Direct Inward Dialing: +1 408 916 9892
Once ADAudit Plus is installed, it automatically configures audit policies required for Active Directory auditing.
To enable automatic configuration: Log in to the ADAudit Plus web console → Domain Settings → Audit Policy: Configure.
Permission changes in DNS records can be identified by following the below mentioned steps:
Login to ADAudit Plus.
Select the required Domain from the dropdown list.
Go to the Reports tab.
Navigate to User Logon Reports.
Select Domain Controller Logon Activity.
ADAudit Plus enables IT administrators to have a comprehensive picture of all the activities that happen within their organization's network. The real-time monitoring capabilities and out-of-the-box reports offered by ADAudit Plus makes it easier to track critical domain controller logon events, and detect and prevent mishaps.
With native AD auditing, here is how you can monitor domain controller logon activity:
Launch Server Manager in your Windows Server instance.
Under Manage, select Group Policy Management and launch the Group Policy Management console.
Navigate to Forest ➔ Domain ➔ Your domain ➔ Domain Controllers.
Create a new GPO and link it to the domain containing the DC to be monitored, or edit any existing GPO that is linked to the domain to open the Group Policy Management Editor.
Navigate to Computer Configuration ➔ Windows Settings ➔ Security Settings ➔ Local Policies ➔ Audit Policy.
The Audit Policy lists all of its sub-policies in the right panel, as shown in the figure below.
Under Audit Policy, turn auditing on for Success and failure events of the following policies:
Audit Account Logon Events
Audit Logon Events
Click Apply and OK to close Properties window.
To enforce these changes throughout the domain, run the command gpupdate /force, in the Run console.
In Event Viewer window, go to Windows Logs ➔ Security logs.
Click on Filter current log under Action in the right panel.
Search for Event IDs 4624 and 4634, these identify when an account was logged on or logged off respectively.
You can double-click on the event to view Event Properties.
These steps need to be repeated for all the domain controllers in the Active Directory environment to audit logon activity. Manually checking every event is time-consuming, inefficient and practically impossible for large organizations.
Native auditing becoming a little too much?
Simplify domain controller logon activity auditing and reporting with ADAudit Plus.
Get Your Free Trial Fully functional 30-day trialADAudit Plus simplifies monitoring of DC logon activity by offering predefined Domain Controller Logon Activity reports along with intuitive graphical representation of the same for the ease of comprehension. ADAudit Plus also provides the option to generate custom reports and export them in your preferred format (PDF, XLS, HTML, and CSV).