How to find admin users on EDR.

Newbie579173 Lv1Posted Mar-10-2025 15:29

Hello, I want to identify users that are added to admin group on their machine. Please guide if I can identify it through sangfor endpoint secure.

Enrico Vanzetto has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Hi, on edr web ui console, you can go to Administrators and see the related groups they are assigned:

9417467ceaefd0700e.png (82.97 KB, Downloads: 82863)

9417467ceaefd0700e.png
Is this answer helpful?
Humayun Ahmed Lv3Posted Mar-10-2025 15:49
  
1. Enable Endpoint Monitoring
   Ensure that the Sangfor Endpoint Secure agent is installed on all endpoints you want to monitor.
   Configure the Endpoint Secure Manager to collect detailed user and group information from the endpoints.

2. Set Up Policies for Admin Group Monitoring
   In the Endpoint Secure Manager, create or modify a security policy to monitor changes in user group memberships.
   Enable real-time monitoring for administrative group changes. This will allow the system to detect and log any modifications to the admin group.

3. Generate Reports
   Use the reporting feature in Sangfor Endpoint Secure to generate logs or reports that show changes in group memberships.
  Look for events where users are added to the admin group. These logs will provide details such as the username, machine name, and timestamp of the change.

4. Set Alerts
   Configure alerts in Endpoint Secure to notify you whenever a user is added to the admin group. This ensures you are immediately informed of any unauthorized changes.

5. Audit and Investigate
   Regularly audit the logs and reports to ensure that only authorized users are part of the admin group.
   Investigate any suspicious additions to the admin group to prevent potential security risks.
SassyScorpio Lv2Posted Mar-10-2025 15:58
  
You can monitor users added to the local Administrators group using Sangfor Endpoint Secure by:

Reviewing Sangfor's Features – Check its asset management and security policy enforcement for detecting privilege changes.
Using Network Integration – Leverage Sangfor NGAF and Cyber Command for correlated threat detection.
Checking Windows Event Logs – Monitor Event ID 4732 to track additions to the local Administrators group.
Consulting Sangfor Support – Reach out for documentation or configuration guidance if needed.

If Sangfor lacks direct monitoring for this, consider complementary solutions like SIEM tools or scripts for real-time alerts.
AR Lv2Posted Mar-10-2025 17:13
  
Hello,
1. Make Endpoint Monitoring Active
    Make sure that every endpoint you wish to monitor has the Sangfor Endpoint Secure agent installed.
   Set up the Endpoint Secure Manager to gather comprehensive endpoint user and group data.

2. Establish Admin Group Monitoring Policies
    Create or edit a security policy in the Endpoint Secure Manager to track modifications to user group memberships.
    Turn on real-time monitoring for changes to the administrative group.  This will make it possible for the system to identify and record any changes made to the admin group.
3. Produce Reports
    Create logs or reports demonstrating changes in group memberships using Sangfor Endpoint Secure's reporting capability.
   Keep an eye out for occasions when people are added to the administrator group.  These logs will include information like the machine name, username, and change time.

4. Configure Alerts
    To be informed anytime a user is added to the admin group, set up alerts in Endpoint Secure.  This guarantees that you are notified right away of any unauthorised modifications.

5. Examine and Look Into
    Make sure that only authorised users are included in the admin group by routinely auditing the logs and reports.
    To avoid any possible security threats, look into any unusual additions to the admin group.

Enrico Vanzetto Lv4Posted Mar-10-2025 17:21
  
Hi, on edr web ui console, you can go to Administrators and see the related groups they are assigned:

9417467ceaefd0700e.png (82.97 KB, Downloads: 82863)

9417467ceaefd0700e.png

I Can Help:

Change

Moderator on This Board

2
1
0

Started Topics

Followers

Follow

1
1
0

Started Topics

Followers

Follow

926
185
94

Started Topics

Followers

Follow

Trending Topics

Board Leaders