Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 213
  • Last Modified:

How can I run an audit on Active directory admin users to see what they have changed.

We have to give admin permissions in Active Directory for people to do user admin tasks like change passwords etc. A particular user who had this role gave himslf rights to open the MD's mailbox in exchange. Is there anyway we can lock this down or even better give them access but audit if they change anything in AD for example give himself access to someones mailbox.

Cheers Guys glad for any help on this
0
HBPROCK
Asked:
HBPROCK
  • 2
  • 2
2 Solutions
 
KCTSCommented:
You need to aduit account management and privilaged use for the users see
http://technet.microsoft.com/en-us/library/cc737542.aspx
0
 
tigermattCommented:

Why are you giving users Domain Admins access just to perform simple tasks such as Reset Passwords, Unlock User Accounts etc.? This completely defies the rule of 'only give just as many permissions as required' - having users as complete Domain Admins when it isn't required is just a major security risk.

I suggest you remove these Domain Admin privileges from users, and add all the users who need the elevated privileges to a Security group. You can then Delegate Control over particular OUs to that security group - so you can delegate the rights to reset a password without the need for users to be a major security risk to your company network. See http://www.windowsecurity.com/articles/Built-in-Groups-Delegation.html.

And as for auditing what has already been done, you can use the approach KCTS has posted, but remember you CANNOT enable this and expect to see audit logs from before it was enabled. You can only see the audited logs from the moment of enabling this feature.

-tigermatt
0
 
HBPROCKAuthor Commented:
Hi guys thanks for you replys I have turned this on and there already seems to be loads of security logs flying around in event viewer especialy logon logoff etc. I can now see if an admin goes in and resets a password but doesn't seem to show anything if they goint a user and give themselves access to there mailbox. Also is this the only way of logging as it seems that you have to keep an eye on it all the time is there no way it can just email you when a certain event occurs?

Thanks
0
 
tigermattCommented:

Natively, Windows uses the Security event log to log audited events - that is what that event log exists for in the first place. There's no native method by which you can set yourself to be emailed if something happens, and it is expected for lots of events to be flying around as a result of auditing. You need to be very careful precisely what you audit - and only audit just enough - to ensure you do not fill the event logs too quickly and cause a detriment to the server performance.

-tigermatt
0
 
HBPROCKAuthor Commented:
Ok guys thanks for your help!
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now