Windows Server logs deleted - Find user who did it?


hi

at thuesday happened overwrite ntfs permissions on share on windows 2012 file server.
instead of telling his/herscolleagues, "sorry did mistake", person log server local administrator (windows account) , delete logs cover mistake up. that!

so question is, there way find out did this?, thoguh logs deleted? there other logs eventviewer logs into?
find in "applications , services logs\microsoft\windows\remotedesktop" connection computer 2 min before logs deleted, , new computer. person had figured out...

so?

thank!

hi,

at point, not possible find out did through system logs, may find out did if have camera/cameras recording.

we should never grant administrative privileges people don’t trust. in addition, make sure 1 user has 1 account in future , ask them change passwords frequently.

best regards,

amy


please remember mark replies answers if , un-mark them if provide no help. if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS