Re: Audit Admnistrators



You can enable auditing for various categories on domain controllers via
Domain Controller Security Policy such as for account management, object
access, and directory services [for AD objects]. However you need to be
selective in auditing what you think is important or you will need a couple
more people to review all the tens of thousands of entries in the security
logs of domain controllers. The free Event Comb from Microsoft can help in
parsing the logs for events you want to track and text strings such as user
names. To track changes to DNS and DHCP you would probably need to audit the
registry keys used by those services. The link below is to a white paper
from Microsoft that may be helpful. --- Steve

http://www.microsoft.com/technet/security/topics/auditingandmonitoring/securitymonitoring/default.mspx -
-- The Security Monitoring and Attack Detection Planning Guide

"Erasmo" <Erasmo@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:45C7C85A-54F9-4F53-824E-DB3A5346D0F9@xxxxxxxxxxxxxxxx
I'm trying to determine the best way to have my Domain Admins
administrators
to audit each other, what I mean I want to keep track when eithe one of
them
make a change in anything in AD such as DNS, DHCP, AD, etc. What is the
best
method to centralized and keep track of administrators activities.


.



Relevant Pages

  • Re: Event ID 1863
    ... MVP - Directory Services ... Running partition tests on: DomainDnsZones ... Starting test: CrossRefValidation ... number of domain controllers within the configured latency interval. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Receiving a File Replication Service error on 2 DCs.
    ... To migrate a domain controller, reboot the server, press F8 ... boot to Directory Services Restore Mode, and launch the SMP - P2P ... migration of domain controllers, see your HP account manager for the ...
    (microsoft.public.windows.server.active_directory)
  • Re: Event ID 623
    ... Another place to check would be the number of security and distribution ... MVP - Directory Services ... The version store for this instance has reached its ... Event Source: NTDS SDPROP ...
    (microsoft.public.windows.server.active_directory)
  • Re: Security of a virtualized domain controller ?
    ... MVP - Directory Services ... why it protect the physical access to the harddrives please? ... Indeed, if someone stole the VMDK file of our domain controllers, he ...
    (microsoft.public.windows.server.active_directory)
  • Re: Grant Administrative Access to a Domain Controller
    ... MPerrault suggested security, you said "IT CAN BE DONE WITHOUT ANY FANCY ... Joe Richards Microsoft MVP Windows Server Directory Services ... Author of O'Reilly Active Directory Third Edition ...
    (microsoft.public.windows.server.active_directory)