Checking your rights and roles using dzinfo

You can use the dzinfo command line program in a Command Prompt window to view detailed information about your rights, roles, and role assignments. The dzinfo command line utility provides the same functionality as the Authorization Center described in Checking your rights and role assignments, but allows you to view and capture the output from the command in a single window.

The syntax for the dzinfo program is:

dzinfo

The command returns detailed information about your rights, roles, and role assignment similar to the following:

Effective roles for AJAX\rey.garcia:
   weblogic2/portland
      Zone:    CN=portland,CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Status:  Active
   Domain Admin/portland
      Zone:    CN=portland,CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Status:  Active
   Windows Login/mainoffice
      Zone:    CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Status:  Active
Effective Login Rights for AJAX\rey.garcia:
   Console Login: Permitted
      Audit Level: Audit if possible
   Remote Login: Permitted
      Audit Level: Audit if possible
   PowerShell Remote Access: Permitted
      Audit Level: Audit if possible
Role Assignments for AJAX\rey.garcia:
   weblogic2/portland
      Status:        Active
      Account:       AJAX\rey.garcia
      Scope:         Zone
      Zone:          ajax.org/Centrify/Zones/mainoffice/portland
      Local Role:    No
      Network Role:  Yes
      Effective:     Immediate
      Expires:       Never
   Domain Admin/portland
      Status:        Active
      Account:       AJAX\rey.garcia
      Scope:         Zone
      Zone:          ajax.org/Centrify/Zones/mainoffice/portland
      Local Role:    No
      Network Role:  Yes
      Effective:     Immediate
      Expires:       Never
   Windows Login/mainoffice
      Status:        Active
      Account:       AJAX\Domain Admins
      Scope:         Zone
      Zone:          ajax.org/Centrify/Zones/mainoffice
      Local Role:    Yes
      Network Role:  No
      Effective:     Immediate
      Expires:       Never
Role Definitions:
   weblogic2/portland
      Status:          Active
      Description:     None
      Zone:            CN=portland,CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Login Permitted: No
      Audit Level:     Audit if possible
      Rescue Right:    No
      Require MFA:     No
      Available Hours:
       	 12  2   4   6   8   10  12  2   4   6   8   10
Sunday  X X X X X X X X X X X X X X X X X X X X X X X X
Monday    X X X X X X X X X X X X X X X X X X X X X X X X 
Tuesday   X X X X X X X X X X X X X X X X X X X X X X X X 
Wednesday X X X X X X X X X X X X X X X X X X X X X X X X 
Thursday  X X X X X X X X X X X X X X X X X X X X X X X X 
Friday    X X X X X X X X X X X X X X X X X X X X X X X X 
Saturday  X X X X X X X X X X X X X X X X X X X X X X X   
      Rights:
         weblogic Network Access/portland
            Type:                   Network Access
            Description:            None
            Priority:               0
            Run As:                 AJAX\wladmin
            Require Authentication: No
         weblogic Desktop/portland
            Type:                   Desktop
            Description:            None
            Priority:               0
            Run As:                 AJAX\wladmin
            Require Authentication: No
   Domain Admin/portland
      Status:          Active
      Description:     None
      Zone:            CN=portland,CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Login Permitted: No
      Audit Level:     Audit if possible
      Rescue Right:    No
      Available Hours: All
      Rights:
         ADUC/portland
            Type:                   Application
            Description:            Active Directory Users and Computers as Admin
            Priority:               0
            Run As:                 AJAX\Administrator
            Application:            mmc.exe
            Path:                   C:\Windows\system32
                                    C:\Windows
                                    C:\Program Files
                                    C:\Program Files (x86)
                                    C:\Windows\SysWOW64
            Arguments:              "C:\Windows\system32\dsa.msc"
            Match Case:             No
            Require Authentication: No
            Application Criteria:
               None
         Domain Admin Network Access/portland
            Type:                   Network Access
            Description:            None
            Priority:               0
            Run As:                 AJAX\Administrator
            Require Authentication: No
   Windows Login/mainoffice
      Status:          Active
      Description:     Predefined system role for general Windows login users.
      Zone:            CN=mainoffice,CN=Zones,OU=Centrify,DC=ajax,DC=org
      Login Permitted: Console & Remote & PowerShell Remote
      Audit Level:     Audit if possible
      Rescue Right:    No
      Available Hours: All
      Rights:
         None
Computer is joined to zone ajax.org/Centrify/Zones/mainoffice
Auditing for AJAX\rey.garcia:
   Session ID 2:
      Desktops:
         Default: Not currently auditing.
Auditing is not available on this computer.