• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 3337
  • Last Modified:

event ID of AD object being deleted

hello experts
our domain level is windows 2008 R2, today i found an AD account being deleted by someone, i what to know who did this, may i find it out from event viewer?
if yes, which event ID will record this action?

thank you
2 Solutions
SandeshdubeySenior Server EngineerCommented:
If auditing is enable you can track the same.

In order to find out changes, creation or deletion events, you must keep the “Account Management” auditing enabled.

Apart from the auditing, you can use third party tools like Quest and Ntewrix to find out WHO changed WHAT, WHEN, and WHERE to list additions, deletions, and modifications made to Active Directory users, groups, computers, OUs, group memberships.
NetWrix tool : http://www.netwrix.com/active_directory_change_reporting_freeware.html
Quest: http://www.quest.com/changeauditor-for-active-directory/

If auditing is not enabled, still you can find out changes were made on which DC and when using repadmin /showobjmeta

Hey who deleted that user from AD???http://blogs.technet.com/b/brad_rutkowski/archive/2006/09/21/hey-who-deleted-that-user-from-ad.aspx

Tracing down user and computer account deletion in Active Directory
For computer account deletion:

·         On Windows 2003, we should get Event ID: 647

·         On Windows 2008, we should get Event ID: 4743

For User account deletion:

·         On Windows 2003, we should get Event ID: 630

·         On Windows 2008, we should get Event ID: 4726

For the complete process of tracing down the account deletion, please refer the below link..

beardog1113Author Commented:
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily manage email signatures in Office 365

Managing email signatures in Office 365 can be a challenging task if you don't have the right tool. CodeTwo Email Signatures for Office 365 will help you implement a unified email signature look, no matter what email client is used by users. Test it for free!

Tackle projects and never again get stuck behind a technical roadblock.
Join Now