Solved

find out who deleted a group in AD (2008)

Posted on 2011-02-18
8
995 Views
Last Modified: 2012-05-11
I have the basic auditing on our Domain Controller running server 2008. Someone deleted a couple of groups and I need to find out who.

How can I find out who removed those groups in Active Directory?
0
Comment
Question by:willlandymore
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 14

Assisted Solution

by:athomsfere
athomsfere earned 250 total points
ID: 34926970
You have to have the auditing enabled when the object is changed, do you know if you have done this?

http://technet.microsoft.com/en-us/library/cc731607%28WS.10%29.aspx
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34927061
they're all listed as 'not defined' so I guess they haven't been turned on.

Is the one for "Audit directory service access" the one that will show deletions and where does it show up in then event logs?
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34927103
okay, I think I found it.

I think it's the "Audit Account Management" one but it says the default is to log success on Domain Controllers so that means if someone deleted the account I should have a success audit saying so
0
Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 34927162
Yes if you have auditing configured then you will see that event telling you the group was deleted.  More info on the events here:

http://technet.microsoft.com/en-us/library/cc737542(WS.10).aspx

I can take a screenshot later this weekend from my lab if that helps

thanks

Mike
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34927314
yeah, if I knew which part of the tree it's showing up in that would be good so a picture might help. :)
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 34927337
It would be in the security log on the DC.
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34927352
okay, that's the one I'm looking through now
0
 
LVL 1

Author Comment

by:willlandymore
ID: 34927357
thanks for the help
0

Featured Post

Forrester Webinar: xMatters Delivers 261% ROI

Guest speaker Dean Davison, Forrester Principal Consultant, explains how a Fortune 500 communication company using xMatters found these results: Achieved a 261% ROI, Experienced $753,280 in net present value benefits over 3 years and Reduced MTTR by 91% for tier 1 incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question