Are AD Object moves/deletions recorded in event viewer?

JoeyBugeyes
JoeyBugeyes used Ask the Experts™
on
Hello,

If a user object in Active Directory is deleted, is there an event log entry that will tell me who deleted it, and when?  
If so, is this something you can turn on/off?  How?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Head of ICT
Top Expert 2009
Commented:
You would need to enabled auditing on your DCs to log this sort of event:
In the default domain controller GPO:
Computer Config > Windows Settings > Security Settings > Local Policies > Audit Policy
Enable:
'Audit object access' (at least success)
'Audit directory service access' (at least success)
Now you need to enable auditing on the objects in question in ADUC. Right click an OU in question > properties > security > auditing > add the group of users who you wish to audit, then you can select what actions you wish to audit, e.g. create user objects, delete computer objects etc...
Yes definitelly, if you turn on auditing in group policy.
The event group you need to audit is Audit directory service access. In server 2008 you even have 4 subcategories. For subcategory config you need command-line access.
This technet article might help you
Link
Event ID for user account deleted is "630                               "
bluntTonyHead of ICT
Top Expert 2009

Commented:
Correction - I don't think you need to enable 'Audit object access'. Have a read of this:
http://support.microsoft.com/kb/814595 

Author

Commented:
Thank you everyone for you quick and accurate responses.   I appreciate it.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial