[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 260
  • Last Modified:

Group Membership change

Hi,

We are using Windows server 2003 domain controllers. I have a small query regarding group memership. We have a global group called GLOBALUSERS. This group is currently having 200 users. Two users added recently by someone. I would like to know who are all the users recently added to this group and the Date when these users are added to this group?

I know event id 632 can help this out.But we are running around 50 Domain controllers, so it will not be possible for to check the event logs on Domain controllers.

Please provide me any command or script which can resolve my query.
0
gaddam01
Asked:
gaddam01
1 Solution
 
HeshamMousaCommented:
this query will give you the date of creation and modification

dsquery * -filter "(objectCategory=group)" -attr cn whenChanged whenCreated
0
 
Mike KlineCommented:
You will need to search logs to view audit information, eventcomb can help you go through logs on multiple DCs    http://support.microsoft.com/kb/824209

There are third party tools that can help with event logs and managing them; those can get expensive though.

Thanks

Mike
0
 
HeshamMousaCommented:
this script will go through all DCs and collect group auditing events

http://blog.powershell.no/tag/active-directory-group-membership-auditing/
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
gaddam01Author Commented:
Hi,

Thanks for the reply. But in the query dsquery * -filter "(objectCategory=group)" -attr cn whenChanged whenCreated can you please provide what are the parameters here I need to pass for group and for cn?
0
 
HeshamMousaCommented:
nothing to be specified just use it in CMD and it will get all groups with both dates and if you want to export it just use >>c:\groups.csv

this has a limit of displaying only 100 if you have more just add - limit 10000 before >>c:\  
0
 
gaddam01Author Commented:
But I would like to know when that particular user has been added to the group GLOBAL USERS. I know the user id and how to find the date when this user has been added to the group?
0
 
HeshamMousaCommented:
this will be using the script provided above as it reports the member and the addition date
0
 
vinitoguptaCommented:
just use manage engine AD Manager and you can run audit from their too
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now