Authored by: Support.com Tech Pro Team
How to Track Changes Made in Active Directory
Type the command gpmc.msc in order to open the Group Policy Management Console.
Under Group Policy Management, select the forest domain you wish to choose and expand it further to navigate to the Domain Controllers→ Default Domain Controller Policy, right click on it and select Edit to open the configuration window.
Navigate to Computer Configuration> Policies> Windows Settings> Security Settings> Advanced Audit Policy Configuration> Audit Policies in the GPMC Editor.
In order to configure all the policies, define the following categories and then configure them one after another:
Click on the first policy – Account Logon and configure the audit events of its subcategories one after another.
In the Policy tab of Audit Credential Validation Window, simply check both the options – success and failure to audit the events and click OK.
Follow the step 6 for all other Advanced Audit Policies listed above.
This can be done by executing the command: gpupdate /force in the command prompt.
Then, proceed on to connect to the default naming context. Also, Right click on the node = “ADSIEdit†and select “Connect Toâ€.
Configuring Default Naming Context
Configuring Connection Settings
Establishing connection with Root DSE
Connection Settings for Schema
For all the four root nodes of different naming contexts, enable the auditing settings.
In the Domain Controller properties, navigate to the security tab and click Advanced. This will open the Advanced Security Settings. Now, quickly navigate to the Auditing tab and click Add to open the Auditing Entry window. In the field “Nameâ€- type “Everyone†and in the “Access†section, check all the boxes except the following four options:
In the ADSI Edit, repeat steps 3 and 4 in order to enable the auditing of the remaining root nodes.
View audit logs in event viewer to track AD changes by searching relevant event ids
In the Event Viewer, navigate to Windows Logs and select Security. Then, simply click Filter Current Log.
In the “Filter Current Log†window, simply enter the particular Event ID and carry out the search operation. In above image event id 4720 refers to ‘User Account Creation’. have
To know more about any particular event, simply double click on it to see further details.