Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

 

How to set up alerts in Active Directory - ADAudit Plus

Auditing changes in an organization's Active Directory environment is essential to obtain a comprehensive picture of the network's status but it is not sufficient. Without real-time alert mechanisms in place, inappropriate access to network resources may not be detected soon enough before a compromise occurs. The longer a malicious activity goes unnoticed, the greater could be the impact on the organization. Hence it is crucial to set up real-time alerts to combat threats proactively.

Download for FREE
Free, fully functional 30-day trial
  • With Native AD Auditing

  • With ADAudit Plus

  • How to configure alerts in Active Directory with ADAudit Plus
  • Once ADAudit Plus is installed, it automatically configures audit policies required for Active Directory auditing.

  • To enable automatic configuration: Log in to the ADAudit Plus web console → Domain Settings → Audit Policy: Configure.

  • Active Directory alert notifications can be setup using ADAudit Plus by following the below mentioned steps:

    1. Login to ADAudit Plus.

    2. Select the required Domain from the dropdown list.

    3. Go to the Configuration tab.

    4. Navigate to Alert Profiles.

    5. Select Create Alert Profile.

    how-to-setup-active-directory-alerts-2
  • Fill the necessary fields such as

    1. Name - Enter a name for the alert.

    2. Description - Provide a short description about the alert.

    3. Severity - Indicate the degree of importance associated with an event.

    4. Category - Select the AD report that needs to be monitored.

    5. Alert Message - Specify the details of the alert generated in a easy-to-understand manner.

  • Click on the Advanced Configuration option to filter the event based on

    1. Threshold based Alerts - Use this to manage the number of alerts generated for a particular event.

    2. Business hour alert - Filter the event based on business or non-business hours.

    3. Filter - Using this advanced filter, any event can be drilled further down.

  • ADAudit Plus permits three types of alerting actions to be performed.

    1. E-mail Notification - This option sends notifications for configured alerts by e-mail.

      how-to-setup-active-directory-alerts-3
    2. E-mail Notification - This option sends notifications for configured alerts by e-mail.

      how-to-setup-active-directory-alerts-4
    3. Execute Script - This option permits configuration of actionable scripts to be executed. PowerShell, VBScript, Batch and Executables are the supported script formats.

      how-to-setup-active-directory-alerts-5
  • Once all the fields have been filled appropriately, click Save.

  • Navigate to Alerts tab to get a comprehensive view of all the alert profiles that have been setup.

    how-to-setup-active-directory-alerts-6
  • ADAudit Plus's real-time Active Directory auditing capability and comprehensive yet convenient to handle dashboard makes setting up and managing alert profiles for critical events a breeze.

  • With native AD auditing, here is how you can monitor Windows registry permission changes:

  • Step 1: Enable required audit policies
  • Identify the Active Directory events that you would like to monitor and receive alert notifications for.

  • Launch Server Manager in your Windows Server instance.

  • Under Manage, select Group Policy Management and launch the Group Policy Management console.

  • Navigate to Forest ➔ Domain ➔ Your domain ➔ Domain Controllers.

  • Create a new GPO and link it to the domain containing the user object, or edit any existing GPO that is linked to the domain to open the Group Policy Management Editor.

  • Depending on the events that you would like to monitor, navigate appropriately and select the policies you want to enable for both its successful and failure events.

  • Click Apply and OK to close Properties window.

  • To enforce these changes throughout the domain, run the command gpupdate /force, in the Run console.

  • Step 2: Enable alert notifications in Event Viewer
  • Once auditing has been enabled, each time that event occurs, an entry is made in the Event Viewer. You can setup alerts by following the steps below:

  • Click on Start ➔ Administrative Tools ➔ Event Viewer

  • Click Windows Logs and select Security. You will see all the events logged in security logs.

  • Use Find option to search for the event you are looking for.

  • Right-click on the event and select Attach Task to this Event.

  • Follow the steps in the Create Basic Task Wizard.

  • The Action part of the wizard lets you perform three operations:

    1. Start a Program

    2. Send an e-mail

    3. Display a message

    how-to-setup-active-directory-alerts-1
  • To Start a Program, save the code to be executed upon occurrence of the event as a Powershell script with .ps1 extension. Specify the path to the script in the Program/Script field.

  • Similarly you can setup an e-mail or message notification by entering the necessary details such as the message to be displayed, SMTP server, sender and receiver's e-mail addresses.

  • Click Finish and close the wizard.

  • These steps need to be repeated for all the desired events in the Active Directory environment to receive notifications each time the event occurs. Manually setting up alert notifications for every event is time-consuming, inefficient and practically impossible.

Native auditing becoming a little too much?

Simplify alert configuration with ADAudit Plus.

Get Your Free Trial Fully functional 30-day trial

ADAudit Plus can serve as a efficient Active Directory change notification tool. It simplifies the monitoring of Active Directory events and configuring alert profiles for critical events by offering an easy-to-use interactive user interface. ADAudit Plus doubles up as a AD alerting software, using which the IT administrators can set up and manage alerts centrally.

Request 1-on-1 demo

  •  
  •  
  •  
  •  
  •  
  • -Select-
  • By clicking 'Submit' you agree to processing of personal data according to the Privacy Policy.

Thanks

One of our solution experts will get in touch with you shortly.

ADAudit Plus Trusted By