Click here to get back home

"Who disabled the user" problem

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
"Who disabled the user" problem Special Access 03-28-2007
Posted by Special Access on March 28, 2007, 9:38 pm
Please log in for more thread options
Although I have done several searches online and through the event
log...

Is there a way to tell who created a user, and who disabled a user in
Active Directory (2003 native mode). If not who did, how about what
do we need to set in order to tell who will (sometime in the future)



Thanks... I hate political bs on the job <g>

Mike

Posted by DaveMo on March 29, 2007, 11:21 am
Please log in for more thread options
> Although I have done several searches online and through the event
> log...
>
> Is there a way to tell who created a user, and who disabled a user in
> Active Directory (2003 native mode). If not who did, how about what
> do we need to set in order to tell who will (sometime in the future)
>
> Thanks... I hate political bs on the job <g>
>
> Mike

Setting a SACL on the user objects should do the trick.

HTH.

Dave


Posted by Roger Abell [MVP] on March 29, 2007, 1:39 pm
Please log in for more thread options

> Although I have done several searches online and through the event
> log...
>
> Is there a way to tell who created a user, and who disabled a user in
> Active Directory (2003 native mode). If not who did, how about what
> do we need to set in order to tell who will (sometime in the future)

Mike

You should be getting audit events in the security logs provided
that Account Management auditing is enabled. You need to view
a consolidated event log from all DCs to really get the picture, as
these are logged on the DC where the action was taken.

Roger



Posted by Special Access on March 29, 2007, 9:49 pm
Please log in for more thread options
On Thu, 29 Mar 2007 10:39:26 -0700, "Roger Abell [MVP]"

>
>> Although I have done several searches online and through the event
>> log...
>>
>> Is there a way to tell who created a user, and who disabled a user in
>> Active Directory (2003 native mode). If not who did, how about what
>> do we need to set in order to tell who will (sometime in the future)
>
>Mike
>
>You should be getting audit events in the security logs provided
>that Account Management auditing is enabled. You need to view
>a consolidated event log from all DCs to really get the picture, as
>these are logged on the DC where the action was taken.
>
>Roger
>

I'll have to look and see if Account Mgt is audited. I know they have
auditing enabled, just not exactly what is being tracked as yet. I
really hate coming in on the tail end of a project, especially one
with little to no documentation on the setup.

Thanks again Roger. You have always tried to help me every time I
have posted a question. I appreciate it.

Mike

Posted by Roger Abell [MVP] on March 30, 2007, 12:04 am
Please log in for more thread options

> On Thu, 29 Mar 2007 10:39:26 -0700, "Roger Abell [MVP]"
>
>>
>>> Although I have done several searches online and through the event
>>> log...
>>>
>>> Is there a way to tell who created a user, and who disabled a user in
>>> Active Directory (2003 native mode). If not who did, how about what
>>> do we need to set in order to tell who will (sometime in the future)
>>
>>Mike
>>
>>You should be getting audit events in the security logs provided
>>that Account Management auditing is enabled. You need to view
>>a consolidated event log from all DCs to really get the picture, as
>>these are logged on the DC where the action was taken.
>>
>>Roger
>>
>
> I'll have to look and see if Account Mgt is audited. I know they have
> auditing enabled, just not exactly what is being tracked as yet. I
> really hate coming in on the tail end of a project, especially one
> with little to no documentation on the setup.
>
> Thanks again Roger. You have always tried to help me every time I
> have posted a question. I appreciate it.
>
> Mike

No problem, thanks.

Your comments reminded me of the sign in the auto shop,
Labor $50/hour I work on it first, $250/hour you work on it first.

Roger



Similar ThreadsPosted
IPSec NAT-T disabled on SP2 September 19, 2005, 12:11 pm
Services disabled by itself March 1, 2006, 8:40 pm
Inherited Permissions disabled? October 12, 2007, 9:16 pm
Problem with Machine Certs being used as User Certs June 15, 2005, 7:06 am
Disabled Domain Computer Accounts September 20, 2006, 4:09 pm
server2008 password expiration disabled? February 28, 2008, 7:00 pm
PCs still function on domain with computer account disabled June 14, 2006, 3:51 pm
Logon to Windows disabled on Vista Remote Desktop December 12, 2007, 9:30 pm
Server 2003 sp1 - DCOM 'Edit Limits' button disabled June 17, 2005, 2:42 pm
Administrator account disabled but still get "incorrect password" errors in Event log May 4, 2008, 2:11 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap