nav2567
asked on
DNS Auditing question
Our default domain controller policy has the "Audit Directory Service Access" enabled and log all success events for group EVERYONE.
We have some missing production DNS records. Exactly where do I look in the event log and what event I can look for in order to determine who removed the DNS records?
Someone who knows please advise.
We have some missing production DNS records. Exactly where do I look in the event log and what event I can look for in order to determine who removed the DNS records?
Someone who knows please advise.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER