Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Active Directory Security Group Audit

Posted on 2014-04-04
7
Medium Priority
?
567 Views
Last Modified: 2014-04-11
Greetings!

I do not currently have any A.D. auditing tools in place. A security group was added to the Domain Admins security group and I am needing to find out how it was added. Is there an event in the event log I can check or an A.D. log to check this?
0
Comment
Question by:Schuyler Dorsey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 51

Assisted Solution

by:Netman66
Netman66 earned 1000 total points
ID: 39979466
Check the Security log on a DC.  There should be an event shown there that is related.
0
 
LVL 10

Author Comment

by:Schuyler Dorsey
ID: 39979468
Thanks. Do you happen to know event codes or anything?
0
 
LVL 10

Author Comment

by:Schuyler Dorsey
ID: 39979471
I found 4728: A member was added to a security-enabled global group.

But this seems to list individual accounts added, not security groups added to security groups.
0
Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

 
LVL 10

Author Comment

by:Schuyler Dorsey
ID: 39979474
Nevermind. 4728 shows the sec groups being added but I don't see an entry for the one needed. I am guessing it was done long enough ago the events were overwritten.
0
 
LVL 51

Expert Comment

by:Netman66
ID: 39979504
Sorry, using my phone to answer.  It may have been overwritten as default log size is 4Mb.
0
 
LVL 37

Accepted Solution

by:
Mahesh earned 1000 total points
ID: 39979737
You need to setup audit account management, audit directory service and audit privilege use for success and failure in default domain controller policy under audit policy if you wanted to track these kind of events
Also you need to increase security events log size on domain controllers and save them on regular basis , other wise those logs will wipe out as required

Also one more thing towards your issue

Please how many accounts are member of domain admins and built-in administrators group in active directory
Some one who has membership of these groups only can add \ remove new accounts \ groups in domain admins \ enterprise admins and built-in administrators

You need to remove unwanted accounts from these well known high privileged groups other wise one can modify AD and also can cleanup security events as well

Please check how to setup auditing on Domain controllers
http://blogs.technet.com/b/askpfeplat/archive/2012/04/22/who-moved-the-ad-cheese.aspx
http://technet.microsoft.com/en-us/library/cc731607(v=ws.10).aspx

Mahesh.
0
 
LVL 56

Expert Comment

by:McKnife
ID: 39980055
And to find out the event ID: simply add a test account/group and see what gets logged.
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Microsoft Office 365 is a subscriptions based service which includes services like Exchange Online and Skype for business Online. These services integrate with Microsoft's online version of Active Directory called Azure Active Directory.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question