Solved

User Acct. is being removed from AD group.

Posted on 2010-09-16
4
644 Views
Last Modified: 2012-06-22
I have added a user account to a Global group, and twice I have found the next day, that the account has been removed from the group.  I have Auding enabled, and have found the Event ID 633....

Type:      Audit Success
Source:      Security
Event ID:      633
Event Time:      9/16/2010 8:21:18 AM
User:      NT AUTHORITY\SYSTEM
Computer:      Pri-DCSVR00
Description:
Security Enabled Global Group Member Removed:
      Member Name:      CN=Joe Blow,OU=Contractors,OU=Technology Department,OU=STL,DC=acme,DC=com
      Member ID:      %{S-1-5-21-1814976544-1464880352-2118856591-5839}
      Target Account Name:      Test_Consult
      Target Domain:      Test
      Target Account ID:      %{S-1-5-21-1814976544-1464880352-2118856591-5712}
      Caller User Name:      -
      Caller Domain:      -
      Caller Logon ID:      (0x0,0x92837100)
      Privileges:      -

I am lost by the "User" that is removing the account from the Group, that user being "NT AUTHORITY\SYSTEM".  Is there a way to find out who or why this is getting removed?
0
Comment
Question by:mbigogno
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 24

Accepted Solution

by:
Mike Thomas earned 250 total points
ID: 33698874
It is possibly being removed by a group policy.
0
 
LVL 24

Expert Comment

by:Mike Thomas
ID: 33698877
And do you really have a contracter called Joe Blow? cos that's a cool name. ;)
0
 
LVL 22

Expert Comment

by:65td
ID: 33705156
I'd be leaning to a GPO as well, look in restricted groups.
0
 

Author Closing Comment

by:mbigogno
ID: 33734378
Sorry it took so long to get back.  Had another administrator mucking around with group policy.  That was the fix.  Thanks.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
A company’s centralized system that manages user data, security, and distributed resources is often a focus of criminal attention. Active Directory (AD) is no exception. In truth, it’s even more likely to be targeted due to the number of companies …
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question