Paul Walsh
asked on
Administrator Account Audit
Hi All,
We are going through a process of changing the password and remvoing as much as possible the network administrator account. Histroically it has been used to authenticate a number of systems. What is the easiest way to find out which servers/services/system are still using this account?
I have been going through the services (logonas) on each server. Account audit is turned on in Group Policy. I can see anumber of events 6224 for the target account on the DC's. How can i easily check in the security event log for when that account has been used / what has used it?
Thanks for your help.
Paul
We are going through a process of changing the password and remvoing as much as possible the network administrator account. Histroically it has been used to authenticate a number of systems. What is the easiest way to find out which servers/services/system are still using this account?
I have been going through the services (logonas) on each server. Account audit is turned on in Group Policy. I can see anumber of events 6224 for the target account on the DC's. How can i easily check in the security event log for when that account has been used / what has used it?
Thanks for your help.
Paul
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.