Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

automate notification for disable user account in AD

Posted on 2016-10-05
4
Medium Priority
?
86 Views
Last Modified: 2016-10-06
We run Windows Server 8 R2 with Exchange 2010. Is there a script to get notification  as soon as the user go into disabled status in AD?
0
Comment
Question by:TreeRootHD
  • 2
4 Comments
 
LVL 40

Accepted Solution

by:
Subsun earned 1000 total points
ID: 41829881
If you are talking about alert for any disabled user account, better enable active directory auditing and create a alert for  Security log for event ID’s 4725 (User Account Management task category).

Set email alert   for an event  
https://blogs.technet.microsoft.com/jhoward/2010/06/16/getting-event-log-contents-by-email-on-an-event-log-trigger/

If you are trying to monitor a single user, then PowerShell script is better option..
0
 
LVL 58

Assisted Solution

by:McKnife
McKnife earned 1000 total points
ID: 41829900
Setup a scheduled task on all of your DCs that uses event triggers. When account management is audited at the DCs, an event is logged to their security event logs. You can define an action that notifies you very simple using powershell mailing.

Steps:
1 create and right away disable a test account
2 open the DC's eventvwr and in it, the security log. Search for the username (1) so you'll find the event number and all.
3 create a task that gets triggered by this event and sends you the event (2) as body

If you need further help, just say

Edit: sorry subsun... just got distracted while writing and now yours was there, first.
0
 
LVL 40

Expert Comment

by:Subsun
ID: 41829928
No worries :-)
0
 

Author Closing Comment

by:TreeRootHD
ID: 41832020
That worked well. Thank you both.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Understanding the various editions available is vital when you decide to purchase Windows Server 2012. You need to have a basic understanding of the features and limitations in each edition in order to make a well-informed decision that best suits …
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…
Loops Section Overview

571 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question