<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: AD Domain Admin permissions to SQL</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-admin-permissions-to-sql/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-admin-permissions-to-sql/</link>
	<description></description>
	<pubDate>Fri, 27 Nov 2009 06:43:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Hlx</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/ad-domain-admin-permissions-to-sql/#comment-64336</link>
		<dc:creator>Hlx</dc:creator>
		<pubDate>Tue, 09 Jun 2009 17:09:36 +0000</pubDate>
		<guid isPermaLink="false">#comment-64336</guid>
		<description>Depending on your viewpoint, it would be pretty trivial for a Domain Admin to change a password and login as a domain user that they know is SA and then grant themselves access. The only clue would be that the hijacked account holder would then be unable to login with what they thought was their password. One call to the help desk or perhaps even the Domain Admin to reset their password and all traces go away.</description>
		<content:encoded><![CDATA[<p>Depending on your viewpoint, it would be pretty trivial for a Domain Admin to change a password and login as a domain user that they know is SA and then grant themselves access. The only clue would be that the hijacked account holder would then be unable to login with what they thought was their password. One call to the help desk or perhaps even the Domain Admin to reset their password and all traces go away.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
<!-- dynamic -->