Solved

Want AD Tools - User login auditing, file change activity, etc.

Posted on 2009-04-10
5
795 Views
Last Modified: 2012-06-27
Relatively new AD environment for us and I am now looking for some good management and/or auditing tools.  It does not have to be free, commerical products are fine, and we are willing to spend a few thousand bucks to get something that is really good.  Looking for some recommendations from a few people.

Some initial thoughts:

- Would like a way to determine if an AD account is presently logged in.  
- What time did that user login
- Better yet, would like to see login/logout activity for the past x days

- File auditing, who changed what, when, who deleted a file, etc.

We just bought Diskeeper's Undelete product so I'm looking for anything else that's cool :)

Thanks!
0
Comment
Question by:rvthost
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 24

Expert Comment

by:ryansoto
ID: 24118327
You can use the built in auditing tools that come with windows you just need to turn auditing on
0
 
LVL 11

Author Comment

by:rvthost
ID: 24118349
How far do the built-in utilities take it?  Just enabling auditing and then pouring through event logs?  I'm looking for something that has a cleaner reporting-type interface.  thanks for the comment.
0
 
LVL 18

Accepted Solution

by:
Americom earned 300 total points
ID: 24118394
http://www.scriptlogic.com/products/enterprisesecurityreporter/
This product is more than just for file/folder permission, it's good  to report Active Directory object status etc. (See attachment)

Active Administrator:
http://www.scriptlogic.com/products/activeadmin/
This one will allow you to restore AD object instantly. It also shows friendly security of AD objects.
AD Activities can be save in a SQL database and you can receive instant alerts when someone create/delete AD Objects etc.
ESR.bmp
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 200 total points
ID: 24118460
GFI is the way to go then

http://www.gfi.com/eventsmanager
0
 
LVL 11

Author Comment

by:rvthost
ID: 24146846
Thanks both for the comments!
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will walk an individual through locating and launching the BEUtility application to properly change the service account username and\or password in situation where it may be necessary or where the password has been inadvertently change…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question