RKRizwan Khan
← Back to all projects

UKE Hamburg · Security & Recovery · January 2010 — March 2010

UKE HamburgSystem Administrator

I analysed complex ACL, GPO and folder redirection issues and automated access control via user attributes.

Organisation
UKE Hamburg
Period
January 2010 — March 2010
Role
System Administrator
Focus
Security & Recovery
UKE Hamburg: Abstract infrastructure illustration for the UKE Hamburg engagement

Situation

Missing or contradictory permissions, faulty folder redirections and conflicting group policies impaired reliable access to resources.

Constraints

  • Changes within an already established IT environment
  • Short, clearly scoped engagement
  • Internal system and operating details remain confidential

My scope of responsibility

I analysed ACLs, user attributes, folder redirection and GPO processing, developed corrections and scripted the required access control.

  • I identified missing, incorrect and conflicting ACLs.
  • I analysed and corrected folder redirection and GPO conflicts.

Documented scope of work

Key decisions

Investigate permission, user attribute and policy processing as one connected access chain. Individual ACL fixes would not have held if attribute scripts, paths or group policies kept producing contradictory states.

  1. I developed scripts for access control based on user attributes.

Technology in use

ACL

ACL was part of the documented toolset in this Security & Recovery engagement.

Active Directory

Active Directory was part of the documented toolset in this Security & Recovery engagement.

Group Policy

Group Policy was part of the documented toolset in this Security & Recovery engagement.

Folder Redirection

Folder Redirection was part of the documented toolset in this Security & Recovery engagement.

Scripting

Scripting was part of the documented toolset in this Security & Recovery engagement.

Evidence and limits

Access control, folder access and policy application gained a more consistent technical foundation.

Role
System Administrator
Period
January 2010 — March 2010

Lesson from the engagement

Access problems are solved for good when permissions, identity data and policy processing are viewed end to end.

Confidentiality note: Internal architecture and operating data of this engagement are not published.

Related case studies

Planning a demanding change to your Microsoft infrastructure?

View Active Directory & Recovery as a service Discuss your project