Start a Conversation

Unsolved

This post is more than 5 years old

827

March 23rd, 2016 06:00

AD account details in isilon

     Hello,

     Is is possible to get administrator account which was used to join AD to Isilon ?

     If Yes. How ?

Thanks

Chughh

450 Posts

March 23rd, 2016 08:00

If you look at the machine account in AD, with ADSI Edit, you can see for instance when it was created with the value 'whencreated'

If you look at the security tab on that machine account in ADSI Edit, you might see the username who performed the join.  Separate from that security, in some systems (like VNX[optionally requires a param change], or Windows Server) that user account that performed the join operation is added to the local administrators group.  If that's not the case the group membership would just be 'domain admins'.  From my own verification, it would appear that on Isilon only 'Domain Admins' are automatically added into the local administrators group.

Here is the syntax to check FWIW on Isilon.  This is saying look at the 'local' auth provider in the 'System' Access Zone, so change as appropriate for your system.

isi01-1# isi auth groups members list --group=Administrators --provider=local --zone=System

Type  Name

-------------------

group domain admins

-------------------

Total: 1

Hope this helps,

~Chris Klosterman

Advisory Solution Architect

EMC Enablement Team

No Events found!

Top