pingcastle icon indicating copy to clipboard operation
pingcastle copied to clipboard

"Computer Information" of "Domain Controllers" can list member server as Domain Controller

Open An-dir opened this issue 11 months ago • 1 comments

"Domain Controllers" (in the "Computer Information" section) lists all computer objects in the DomainControllers OU. Normally this is correct, but I have found normal AD member computer objects in this OU. So there were more "DCs" listed than in any other Domain Controller check. So fixing it in this environment is easy - move the object out.

I also had a customer with multiple cluster objects in the "Domain Controllers" OU, because they had an application with cluster feature on DCs. As you can guess the cluster objects all looked like DCs.

Could you optimize that area? Maybe add a column that tells us what DC it is. So it could be "RODC", "RWDC", "ERROR".

An-dir avatar Aug 04 '23 10:08 An-dir