Need to check who created users in active directory
I have assigned some permission to my colleagues for users creation, deletion in active directory. In last week, I was on holiday and some new users are created in my absence. Though, I have asked to those guys who are authorized for such actions but no one is accepting now. Can I track, who was the person. My server is Windows 2008R2.
February 11th, 2015 7:03am

If account management audit is turned on, then you will see account creation events in the security log.
Free Windows Admin Tool Kit Click here and download it now
February 11th, 2015 8:21am

Hi

If auditing is enable you can track the same by checking the event log.In order to find out changes, creation or deletion events, you must keep the Account Management auditing enabled..You cal also use repadmin /showobjmeta to trace the same.


http://blogs.technet.com/b/ad/archive/2006/06/12/435501.aspx
http://technet.microsoft.com/en-us/library/cc742104%28WS.10%29.aspx

Tracing down user and computer account deletion in Active Directory
http://blogs.technet.com/b/abizerh/archive/2010/05/27/tracing-down-user-and-computer-account-deletion-in-active-directory.aspx

Auditing directory changes 
http://blogs.dirteam.com/blogs/tomek/archive/2006/09/21/Auditing-directory-changes-aka-_2600_quot_3B00_Who-deleted-this-object_3F002600_quot_3B00_.aspx

Apart from the auditing, you can use third party tools like Quest and Ntewrix to find out WHO changed WHAT, WHEN, and WHERE to list additions, deletions, and modifications made to Active Directory users, groups, computers, OUs, group memberships.

Please mark this as answer if it helps you

February 11th, 2015 8:30am

If auditing was enabled then yes. You can track the events in event viewer as long as they were not removed.

More details here: http://blogs.technet.com/b/askpfeplat/archive/2012/03/05/how-to-track-the-who-what-when-and-where-of-active-directory-attribute-changes-part-i-the-case-of-the-mysteriously-modified-upn.aspx

Tracking changes in AD is usually a difficult task if you do not using third party Tools to monitor changes. The one I usually recommend is Lepide Auditor Suite for Active Directory: http://www.lepide.com/lepideauditor/active-directory.html

Free Windows Admin Tool Kit Click here and download it now
February 11th, 2015 8:34am

Thanks for sharing your thoughts guys.

I will appreciate your contribution, this very helpful plateform as well.

@ Mr X, I have tested your recommended tool and it's works very cool, especially live-feed feature impressed me.

February 12th, 2015 4:59am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics