Tracking the ID deletion from which user, workstation and process.
hello experts,
thanks in advance....
couple of ad ids deleted in span of couple of minutes (combination of disabled, enabled user couple of different ous).
ad security event 4726 show id deletion time , account deleted ids
ad security event 4624 event confims account deleted ids shown in 4726 event, has logon authenticated events @ time of incident specific computer
so question how can conclude accounts deleted user accidently or automated mailicious process or program
can correlate these 2 events directly?? wanted root cause.
also 4624 event shows
logon type 3 – network in 4624 event.(is true user not logged on computer interactively from connect keyboard of computer)
required in identifying more logon type 3
thanks.....
you need identify user account used operation. can logged events in event viewer. see more details how can track: http://blogs.technet.com/b/brad_rutkowski/archive/2006/09/21/hey-who-deleted-that-user-from-ad.aspx
please note tracking such events time consuming , complex task. why there third party tools make auditing easier through ui , reporting. favorite lepide auditor active directory: http://www.lepide.com/lepideauditor/active-directory.html you can contact them evaluation period can helpful identify doing in ad.
this posting provided no warranties or guarantees , , confers no rights.
ahmed malek
Windows Server > Directory Services
Comments
Post a Comment