Solved

Event log not logging account creations in Exchange server.

Posted on 2010-08-18
11
330 Views
Last Modified: 2012-05-10
When i create a new user account on either of my 2 domain controllers it creates event ID 624 and 626. However if i create the account on my Mail server the account creates just fine but it is not creating those 2 event ID's in the logs. any ideas why?
0
Comment
Question by:tkthelpdesk
  • 6
  • 5
11 Comments
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469629
I am not sure if there is anyway you can log new account creation.
You can crank up diagnostic logging in Exchange 2003 to monitor all logons

Admin Groups
Domain Name
Servers
SERVERNAME
> right click properties
diagnostic logging tab
expand msexchangeIS

Sembee (Exchange MVP) also said so here
http://www.petri.co.il/forums/showthread.php?t=20203
0
 

Author Comment

by:tkthelpdesk
ID: 33469689
Why does it create the event ID's fine on my DC's?
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469698
Are you creating accounts in your mail server using ADUC ?
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:tkthelpdesk
ID: 33469727
Yes.
0
 

Author Comment

by:tkthelpdesk
ID: 33469745
Guess i could create the account on the DC and then go to the mail server and create a mailbox to it? Just adds a step.
0
 
LVL 28

Accepted Solution

by:
sunnyc7 earned 50 total points
ID: 33469794
0
 

Author Comment

by:tkthelpdesk
ID: 33469866
My auditing for AD is correct as is obvious because the event ID's are needed when i create them on the domain controllers. My problem is not answered in these areticles as to why they do not create in my Mail server logs
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469889
Will wait for others to post.
0
 

Author Comment

by:tkthelpdesk
ID: 33470590
ok figured it out....kinda. My Mail server was authentcating to DC2 so when i created account, nothing was showing up in logs of DC2 (i read an artice that said because account is really being created in AD not on Mail server it wont show up in mail logs). When i forced the mail server to authenticate onto DC1 the files apear in DC1 security logs.
0
 

Author Closing Comment

by:tkthelpdesk
ID: 33470596
Thanks for helping me figure this out.
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33470692
You're welcome. didnt know that part @ DC2 :)
I am glad it worked out.

thanks for the points.
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Read this checklist to learn more about the 15 things you should never include in an email signature.
To show how to create a transport rule in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Rules tab.:  To cr…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question