Who made a change to a domain acounts privileges?


hi

a domain account sabotaged in environment , have been tasked to discover did it.

i have 60 dc's in geographically dispersed private cloud running win2k3. admins granted high level of trust pretty much all of them have domain admin rights.

it appears high level admin rights has modified users group memberships.

i have attempted search through logs on 1 of dc's without success.

thousands of security logs , search users name returns nothing.

it perfect if there tool similar lockoutstatus.exe

i have tried using eventcombmt, after long search no useful information returned (i don’t know how use it)

 

any appreciated

doug

hi

a domain account sabotaged in environment , have been tasked to discover did it.

i have 60 dc's in geographically dispersed private cloud running win2k3. admins granted high level of trust pretty much all of them have domain admin rights.

it appears high level admin rights has modified users group memberships.

i have attempted search through logs on 1 of dc's without success.

thousands of security logs , search users name returns nothing.

it perfect if there tool similar lockoutstatus.exe

i have tried using eventcombmt, after long search no useful information returned (i don’t know how use it)

 

you can find out when/where/what time using repadmin /showobjmeta, can found if auditing enabled prior change taken place. using repadmin /showobjmeta shows on dc changes has been made, can search dc's logs changes, else i'm not aware there method find out w/o dc's security logs.

http://blogs.technet.com/b/askpfeplat/archive/2012/03/05/how-to-track-the-who-what-when-and-where-of-active-directory-attribute-changes-part-i-the-case-of-the-mysteriously-modified-upn.aspx

http://blogs.msdn.com/b/dsadsi/archive/2009/10/02/can-we-know-who-has-changed-an-attribute-in-active-directory.aspx


awinish vishwakarma - mvp

my blog: awinish.wordpress.com

disclaimer posting provided as-is no warranties/guarantees , confers no rights.



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS