Tracking the ID deletion from which user, workstation and process.


hello experts,

thanks in advance....

couple of ad ids deleted in span of couple of minutes (combination of disabled, enabled user couple of different ous).

ad security event 4726 show id deletion time , account deleted ids

ad security event 4624 event confims account deleted ids shown in 4726 event, has logon authenticated events @ time of incident specific computer

so question how can conclude accounts deleted user accidently or automated mailicious process or program

can correlate these 2 events directly?? wanted root cause.

also 4624 event shows

logon type 3 – network in 4624 event.(is true user not logged on computer interactively from connect keyboard of computer)

required in identifying more logon type 3

thanks.....

you need identify user account used operation. can logged events in event viewer. see more details how can track: http://blogs.technet.com/b/brad_rutkowski/archive/2006/09/21/hey-who-deleted-that-user-from-ad.aspx

please note tracking such events time consuming , complex task. why there third party tools make auditing easier through ui , reporting. favorite lepide auditor active directoryhttp://www.lepide.com/lepideauditor/active-directory.html you can contact them evaluation period can helpful identify doing in ad.


this posting provided no warranties or guarantees , , confers no rights.

ahmed malek

my website link

my linkedin profile

my mvp profile




Windows Server  >  Directory Services



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group