Solved

Want AD Tools - User login auditing, file change activity, etc.

Posted on 2009-04-10
5
798 Views
Last Modified: 2012-06-27
Relatively new AD environment for us and I am now looking for some good management and/or auditing tools.  It does not have to be free, commerical products are fine, and we are willing to spend a few thousand bucks to get something that is really good.  Looking for some recommendations from a few people.

Some initial thoughts:

- Would like a way to determine if an AD account is presently logged in.  
- What time did that user login
- Better yet, would like to see login/logout activity for the past x days

- File auditing, who changed what, when, who deleted a file, etc.

We just bought Diskeeper's Undelete product so I'm looking for anything else that's cool :)

Thanks!
0
Comment
Question by:rvthost
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 24

Expert Comment

by:ryansoto
ID: 24118327
You can use the built in auditing tools that come with windows you just need to turn auditing on
0
 
LVL 11

Author Comment

by:rvthost
ID: 24118349
How far do the built-in utilities take it?  Just enabling auditing and then pouring through event logs?  I'm looking for something that has a cleaner reporting-type interface.  thanks for the comment.
0
 
LVL 18

Accepted Solution

by:
Americom earned 300 total points
ID: 24118394
http://www.scriptlogic.com/products/enterprisesecurityreporter/
This product is more than just for file/folder permission, it's good  to report Active Directory object status etc. (See attachment)

Active Administrator:
http://www.scriptlogic.com/products/activeadmin/
This one will allow you to restore AD object instantly. It also shows friendly security of AD objects.
AD Activities can be save in a SQL database and you can receive instant alerts when someone create/delete AD Objects etc.
ESR.bmp
0
 
LVL 24

Assisted Solution

by:ryansoto
ryansoto earned 200 total points
ID: 24118460
GFI is the way to go then

http://www.gfi.com/eventsmanager
0
 
LVL 11

Author Comment

by:rvthost
ID: 24146846
Thanks both for the comments!
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
For anyone that has accidentally used newSID with Server 2008 R2 (like I did) and hasn't been able to get the server running again because you were unlucky (as I was) and had no backups - I was able to get things working by doing a Registry Hive rec…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question