MOCKUP — Tier-0 Inventory · Phase 1 — shipping · security · audit · Follow REPORT-DESIGN-SPEC.md in Power BI Desktop to build this
Cq Claritiq · Tier-0 Inventory Refreshed today
Critical Caution Healthy · target
Scope: eni.enigron.com · c1.eni.enigron.com
Tier-0 accounts
47
across 7 groups
Direct members
31
explicit DN
Nested via groups
16
indirect privilege
Foreign principals
2
cross-forest SID
AdminCount residue
8
SDProp leftovers
Admin w/ mailbox
12
Tier-0 hygiene gap
Privileged groups × membership
GroupDirectNestedTotal recursive
Domain Admins82
10
Enterprise Admins31
4
Schema Admins20
2
Account Operators94
13
Server Operators63
9
Backup Operators54
9
Print Operators32
5
Recursive expansion: nested-group members are surfaced as Tier-0 even though they're not explicit DNs in the privileged group. SDProp re-applies the protected ACL to all of them every 60 minutes.
Tier-0 risk breakdown
Risk dimensionAccountsSeverityDistribution
Foreign Security Principal2Caution
cross-forest
AdminCount=1, not in any group8Caution
SDProp residue
Admin with active mailbox12Caution
Tier-0 hygiene
Admin not in Protected Users31Caution
TGT harvestable
Quick views
Tier-0 roster — recursive membership Showing 8 of 47 · Sorted by Group, User
UserUPNSAMGroupPathEnabledAdminCountIn Protected UsersMailbox
admin-jkentadmin-jkent@contoso.comadmin-jkentDomain AdminsDirectYesYesYesNo
admin-rkumaradmin-rkumar@contoso.comadmin-rkumarEnterprise AdminsDirectYesYesYesNo
Sarah Williamssarah.williams@contoso.comswilliamsAccount OperatorsDirectYesYesNoYes
tier0-svc-backuptier0-svc-backup@contoso.comsvc-backupBackup Operatorsvia GG-BackupTeamYesYesNoNo
Foreign-S-1-5-21-...Domain AdminsForeign SPYesYesNoNo
admin-legacy-disabledadmin-legacy@contoso.comadmin-legacyDomain AdminsDirect (disabled)NoYesNoNo
admin-tchen-newadmin-tchen-new@contoso.comadmin-tchenDomain AdminsDirect (new)YesYesYesNo
ex-svc-archivedex-svc@contoso.comex-svcAdminCount=1 residueNoYesNoNo