mirror of https://github.com/raandree/NTFSSecurity
Browse Source
When an account is deleted and created again with the same name, a Kerberos S4U logon for it keeps returning the SID and the groups of the deleted account for a while, on the domain controller, the client, and the file server. The matrix deletes the fixture after each cell and creates it for the next, so the effective-access tests of the Admin role found no access for the new account in cells that followed within minutes (Windows Server 2022 cell, candidate and baseline alike, shown by a probe that creates the accounts in a loop). A new fixture now gets NtfsLiveSubject and four digits; a fixture that exists keeps its account. The end-state check of the matrix also reports leftover scheduled tasks, stage folders, standard users, and probe accounts, which the review asked for. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant <ai@example.com>pull/119/head
3 changed files with 38 additions and 8 deletions
Loading…
Reference in new issue