Windows Server 2008 offeres the ability to record changes to AD objects. Both what the value of the object was, and what it is now. It also records who did it. Below is the procedure to set it up. - Open Group Policy Manager - Expand you forest until you get to the Default Domain Policy . - Right click the Default Domain Policy and click Edit . - Expand Computer Configuration --> Windows Settings -->Security Settings --> Local Policies and click Audit Policy . - Set Audit directory services access to log both success and failures. - Close Group Policy Manager . - Open a command prompt. - Type auditpol /set /subcategory:"directory service changes" /success:enable You can verify the current settigns by using the following command: auditpol /get /category:"DS Access" In the lab, the next step was to create and modify user account. What the lab did not do is tell us to enable auditing for the account being used. - Open Active Directory Users
Welcome to the blogsite of MCTExpert. I am a Microsoft Certified Trainer. Here you will find the real questions that are asked to me by my students.