Monitor domain account changes

Active Directory Management usually do when sometimes need to know which domain administrator account to do the operation, you need to use the audit log. By default, the record is not who created the account, what has changed content. Especially in the case of multi-manager, it is especially important.
You can achieve this by enabling audit policy.
In the domain level to build a new GPO, and then edit them Computer Configuration - Policies - Windows Settings - Security Settings - Local Policies - Security Options - Audit: Force audit policy subcategory settings (Windows Vista or later) to override audit policy category settings.
Enabling this strategy to adopt advanced audit policy. If you do not see the map, please point me .
Monitor domain account changes
And then edit the Computer Configuration - Policies - Windows Settings - Security Settings - Advanced Audit Policy Configuration - Audit Policies - Account Management - Audit User Account Management
Monitor domain account changes
should do it. I remember running gpupdate on the domain controller / force refresh policy.
In the security log of the system will be able to see the appropriate information.
The following event ID for reference.

1.Event ID 4720 to create a user account.
2.Event ID 4722 user accounts enabled.
3.Event 4740 ID user account is locked.
4.Event 4725 ID user account is disabled.
5.Event 4726 ID user account is deleted.
6. Event ID 4738 user accounts to change.
7.Event ID 4781 renamed user account.

Guess you like

Origin blog.51cto.com/qiyuwei/2421501