RE: How do I find out who disabled an account in AD?

From: Ed02862 (Ed02862_at_discussions.microsoft.com)
Date: 07/21/05


Date: Thu, 21 Jul 2005 08:06:03 -0700

We have "Audit account management" set to "success,failure. I don't see
"audit directory service object" in our AD group policy.

My question is what do I search for in the security log? Do I search for
the word "disabled"? I'm just looking in a TXT version of the exported
security event log, is there somewhere else within AD that I can look? Sorry
for all the questions, I'm really out of my league with this task.

Thanks

"Wong Tuck Wah" wrote:

> If you have enabled the "audit directory service object" policy, all access
> to AD objects will log in security log.
>
> Search for this disabled object and look at the details inform. Pay
> emphasize on the time, date, user and computer attributes. It will tell you
> the object is disabled by which user on which computer.
>
> HTH.
>



Relevant Pages

  • Re: delete user from AD and not exchange
    ... If you have audit account management turned on you will be able to find ... who and when by looking in the security log on your domain controller. ... system manager reconnect this new user to the old mailbox. ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Re: add machine to domain event ID?
    ... You should turn auditing on "Audit account management" (if I remember ... Then you should be able to see events in security log. ...
    (microsoft.public.win2000.security)
  • RE: Event for Password Changes
    ... open domain controller security policy and make audit account management ... Then when user changed password, in the security log, There are several ... Windows 2003 server and SBS 2003 can also support audit ...
    (microsoft.public.windows.server.sbs)
  • Anonymous change of passwords?
    ... BTW - Windows 2003 seems to completely ignore the bit i ... but Windows 2003 doesn't modify this ... In the security log I found the ... >Audit Account Management 627 NT ...
    (microsoft.public.security)
  • Re: securing the event log
    ... There is a user right assignment for managing auditing and security log that would ... Also check ntfs permissions on the .evt files ... it could also be configured as restricted in Group Policy ... > find any reference to locking out the event log. ...
    (microsoft.public.windowsxp.security_admin)