Re: Audit trail of AD Account

Tech-Archive recommends: Speed Up your PC by fixing your registry



On Wed, 6 Jul 2005 16:41:29 +0800, "YMan" <yyyy@xxxxxxxx> wrote:

>Hi,
>
>Yes I have another question.
>
>When the administrator disable an account in Active Directory. Is there any
>way to set up audit trail that will show when the account is being disabled?
>For example, a staff is leaving the company and the administrator will
>disable his / her account by the time s/he leaves for good. Will there be
>any log to record the event that the administrator actually disabled that
>user's account in AD? If not within Microsoft, what will be the options?
>
>Thanks
>
>From the Help file:

Group Policy

Audit account managementComputer Configuration\Windows Settings\Security Settings\Local Policies\Audit Policy

Description
Determines whether to audit each event of account management on a computer. Examples of account management events include the following:

A user account or group is created, changed, or deleted.
A user account is renamed, disabled, or enabled.
A password is set or changed.
If you define this policy setting, you can specify whether to audit successes, audit failures, or not audit the event type at all. Success audits generate an audit entry when any account management event succeeds. Failure audits generate an
audit entry when any account management event fails. To set this value to no auditing, in the Properties dialog box for this policy setting, select the Define these policy settings check box and clear the Success and Failure check boxes.

Default: No auditing.

For more information, see:

Security Configuration Manager Tools

.



Relevant Pages

  • Re: user accounts are reappearing
    ... is a policy setting called "audit account management" that you can enable. ...
    (microsoft.public.win2000.active_directory)
  • Re: Find who added an account to domain admins group
    ... "Audit Account Management" ... "Audit directory service access" ... is enable by default for successes and will audit several actions ... An account 'magically' appears in the domain admins group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM Security Logging
    ... so if you look at the effective local security policy on the ADAM ... "Audit account management". ... account "Generate security audits" right in User Rights Assignment ...
    (microsoft.public.windows.server.active_directory)
  • RE: 2 SBS2003 Questions...
    ... It is important to us that we provide you with the best support possible ... you can use the Account locked out policy in Group Policy to reach ... I suggest you enable User logon audit to monitor the event log to see ...
    (microsoft.public.windows.server.sbs)
  • Audit account (Windows 2000 AD)
    ... We need to audit disabled account, ... I enabled auditing domain policy to ... Category: Account management ... User account type changed. ...
    (Security-Basics)