Solved

Event log not logging account creations in Exchange server.

Posted on 2010-08-18
11
313 Views
Last Modified: 2012-05-10
When i create a new user account on either of my 2 domain controllers it creates event ID 624 and 626. However if i create the account on my Mail server the account creates just fine but it is not creating those 2 event ID's in the logs. any ideas why?
0
Comment
Question by:tkthelpdesk
  • 6
  • 5
11 Comments
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469629
I am not sure if there is anyway you can log new account creation.
You can crank up diagnostic logging in Exchange 2003 to monitor all logons

Admin Groups
Domain Name
Servers
SERVERNAME
> right click properties
diagnostic logging tab
expand msexchangeIS

Sembee (Exchange MVP) also said so here
http://www.petri.co.il/forums/showthread.php?t=20203
0
 

Author Comment

by:tkthelpdesk
ID: 33469689
Why does it create the event ID's fine on my DC's?
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469698
Are you creating accounts in your mail server using ADUC ?
0
 

Author Comment

by:tkthelpdesk
ID: 33469727
Yes.
0
 

Author Comment

by:tkthelpdesk
ID: 33469745
Guess i could create the account on the DC and then go to the mail server and create a mailbox to it? Just adds a step.
0
 
LVL 28

Accepted Solution

by:
sunnyc7 earned 50 total points
ID: 33469794
0
 

Author Comment

by:tkthelpdesk
ID: 33469866
My auditing for AD is correct as is obvious because the event ID's are needed when i create them on the domain controllers. My problem is not answered in these areticles as to why they do not create in my Mail server logs
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33469889
Will wait for others to post.
0
 

Author Comment

by:tkthelpdesk
ID: 33470590
ok figured it out....kinda. My Mail server was authentcating to DC2 so when i created account, nothing was showing up in logs of DC2 (i read an artice that said because account is really being created in AD not on Mail server it wont show up in mail logs). When i forced the mail server to authenticate onto DC1 the files apear in DC1 security logs.
0
 

Author Closing Comment

by:tkthelpdesk
ID: 33470596
Thanks for helping me figure this out.
0
 
LVL 28

Expert Comment

by:sunnyc7
ID: 33470692
You're welcome. didnt know that part @ DC2 :)
I am glad it worked out.

thanks for the points.
0

Join & Write a Comment

In this article, we will see the basic design consideration while designing a Multi-tenant web application in a simple manner. Though, many frameworks are available in the market to develop a multi - tenant application, but do they provide data, cod…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
In this video we show how to create a Shared Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Sha…
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now