Audit domain admins

From: Misaro (anonymous_at_discussions.microsoft.com)
Date: 11/23/04


Date: Tue, 23 Nov 2004 12:38:31 -0800

Hi,

I need to audit or verify every change that any user with
domain admin rights do in the Domain Controller.

For instance: User Beth, she removed domain admin rights
to another user who had them. For that reason the user had
several problems working on a project. So the point is how
may I know that she did it ? 'Cos at the same time she has
full rights? How to audit that , or any software to check
and keep a log about what changes or movements do all
domain admins users !!

Thanks any comments !!!



Relevant Pages

  • Re: Domain admin users audit
    ... The first step is to enable auditing. ... I need to audit or verify every change that any user with domain admin rights do in the Domain Controller. ...
    (microsoft.public.win2000.active_directory)
  • Domain admin users audit
    ... she removed domain admin rights ... How to audit that, ...
    (microsoft.public.win2000.active_directory)
  • Re: Service accounts best practices
    ... guidance on granting admin accounts. ... >> The only people who should have domain admin rights are the exact people ... >> doing domain admin work and it should be a very small group. ... >>>>Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.win2000.security)
  • Re: Audit domain admins
    ... or "tell me everything any Domain Admin ... cause an audit record. ... can also clear the logs or shut logging off. ... > domain admin rights do in the Domain Controller. ...
    (microsoft.public.win2000.security)
  • Re: What permissions are needed to migrate SID?
    ... The user running ADMT must have Domain Admin rights in the source domain, ... he must have administrator rights on the machine running ADMT. ... One of my customer suggests that it would be best to delegate permissions ...
    (microsoft.public.windows.server.migration)