Link to home
Start Free TrialLog in
Avatar of Paul Walsh
Paul Walsh

asked on

Administrator Account Audit

Hi All,

We are going through a process of changing the password and remvoing as much as possible the network administrator account. Histroically it has been used to authenticate a number of systems. What is the easiest way to find out which servers/services/system are still using this account?

I have been going through the services (logonas) on each server. Account audit is turned on in Group Policy. I can see anumber of events 6224 for the target account on the DC's. How can i easily check in the security event log for when that account has been used / what has used it?

Thanks for your help.

Paul
ASKER CERTIFIED SOLUTION
Avatar of McKnife
McKnife
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial