A county OU ACL grants a helpdesk group Full Control over user objects. What should the tester conclude?
Select an answer to reveal the explanation.
Short Explanation
Full Control on user objects is not a participation trophy — it can mean reset, modify, and take over. If helpdesk has that on an OU, you have found a dangerous ACL path worth elevating.
Full Explanation
Active Directory ACLs on OUs and objects can grant rights far beyond intended helpdesk tasks, including control that enables account takeover paths. Excessive permissions are a core misconfiguration theme in AD attack-path analysis. Domain Admin is not the only privilege that matters, and Full Control is not limited to benign attributes like photos. Clear reporting of dangerous ACLs supports remediation of identity governance gaps.