F
fex
Hello,
I've been auditing multiple events (System Events ,
Policy Changes , Logon Events , but specially all events
referents to Account management events like (User Account
create, User Account Deleted , etc ) However , I applied
the auditing to the default group everyone on Defaul
Domain Controller Policy , to check specially all changes
made by users with domain admin rights. But at this moment
they are changing users -passwords - deleting users and -
I don't receive any event id; for instance (ID:624-627-630)
at the moment they applied any change on the DC.
I would like to know what is my misconfiguration or I need
more configuartion or the default group it is not applied
right way ?
I will thanks any comment !!!
I've been auditing multiple events (System Events ,
Policy Changes , Logon Events , but specially all events
referents to Account management events like (User Account
create, User Account Deleted , etc ) However , I applied
the auditing to the default group everyone on Defaul
Domain Controller Policy , to check specially all changes
made by users with domain admin rights. But at this moment
they are changing users -passwords - deleting users and -
I don't receive any event id; for instance (ID:624-627-630)
at the moment they applied any change on the DC.
I would like to know what is my misconfiguration or I need
more configuartion or the default group it is not applied
right way ?
I will thanks any comment !!!