WinSecWiki
Windows Security Settings
Articles
WinSecWiki
»
Windows Security Settings
»
Local Policies
»
Audit Policy
»
Audit directory service access
»
Directory Service Changes
Directory Service Changes
Directory Service Changes
This category only generates events on domain controllers and is very useful for tracking changes to Active Directory objects that have object level auditing enabled. These events not only tell you what object and property was changed and by whom but also the new value of the affected properties. To configure this category you must use
auditpol.
Coverage on events generated by this category are currently in the
Security Log Encyclopedia
:
Event ID
Title
5136
A directory service object was modified.
5137
A directory service object was created.
5138
A directory service object was undeleted.
5139
A directory service object was moved.
5141
A directory service object was deleted
Add Your Comments
Name:
*
Email Address:
Web Address:
Verification Code:
*
Details
Rated 5 stars based on 1 vote.
Article has been viewed 2,327 times.
Options
Bookmark Article
Social Bookmarks
Comments RSS
Upcoming Webinars
Web Protection: The Missing Link in the Endpoint Security Chain?
File Integrity Monitoring with the Windows Security Log
Anatomy of an Attack: What Happened at RSA and What Can We Learn From It?
Implementing Virtual Security Cameras to Protect Privileged Access and Enforce Accountability
Additional Resources
Security Log Quick Reference Chart
Security Log Resource Kit
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
Home
>
Windows
>
WinSecWiki
User name:
Password:
/
Forgot?
Register
Home