Privileged Accounts Job Group
The Privileged Accounts Job Group highlights the activity performed by this accounts, to identify potential abuses or unused accounts which can be deprovisioned.
The following Jobs make up the Privileged Accounts Job Group:
RECOMMENDED: Schedule these jobs to run with the 0.Collection job group.
- AD_AdminAccounts Job – Shows all actions taken by domain administrators within the environment being compromised
- AD_ServiceAccountAuth Job – Shows the last time a service account, identified by the presence of a servicePrincipalName, was active within the environment