• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 263
  • Last Modified:

Group Membership change

Hi,

We are using Windows server 2003 domain controllers. I have a small query regarding group memership. We have a global group called GLOBALUSERS. This group is currently having 200 users. Two users added recently by someone. I would like to know who are all the users recently added to this group and the Date when these users are added to this group?

I know event id 632 can help this out.But we are running around 50 Domain controllers, so it will not be possible for to check the event logs on Domain controllers.

Please provide me any command or script which can resolve my query.
0
gaddam01
Asked:
gaddam01
1 Solution
 
HeshamMousaCommented:
this query will give you the date of creation and modification

dsquery * -filter "(objectCategory=group)" -attr cn whenChanged whenCreated
0
 
Mike KlineCommented:
You will need to search logs to view audit information, eventcomb can help you go through logs on multiple DCs    http://support.microsoft.com/kb/824209

There are third party tools that can help with event logs and managing them; those can get expensive though.

Thanks

Mike
0
 
HeshamMousaCommented:
this script will go through all DCs and collect group auditing events

http://blog.powershell.no/tag/active-directory-group-membership-auditing/
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
gaddam01Author Commented:
Hi,

Thanks for the reply. But in the query dsquery * -filter "(objectCategory=group)" -attr cn whenChanged whenCreated can you please provide what are the parameters here I need to pass for group and for cn?
0
 
HeshamMousaCommented:
nothing to be specified just use it in CMD and it will get all groups with both dates and if you want to export it just use >>c:\groups.csv

this has a limit of displaying only 100 if you have more just add - limit 10000 before >>c:\  
0
 
gaddam01Author Commented:
But I would like to know when that particular user has been added to the group GLOBAL USERS. I know the user id and how to find the date when this user has been added to the group?
0
 
HeshamMousaCommented:
this will be using the script provided above as it reports the member and the addition date
0
 
vinitoguptaCommented:
just use manage engine AD Manager and you can run audit from their too
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now