<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>&amp;quot;Account Ops-FC&amp;quot; access control entry (ACE)</title><link>http://blogs.technet.com/activedirectoryua/archive/2009/04/22/account-operators-group-and-ad-computer-accounts.aspx</link><description>Account Operators is a default groups located in the Builtin container. Members of this group can create, modify, and delete accounts for users, groups, and computers located in the Users or Computers containers and organizational units in the domain,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>  Active Directory Documentation Team : Account Operators group and &amp;#8230; | Computer Internet and Technology Articles.</title><link>http://blogs.technet.com/activedirectoryua/archive/2009/04/22/account-operators-group-and-ad-computer-accounts.aspx#3229510</link><pubDate>Thu, 23 Apr 2009 04:16:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3229510</guid><dc:creator>  Active Directory Documentation Team : Account Operators group and &amp;#8230; | Computer Internet and Technology Articles.</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://program.cgwebstudio.com/active-directory-documentation-team-account-operators-group-and/"&gt;http://program.cgwebstudio.com/active-directory-documentation-team-account-operators-group-and/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Default Account Operators permissions on DC object</title><link>http://blogs.technet.com/activedirectoryua/archive/2009/04/22/account-operators-group-and-ad-computer-accounts.aspx#3229918</link><pubDate>Thu, 23 Apr 2009 23:42:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3229918</guid><dc:creator>Tomek's DS World</dc:creator><description>&lt;p&gt;Active Directory Documentation Team has put on the web interesting post about default permissions of&lt;/p&gt;
</description></item><item><title>re: Account Operators group and AD computer accounts</title><link>http://blogs.technet.com/activedirectoryua/archive/2009/04/22/account-operators-group-and-ad-computer-accounts.aspx#3234187</link><pubDate>Sat, 02 May 2009 04:08:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3234187</guid><dc:creator>JPolicelli</dc:creator><description>&lt;p&gt;This is great info to make available to the public. I am curious why this is being made publically available 10 years after AD was released. Better late than never I guess.&lt;/p&gt;
&lt;p&gt;I have always preached that the built-in groups should not be used. I have seen many cases where the Account Operators group has been used to exploit AD and DCs. I posted about this a while back (&lt;a rel="nofollow" target="_new" href="http://policelli.com/blog/?p=128"&gt;http://policelli.com/blog/?p=128&lt;/a&gt;). This lingering ACE is another reason to NOT use the built-in groups, especially the Account Operators group.&lt;/p&gt;
</description></item></channel></rss>