname,
tblUsersInGroup.Groupname
From tblAssets
Inner Join tblUsersInGroup On tblAssets.AssetID = tblUsersInGroup.AssetID
Where tblUsersInGroup.Username != 'Administrator' And
tblUsersInGroup.Groupname = 'Administrators' And
Not Exists(Select tsysadmins.Domain,
tsysadmins.AdminName From tsysadmins
Where (tblAssets.AssetName Like tsysadmins.Domain Or
tsysadmins.Domain Like '%DOMAIN%') And tblUsersInGroup.Username Like
tsysadmins.AdminName)
Order By tblAssets.AssetName


Thanks, worked like a charm
Jackie.L
#5Jackie.L Member Posts: 1  
posted: 5/20/2020 8:01:17 PM(UTC)
Here is my change to our query to allow the ability to authorize domain user for specific computer:

Code:

SELECT TOP 1000000 tsysOS.IMAGE AS icon
	,tblAssets.AssetID
	,tblAssets.AssetName
	,tblUsersInGroup.Domainname
	,tblUsersInGroup.Username
	,tblUsersInGroup.Lastchanged
	,tblAssets.Domain
	,tblAssets.IPAddress
	,tblAssets.Description
	,tblAssetCustom.Manufacturer
	,tblAssetCustom.Model
	,tblAssetCustom.Location
	,tsysIPLocations.IPLocation
	,tsysOS.OSname AS OS
	,tblAssets.SP AS SP
	,tblAssets.Firstseen
	,tblAssets.Lastseen
FROM tblUsersInGroup
INNER JOIN tblAssets ON tblUsersInGroup.AssetID = tblAssets.AssetID
INNER JOIN tblAssetCustom ON tblAssets.AssetID = tblAssetCustom.AssetID
INNER JOIN tsysOS ON tblAssets.OScode = tsysOS.OScode
LEFT JOIN tsysIPLocations ON tsysIPLocations.StartIP <= tblAssets.IPNumeric
	AND tsysIPLocations.EndIP >= tblAssets.IPNumeric
WHERE NOT EXISTS (
		SELECT tblAssets.AssetName AS Domain
			,tblUsers.Name AS Username
		FROM tblAssets
		INNER JOIN tblUsers ON tblAssets.AssetID = tblUsers.AssetID
		WHERE tblUsers.BuildInAdmin = 1
			AND tblUsersInGroup.Domainname = tblAssets.AssetName
			AND tblUsersInGroup.Username = tblUsers.Name
		)
	AND NOT EXISTS (
		SELECT tsysadmins.Domain
			,tsysadmins.AdminName AS username
		FROM tsysadmins
		WHERE ( tblUsersInGroup.Domainname LIKE tsysadmins.Domain
			AND tblUsersInGroup.Username LIKE tsysadmins.AdminName )
			OR ( tblassets.AssetName LIKE tsysadmins.Domain
			AND tblUsersInGroup.Username LIKE tsysadmins.AdminName )
		)
	AND tblUsersInGroup.Admingroup = 1
	AND tblAssetCustom.STATE = 1
ORDER BY tblAssets.AssetName

Active Discussions

Lansweeper Unable to send to External Email
by  pryan67   Go to last post Go to first unread
Last post: Yesterday at 8:21:01 PM(UTC)
Lansweeper Lansweeper assets not being Scanned
by  Jordan  
Go to last post Go to first unread
Last post: Yesterday at 6:42:22 PM(UTC)
Lansweeper Database size growing too large
by  bladd   Go to last post Go to first unread
Last post: Yesterday at 4:26:44 PM(UTC)
Lansweeper Searching Specific File
by  mzipperer  
Go to last post Go to first unread
Last post: Yesterday at 4:23:29 PM(UTC)
Lansweeper Exchange 2010 information is not populating
by  Moe   Go to last post Go to first unread
Last post: Yesterday at 12:30:38 PM(UTC)
Lansweeper Routinely Exploited Vulnerabilities Query Report
by  pryan67  
Go to last post Go to first unread
Last post: Yesterday at 12:25:31 PM(UTC)
Lansweeper Creating a report for new devices every 2 hours to alert
by  Moe   Go to last post Go to first unread
Last post: 6/4/2020 7:26:11 PM(UTC)
Lansweeper Changes in the licensing model
by  BullGates  
Go to last post Go to first unread
Last post: 6/4/2020 6:27:23 PM(UTC)