As Active Directory Networks grow larger, users are often made members of ever more groups, sometimes unknowingly. ADUC Admin Plus helps detect bloated Access Tokens.
When the aggregated, or effective memberships of a user exceed certain thresholds, authentication will no longer be possible, and users suddenly find themselves no longer being able to log on to a website, or even to their own workstation.
Logon problems due to bloated Access Tokens are occurring more and more frequently, are very hard to recognize and equally hard to fix.
ADUC Admin Plus enables you calculate the Access Token size of any user or computer in your Active Directory. And since memberships of SAM local groups are included in a user’s access token upon computer logon, the Access Token size can also be calculated for specific computer logons.
Local SAM database and SID History parts in Access Tokens can be listed as separate, generated properties.
Benefits of the Access Token Feature:
- Proactively keep an eye on who’s on the verge of experiencing logon problems
- Access Token Sizes can be calculated and listed for any number of users or computers simultaneously
- The SID History part of Access Tokens can be requested separately
- In combination with the ‘Membership derived From’ generated property, Access Token problems can be easily fixed by removing multiple, aggregated group memberships