Improve company productivity with a Business Account.Sign Up

x
?
Solved

An Active Directory security group was deleted today. Is there an event ID I can look for an place in the event viewer I should look to find out what happened?

Posted on 2013-05-15
2
Medium Priority
?
569 Views
Last Modified: 2013-05-17
We had an active directory security group vanish today and have to assume one of us deleted it by accident or with a script. Is there a place in the AD event viewer that would display what happened? Windows 2008 domain
0
Comment
Question by:Thor2923
2 Comments
 
LVL 18

Accepted Solution

by:
Sarang Tinguria earned 2000 total points
ID: 39169463
If you have auditing enabled you may search security logs of DC
Find below events based upon security Group type

4754 A security-enabled universal group was created.
4730 A security-enabled global group was deleted.
4734 A security-enabled local group was deleted
0
 
LVL 3

Expert Comment

by:violageek
ID: 39173351
As mentioned if you have auditing enabled you can look for event id 564 and event id 634 and event id 638 that are all related to deletion of objects.

Ref: http://support.microsoft.com/kb/174074
0

Featured Post

Simplify Active Directory Administration

Administration of Active Directory does not have to be hard.  Too often what should be a simple task is made more difficult than it needs to be.The solution?  Hyena from SystemTools Software.  With ease-of-use as well as powerful importing and bulk updating capabilities.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

High user turnover can cause old/redundant user data to consume valuable space. UserResourceCleanup was developed to address this by automatically deleting user folders when the user account is deleted.
Scripts are great for performing batch jobs against users, however sometimes the GUI is all you need.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …

608 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question