Comments (3)
  1. Anonymous says:
    (The content was deleted per user request)
  2. TrixM says:

    Great idea… except when your mystery admin has set up AAD with a custom service account rather than using the GMSA that gets created during the default install. 🙁

    With any luck, they gave it an identifiable name, so you can go through your DC security log for 4624 logon events from that user.

Comments are closed.

Skip to main content