Solved

Fomer ColleagueOU contents deleted

Posted on 2007-03-30
3
279 Views
Last Modified: 2010-04-20
Hi,

In my ADS there is a OU called former Colleague in that we move in disabled user accounts suddenly i see today that all the users are deleted how can i find who deleted and from which machine this has happened.

THX
Sharath
0
Comment
Question by:bsharath
  • 2
3 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 500 total points
ID: 18822762
If you have auditing turned on for the "Directory Service Access" event category, this will appear in the Security logs in the Event Viewer on your domain controllers.

Though it may be shutting the barn door after the horse has bolted where this particular incident is concerned, here is a step-by-step KB for configuring auditing of Active Directory objects: http://support.microsoft.com/kb/814595/

Hope this helps.

Laura E. hunter - Microsoft MVP: Windows Server - Networking
0
 
LVL 11

Author Comment

by:bsharath
ID: 18840894
Can we enable auditing on a win xp and win 2003 local machines.

How do i do this.

THX
Sharath
0
 
LVL 30

Expert Comment

by:LauraEHunterMVP
ID: 18842275
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
User having issues with opening files Server 2012 5 34
How to find the user path in AD by find now. 3 32
Internet Protocol Security question 3 66
ACTIVE DIRECTORY 18 43
Remote Apps is a feature in server 2008 which allows users to run applications off Remote Desktop Servers without having to log into them to run the applications.  The user can either have a desktop shortcut installed or go through the web portal to…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now