Auditing Account management events
From: fex (anonymous_at_discussions.microsoft.com)
Date: 11/28/04
- Next message: Joey: "GPO OBJECT ACCESS"
- Previous message: Mark Renoden [MSFT]: "Re: Expanding knowledge of Group Policy"
- Next in thread: Steven L Umbach: "Re: Auditing Account management events"
- Reply: Steven L Umbach: "Re: Auditing Account management events"
- Messages sorted by: [ date ] [ thread ]
Date: Sun, 28 Nov 2004 15:58:50 -0800
Hello,
I've been auditing multiple events (System Events ,
Policy Changes , Logon Events , but specially all events
referents to Account management events like (User Account
create, User Account Deleted , etc ) However , I applied
the auditing to the default group everyone on Defaul
Domain Controller Policy , to check specially all changes
made by users with domain admin rights. But at this moment
they are changing users -passwords - deleting users and -
I don't receive any event id; for instance (ID:624-627-630)
at the moment they applied any change on the DC.
I would like to know what is my misconfiguration or I need
more configuartion or the default group it is not applied
right way ?
I will thanks any comment !!!
- Next message: Joey: "GPO OBJECT ACCESS"
- Previous message: Mark Renoden [MSFT]: "Re: Expanding knowledge of Group Policy"
- Next in thread: Steven L Umbach: "Re: Auditing Account management events"
- Reply: Steven L Umbach: "Re: Auditing Account management events"
- Messages sorted by: [ date ] [ thread ]
Relevant Pages
|