User removed from AD group


hi

we running 2003 ad. auditing enabled on dc's.

we have security group, , someone/something keeps removing user group.

i figure can run eventcomb on our dc's find out who/what did this, have no idea search for...

there ms link here security events:

http://support.microsoft.com/kb/174074

if user user1 , group group1, know should entering in event comb find out did this?

assuming have account management audit enabled, can find relevant event ids at http://technet.microsoft.com/en-us/library/cc737542(ws.10).aspx (details depend on group type)

hth
marcin


Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group