Auditing Account management events

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: fex (anonymous_at_discussions.microsoft.com)
Date: 11/28/04


Date: Sun, 28 Nov 2004 15:58:50 -0800


 Hello,

 I've been auditing multiple events (System Events ,
Policy Changes , Logon Events , but specially all events
referents to Account management events like (User Account
create, User Account Deleted , etc ) However , I applied
the auditing to the default group everyone on Defaul
Domain Controller Policy , to check specially all changes
made by users with domain admin rights. But at this moment
they are changing users -passwords - deleting users and -
I don't receive any event id; for instance (ID:624-627-630)
at the moment they applied any change on the DC.

I would like to know what is my misconfiguration or I need
more configuartion or the default group it is not applied
right way ?

I will thanks any comment !!!



Relevant Pages

  • Account management events audit !!
    ... I've been auditing multiple events (System Events, ... Policy Changes, Logon Events, but specially all events ... referents to Account management events like (User Account ... Domain Controller Policy, ...
    (microsoft.public.win2000.active_directory)
  • SceCLi event id 1202 , Need Help Please!
    ... folder from the %systemroot% ... Default Domain Controller Policy program in Administration ... I found out that this is not a user account, ... >but it was the Power Users group. ...
    (microsoft.public.win2000.security)