We help IT Professionals succeed at work.

How can you tell who created an Active Directory user object?

46,343 Views
Last Modified: 2012-06-07
Is there a way to tell who created user accounts in Active Directory?  I've found the attribute that tells me when the object was created (whenCreated) but is there any method to determine the creator?


Thanks.

Comment
Watch Question

CERTIFIED EXPERT
Top Expert 2013
Commented:
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION
Justin DurrantSr. Engineer - Windows Server/Virtualization

Commented:
it is tough without a 3rd party auditing product. Your one chance is by looking at the ACL for any telltale ACES and look at the owner listed on the SD. If the user had admin rights in the domain this won't work because it will say administrators
This one is on us!
(Get your first solution completely free - no credit card required)
UNLOCK SOLUTION

Commented:
Usually you can right click on the user object>Properties>Security>Advanced>Owner, only if it was not created by Administrator. The Object will also show you when the object was created and modified.
The only problem with security event viewer is you may need to increase the log size to record a day or two. If your DC is very busy, even with 130MB size could only record 24 hours. Any size larger than that would create viewing problem as the security event log are constant being updated. Without a realy product like MOM or a 3rd party product to manage event log would be tough.
Justin DurrantSr. Engineer - Windows Server/Virtualization

Commented:
^^ right. That is why I mentioned using a 3rd party auditing tool.. the overload on the DC is not worth using normal auditing methods.

Author

Commented:
Thanks everyone!  Looks like event 624 will do the trick.  I did find out that in Win2008/Vista, the event ID is now 4720 just as an FYI.

@mkline71- Very helpful link you provided...Thanks!

@gregcmsce- My DC's were all set to audit that event, so I'm guessing that was default as you mentioned.  As I have not set that.

@Americom- My DC's are very busy and it does flush the old events in the log.  I was going to use a clever workaround with my Vista workstation and Subscribe to these specific 624 events from my DC's.  This way I was hoping it would create a local event log file on my Vista machine eliminating the size problem with the log files.  Of course, I'm not 100% sure it creates a local log file, nor do I think I can subscribe to Win2003 DC events using Vista.  It's a good idea so I'm trying to see if I can get it to work.

Thanks for all of the help and ideas!


Author

Commented:
Split the points as provided same solution and extra information.  Thanks!
If the event logs are overwritten from DC ,than is there option to find out who has created the user account in active directory.

Regards

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Unlock the solution to this question.
Join our community and discover your potential

Experts Exchange is the only place where you can interact directly with leading experts in the technology field. Become a member today and access the collective knowledge of thousands of technology experts.

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.